<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Jesper Olsen-arkiv - IT-säkerhetspodden</title>
	<atom:link href="https://www.itsakerhetspodden.se/tag/jesper-olsen/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.itsakerhetspodden.se/tag/jesper-olsen/</link>
	<description>IT-säkerhet med Erik och Mattias som varvar kändisintervjuer med säkerhetssnack i tiden</description>
	<lastBuildDate>Sun, 12 Jun 2022 08:24:14 +0000</lastBuildDate>
	<language>sv-SE</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://www.itsakerhetspodden.se/wp-content/uploads/2020/04/cropped-sitelogo-32x32.jpg</url>
	<title>Jesper Olsen-arkiv - IT-säkerhetspodden</title>
	<link>https://www.itsakerhetspodden.se/tag/jesper-olsen/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">171781042</site>	<item>
		<title>#170 &#8211; Sig Security about the practical use of Threat Intelligence</title>
		<link>https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/</link>
					<comments>https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/#respond</comments>
		
		<dc:creator><![CDATA[Erik Zalitis]]></dc:creator>
		<pubDate>Sun, 22 May 2022 16:00:01 +0000</pubDate>
				<category><![CDATA[ShowNotes]]></category>
		<category><![CDATA[Christoffer Strömblad]]></category>
		<category><![CDATA[Erik Zalitis]]></category>
		<category><![CDATA[Jesper Olsen]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[SIG Security Shownotes]]></category>
		<category><![CDATA[Sponsrat]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[TrueSec]]></category>
		<guid isPermaLink="false">https://www.itsakerhetspodden.se/?p=5250</guid>

					<description><![CDATA[<p>Erik Zalitis, Jesper Olsen and Christoffer Strömblad talk about Threat intelligence - the capability to know yourself and the enemy. How do they work, how do you look to them and are you up to the task of being on the network at all.</p>
<p>It used to be a bit suspicious with security people quoting Sun Tzu, as it was more bravado than actual product. But here, and in this warlike state of business that is the Internet, it fits very well. We are in the middle of a coevolution between hackers and defenders.</p>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/">#170 &#8211; Sig Security about the practical use of Threat Intelligence</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="683" src="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-1024x683.jpg" alt="Threat intelligence illustreras av några mönster i grönt och IT-säkerhetspoddens och SIG Securitys logos." class="wp-image-5248" srcset="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-1024x683.jpg 1024w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-300x200.jpg 300w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-768x512.jpg 768w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-1536x1024.jpg 1536w, https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide.jpg 1800w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>The episode: </strong><a href="https://www.itsakerhetspodden.se/podcast/170/" target="_blank" rel="noreferrer noopener">170 &#8211; Sig Security about the practical use of Threat Intelligence</a><a href="https://www.itsakerhetspodden.se/podcast/142-metaverse-och-sakerhet/" target="_blank" rel="noreferrer noopener"><br></a><strong>Recorded:</strong> 2022-05-17 (publicerat 2022-05-22)<br><strong>Participants: </strong><a href="https://erik.zalitis.se/" target="_blank" rel="noreferrer noopener">Erik Zalitis</a>, Jesper Olsen and Christoffer Strömblad<br>This episode is made in cooperation with SIG Security.</p>



<h2 class="wp-block-heading" id="h-listen-to-the-episode-now-threat-intelligence">Listen to the episode, now &#8211; Threat intelligence</h2>



<iframe title="Libsyn Player" style="border: none" src="//html5-player.libsyn.com/embed/episode/id/23128628/height/90/theme/custom/thumbnail/yes/direction/forward/render-playlist/no/custom-color/000000/" height="90" width="100%" scrolling="no" allowfullscreen="" webkitallowfullscreen="" mozallowfullscreen="" oallowfullscreen="" msallowfullscreen=""></iframe>



<h2 class="wp-block-heading" id="h-while-listening-to-this-episode-threat-intelligence">While listening to this episode &#8211; Threat intelligence</h2>



<p class="wp-block-paragraph">English, again? Yes. I thought it would make it easier to pull together with two Swedes and a Danish. I talk about nationalities here, not food, just pointing that out. Anyways, we have a old friend, Christoffer Strömblad, who was in this podcast in 2019 and a new one, Jesper Olsen. Christoffer has since left the Swedish Police and joined TrueSec, a Swedish IT-security focused company.</p>



<p class="wp-block-paragraph">Jesper is Danish and works for Palo Alto Network, a very welknown creator of security appliances.</p>



<h3 class="wp-block-heading">IT-admin, know thyself!</h3>



<p class="wp-block-paragraph">The subject is interesting, and simple goes:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>&#8221;If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.&#8221;</p></blockquote>



<p class="wp-block-paragraph">It used to be a bit suspicious with security people quoting Sun Tzu, as it was more bravado than actual product. But here, and in this warlike state of business that is the Internet, it fits very well. We are in the middle of a coevolution between hackers and defenders.</p>



<p class="wp-block-paragraph">Christoffer and Jesper talks about what the properties of common victims are and have three rules to go by to assess the situation:</p>



<ul class="wp-block-list"><li>Archetypes &#8211; who gets attacked?</li><li>Vulnerabilities &#8211; How to they get attacked?</li><li>Recognizance &#8211; How to they find you?</li></ul>



<p class="wp-block-paragraph">This may seem like the same discussion like it always was, and yes, to a certain point it is. But it&#8217;s 2022 and the methods they describe are pretty new as in &#8221;a new way of doing the same&#8221;. In the IT-security business, this counts. Brand new, never seen attacks are few. But new takes on old tricks, is what we see all the time as attackers try to remain in control. They crawl around our latest defences. Right now, TrueSec has seen an uptick in USB-drive attacks. Why? Listen to the podcast. It&#8217;s around 19 minutes into the show.</p>



<p class="wp-block-paragraph">But don&#8217;t worry, we also got a new development for you:</p>



<h3 class="wp-block-heading">Initial Access Brokers</h3>



<p class="wp-block-paragraph">At 20:57 I ask Jesper about IABs. That is hackers selling access to organizations instead of data. As the business of hacking matures, it gets more specialized as I wryly note. This is at least new for me and the big development is not how something appears for the first time. Rather when it becomes a thing. You can&#8217;t go full hipster and say &#8221;I knew about that attackvector before everyone did! Dude, like they sold out!&#8221;.</p>



<h3 class="wp-block-heading">Worse than the decease &#8211; the Therac 25</h3>



<p class="wp-block-paragraph">On or about 19:00 I mentiod an X-ray machine killing a patient. It was a device known as Therac-25 and had a bug that sometimes, very uncommonly delivered deadly doses of radiation. The software bug was eventually found, but it was nearly impossible to reproduce the conditions until you knew them. The device had multiple failsafe, but in the end, it did not matter. I&#8217;ll add a link in the bottom of this page, where you can read the story. But this qoute should scare you:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>What they found was shocking. The software appeared to have been written by a programmer with little experience coding for real-time systems. There were few comments, and no proof that any timing analysis had been performed. According to AECL, a single programmer had written the software based upon the Therac-6 and 20 code. However, this programmer no longer worked for the company, and could not be found.</p></blockquote>



<h2 class="wp-block-heading">Links –  Threat intelligence</h2>



<ul class="wp-block-list"><li><a href="https://nordlo.com/" target="_blank" rel="noreferrer noopener sponsored nofollow">Nordlo</a></li><li><a href="https://hackaday.com/2015/10/26/killed-by-a-machine-the-therac-25/" target="_blank" rel="noreferrer noopener">Killed by a machine &#8211; the Therac-25 incidents</a></li></ul>



<h2 class="wp-block-heading">Errors and omissions</h2>



<ul class="wp-block-list"><li>Nothing to report at this time.</li></ul>
<p>Inlägget <a href="https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/">#170 &#8211; Sig Security about the practical use of Threat Intelligence</a> dök först upp på <a href="https://www.itsakerhetspodden.se">IT-säkerhetspodden</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.itsakerhetspodden.se/170-sig-security-about-the-practical-use-of-threat-intelligence/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5250</post-id>
		<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-150x150.jpg" />
		<media:content url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide.jpg" medium="image">
			<media:title type="html">170_wide</media:title>
			<media:thumbnail url="https://www.itsakerhetspodden.se/wp-content/uploads/2022/05/170_wide-150x150.jpg" />
		</media:content>
	</item>
	</channel>
</rss>
