Skip to Main Content
Accessibility Overview
webinar register page
Topic
IOB: Tracking adversary behaviors closes gaps in cyber threat intelligence sharing
Description
There is a significant gap in CTI sharing when that sharing is solely focused on IOCs. IOCs by their very nature have a limited time window of being actionable towards network defense. While significant progress has been made in responding to IOCs through automation, there remains a clear need for sharing data that can help a community of network defenders proactively defend against advanced attacks. This need led to the founding of our effort to define Indicators of Behavior (IOBs).
IOBs are dynamic digital impressions and identifiers that monitor the interaction of foreign bodies with host systems or networks. From a threat detection and awareness perspective, IOBs help add context. They also help you understand the behavior of potential cyber attackers.
The goal of our IOB effort at OCA is to create a standard way to represent cyber adversary behaviors to make it easier to:
~~share repeatable sets of observed adversary behaviors spanning multiple campaigns,
~~share the analytics to detect those behaviors, and
~~create and share playbooks to correlate those detections.
We’ve seen that an effective defense couldn’t happen without leveraging the power of community, but it also couldn’t happen without a common language to share information. The STIX and TAXII standards help to provide the key to achieving our OCA-IOB results.
During this panel, our guest speakers will share information on the work being done at OCA-IOB that allows actionable threat intelligence to be shared across multiple communities at machine speed and how that intelligence can translate directly into detections and correlations that are both repeatable and have lower false positive rates. They’ll review how past experiences with CTI sharing impacted this work, what’s behind the motivation to represent adversary behavior, and provide access to several reference implementations and analysis capabilities, and finally, how and why you should be involved in the next evolution of OCA-IOB.
Time
Mar 1, 2023 11:00 AM in
Eastern Time (US and Canada)
Webinar is over, you cannot register now. If you have any questions, please contact Webinar host:
.
×
Share via Email
All fields are required
Your Information
Send to
Message preview
Hi there, You are invited to a Zoom webinar. When: Mar 1, 2023 11:00 AM Eastern Time (US and Canada) Topic: IOB: Tracking adversary behaviors closes gaps in cyber threat intelligence sharing Register in advance for this webinar: https://us06web.zoom.us/webinar/register/WN_iw4C_NC_SxS1NPZVOEE4WA After registering, you will receive a confirmation email containing information about joining the webinar. ---------- Webinar Speakers Harley Parkes (IACD Lead @Johns Hopkins University Applied Physics Laboratory) Jason Keirstead (Co-Chair @Open Cybersecurity Alliance (OCA) and IBM Security) Charlie Frick (Chair @OCA-Indicators of Behavior Project and Johns Hopkins Applied Physics Laboratory (APL)) Carter Bullard (Technical Committee Member @OCA-Indicators of Behavior Project and Neya Systems Division)
×
Switch Time Zone
Time Zone:
(GMT-11:00) Midway Island, Samoa
(GMT-11:00) Pago Pago
(GMT-10:00) Hawaii
(GMT-8:00) Alaska
(GMT-8:00) Juneau
(GMT-7:00) Vancouver
(GMT-7:00) Pacific Time (US and Canada)
(GMT-7:00) Tijuana
(GMT-7:00) Arizona
(GMT-7:00) Mazatlan
(GMT-7:00) Yukon
(GMT-6:00) Edmonton
(GMT-6:00) Mountain Time (US and Canada)
(GMT-6:00) Saskatchewan
(GMT-6:00) Mexico City
(GMT-6:00) Guatemala
(GMT-6:00) El Salvador
(GMT-6:00) Managua
(GMT-6:00) Costa Rica
(GMT-6:00) Tegucigalpa
(GMT-6:00) Chihuahua
(GMT-6:00) Monterrey
(GMT-5:00) Winnipeg
(GMT-5:00) Central Time (US and Canada)
(GMT-5:00) Panama
(GMT-5:00) Bogota
(GMT-5:00) Lima
(GMT-5:00) Acre
(GMT-4:00) Montreal
(GMT-4:00) Eastern Time (US and Canada)
(GMT-4:00) Indiana (East)
(GMT-4:00) Puerto Rico
(GMT-4:00) Caracas
(GMT-4:00) La Paz
(GMT-4:00) Guyana
(GMT-3:00) Halifax
(GMT-3:00) Santiago
(GMT-3:00) Montevideo
(GMT-3:00) Recife
(GMT-3:00) Buenos Aires, Georgetown
(GMT-3:00) Greenland
(GMT-3:00) Sao Paulo
(GMT-3:00) Atlantic Time (Canada)
(GMT-2:30) Newfoundland and Labrador
(GMT-2:00) Fernando de Noronha
(GMT-1:00) Azores
(GMT-1:00) Cape Verde Islands
(GMT+0:00) Universal Time UTC
(GMT+0:00) Greenwich Mean Time
(GMT+0:00) Reykjavik
(GMT+0:00) Dublin
(GMT+0:00) London
(GMT+0:00) Lisbon
(GMT+0:00) Casablanca
(GMT+0:00) Nouakchott
(GMT+1:00) Belgrade, Bratislava, Ljubljana
(GMT+1:00) Sarajevo, Skopje, Zagreb
(GMT+1:00) Oslo
(GMT+1:00) Copenhagen
(GMT+1:00) Brussels
(GMT+1:00) Amsterdam, Berlin, Rome, Stockholm, Vienna
(GMT+1:00) Amsterdam
(GMT+1:00) Rome
(GMT+1:00) Stockholm
(GMT+1:00) Vienna
(GMT+1:00) Luxembourg
(GMT+1:00) Paris
(GMT+1:00) Zurich
(GMT+1:00) Madrid
(GMT+1:00) West Central Africa
(GMT+1:00) Algiers
(GMT+1:00) Tunis
(GMT+1:00) Warsaw
(GMT+1:00) Prague Bratislava
(GMT+1:00) Budapest
(GMT+2:00) Helsinki
(GMT+2:00) Harare, Pretoria
(GMT+2:00) Sofia
(GMT+2:00) Athens
(GMT+2:00) Bucharest
(GMT+2:00) Nicosia
(GMT+2:00) Beirut
(GMT+2:00) Tripoli
(GMT+2:00) Cairo
(GMT+2:00) Johannesburg
(GMT+2:00) Khartoum
(GMT+2:00) Kyiv
(GMT+2:00) Chisinau
(GMT+3:00) Jerusalem
(GMT+3:00) Nairobi
(GMT+3:00) Istanbul
(GMT+3:00) Damascus
(GMT+3:00) Amman
(GMT+3:00) Moscow
(GMT+3:00) Baghdad
(GMT+3:00) Kuwait
(GMT+3:00) Riyadh
(GMT+3:00) Bahrain
(GMT+3:00) Qatar
(GMT+3:00) Aden
(GMT+3:00) Djibouti
(GMT+3:00) Mogadishu
(GMT+3:00) Minsk
(GMT+3:30) Tehran
(GMT+4:00) Dubai
(GMT+4:00) Muscat
(GMT+4:00) Baku, Tbilisi, Yerevan
(GMT+4:30) Kabul
(GMT+5:00) Yekaterinburg
(GMT+5:00) Islamabad, Karachi, Tashkent
(GMT+5:30) India
(GMT+5:30) Mumbai, Kolkata, New Delhi
(GMT+5:30) Colombo
(GMT+5:45) Kathmandu
(GMT+6:00) Almaty
(GMT+6:00) Dacca
(GMT+6:00) Astana, Dhaka
(GMT+6:30) Rangoon
(GMT+7:00) Novosibirsk
(GMT+7:00) Krasnoyarsk
(GMT+7:00) Bangkok
(GMT+7:00) Vietnam
(GMT+7:00) Jakarta
(GMT+8:00) Irkutsk, Ulaanbaatar
(GMT+8:00) Beijing, Shanghai
(GMT+8:00) Hong Kong SAR
(GMT+8:00) Taipei
(GMT+8:00) Kuala Lumpur
(GMT+8:00) Singapore
(GMT+8:00) Perth
(GMT+9:00) Yakutsk
(GMT+9:00) Seoul
(GMT+9:00) Osaka, Sapporo, Tokyo
(GMT+9:30) Darwin
(GMT+10:00) Vladivostok
(GMT+10:00) Guam, Port Moresby
(GMT+10:00) Brisbane
(GMT+10:30) Adelaide
(GMT+11:00) Canberra, Melbourne, Sydney
(GMT+11:00) Hobart
(GMT+11:00) Magadan
(GMT+11:00) Solomon Islands
(GMT+11:00) New Caledonia
(GMT+11:00) Lord Howe IsIand
(GMT+12:00) Kamchatka
(GMT+12:00) Fiji Islands, Marshall Islands
(GMT+13:00) Auckland, Wellington
(GMT+13:00) Independent State of Samoa
×
Continue to PayPal
Click to Continue
×
×
Upcoming Meetings
Would you like to start this meeting?
Would you like to start one of these meetings?
View more...