Measuring the IQ of Your Threat Intelligence Feeds

Measuring the IQ of Your Threat Intelligence Feeds

BSidesLV via YouTube Direct link

Experiments with DNS

10 of 30

10 of 30

Experiments with DNS

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Measuring the IQ of Your Threat Intelligence Feeds

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Who are we
  3. 3 What is threat intelligence
  4. 4 The math talk
  5. 5 IP addresses
  6. 6 Metrics
  7. 7 Raw data
  8. 8 Inbound vs Outbound
  9. 9 Experiments with IP Addresses
  10. 10 Experiments with DNS
  11. 11 Dont do maps
  12. 12 Three tests
  13. 13 Information asymmetry
  14. 14 Novelty tests
  15. 15 Daily or hourly
  16. 16 Overlap test
  17. 17 Outbound test
  18. 18 Population test
  19. 19 True population
  20. 20 Public outbound
  21. 21 Hypothesis testing
  22. 22 Confidence intervals
  23. 23 Comparing different populations
  24. 24 Google
  25. 25 GPL
  26. 26 Combine
  27. 27 Main Takeaway
  28. 28 QA
  29. 29 Commercial feeds
  30. 30 False positives

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.