Threat intelligence For Products Explained
Image Source: depositphotos.com
TLDR: Product threat intelligence comes from using product specific threat intelligence platforms like PCA CERVUS and is specific to individual products and their parts.
Most threat intelligence platforms are built for security operations centres (SOCs) and thus they track attacker infrastructure and campaigns aimed at corporate networks.
These platforms are designed to help an SOC defend an organization and give the TTPs needed to run red teaming or pen testing against these environments also.
However, normal threat intelligence platforms are less useful for an organization that builds or runs payment terminals,vehicle ECU, industrial controllers or other embedded products. These kinds of situations need specific product threat intelligence from a product threat intelligence solution like PCA Cervus.
Here we explain the difference between generic threat intelligence and product threat intelligence platforms to show what each does.
Generic threat intelligence vs product threat intelligence platforms
A “ threat intelligence platform” typically delivers indicators of compromise (IOCs), such as malicious IP addresses, domains and file hashes, along with reporting on threat actors and their techniques to SOC teams who might load these into SIEM and detection tools to spot attacks on IT infrastructure.
In contrast, product threat intelligence feeds and platforms are designed to supply specific data on risk that emerge from the components of a device or product by tracking new vulnerabilities in the open-source libraries and chip vendor SDKs that devices are built on.
Product specific platforms thus follow wider threat actor TTPs alongside exploit code for specific components and research into hardware attacks such as fault injection.
Companies providing product intel therefore must watch attacker interest in product categories, for example tools for tampering with payment terminals traded on criminal forums, and translate that into insights that can be used to harden products.
The threat intelligence supplied by product threat intelligence platforms is designed to be used by product security and engineering teams. They need to know which component is affected and which devices carry it. A list of IP addresses does not help them.
Products carry component risks
A payment terminal or industrial controller will often stay in service for many years and thus presents a static and broad attack surface (with a complex supply chain risk) in a highly variable and fast moving threat landscape.
Intelligence about a component therefore will need to be continuous for as long as devices containing it remain deployed, including after the product stops selling. Here’s why this matters.
Product risk relevance is highly contextual
When it comes to products, vulnerability reports only become useful when they are tied to the product i.e the report is based on what is inside each device.
This context is usually obtained by validating a device’s software bill of materials (SBOM) and testing whether the affected code is reachable through the device's interfaces.
Exploit evidence sets priority
Generic threat intelligence often boils down to CVE score. However prioritisation based on vulnerability severity scores alone will produce too many urgent items for a security or product engineering team to sustainably deal with.
Threat intelligence needs to be paired with evidence of active exploitation, or of working exploit code for a device class to be actional, this is what product threat intelligence is.
Sources of this data include public vulnerability databases, supplier and chip vendor advisories, academic and conference research, exploit repositories and underground forums. A product specific threat intelligence platform combines this data with information about device components to produce actional advice.
Product threat Intel Platforms
PCA CERVUS from PCA Cyber Security is a product threat intelligence platform.
It uses an xBOM as the model of each device and monitors the components inside it, whereas traditional threat intelligence platforms monitor IOCs. The workflow starts with an uploaded SBOM. CERVUS validates the components, detects new vulnerabilities, identifies the affected products, prioritises the risk and notifies engineering.
However, product threat intelligence platforms like PCA CERVUS do not replace an SOC's threat intel feeds.
An SOC will still need a threat intelligence platform designed to supply data for IT infrastructure however the product security team needs its own view, organised around devices.
The work lies in connecting threats to products, teams correlate intelligence with product architecture and SBOMs, track which devices and firmware versions are affected, and follow each issue through to a verified fix. Over time the same intelligence informs design decisions for new products, so known weaknesses are dealt with before release.