meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 30th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 May 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. Microsoft $MFT DoS Exploit; SMTP Proxy/Split Tunnel Issues

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 30th, 2017 edition of the Sands Internet Storm Center's Stormcast.

0:07.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.7

Attributing attacks to particular actors is a difficult and often controversial task.

0:18.7

Often politics, for example, affects attribution to assign blame to a convenient

0:24.2

target or to attributed attack to an adversary powerful enough to explain the inevitability

0:31.0

of the breach. Nobody really ever wants to admit that they got hacked by a not very sophisticated attacker.

0:39.3

Pascal wrote a nice diary on Monday that introduces a more objective method to compare

0:46.3

different hypotheses when it comes to attribution.

0:49.3

This method known as analysis of competing hypotheses does recognize that definite attribution

0:56.6

is often impossible and it focuses really more on ruling out entities that are not responsible.

1:03.8

In my opinion, one of the main advantages of using this model is to make sure that you're not

1:09.2

getting locked in to an attribution decision by one particular

1:13.7

interesting and convincing piece of evidence, maybe a piece of code, maybe a string or a comment

1:20.1

in the code that you have seen before. But then again, you know, sometimes code is copied from one

1:26.1

actor to another. So to probably assign a blame,

1:30.7

you really have to avoid this. And this model forces you to look at all available evidence

1:36.4

and to properly assign weights to evidence based on how reliable the evidence is and the relevance

1:43.1

for each fact known about the attack.

1:46.0

And well, to make things a little bit more specific,

1:50.0

Pascal promised a second part to this particular diary

1:54.0

for later in the week,

1:56.0

and I believe he's planning to actually apply

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.