SANS Report: Tailoring Intelligence for Automated Response
Cyber threat intelligence (CTI), when used correctly, provides visibility into attacks and threats. However, security analysts are dealing with too many sources of intelligence. They aren't able to correlate and narrow all these sources of intelligence to those events and vulnerabilities that really matter. The SANS CTI survey states that organizations can accept and utilize up to 10 threat indicators a week, yet most are receiving between 11 and 100 threat intelligence feeds per week. This is causing information overload and causes more confusion for practitioners. What is noise? To what do IT staff really need to pay attention?
