﻿1
00:00:02,730 --> 00:00:07,839
<font color="#E5E5E5">okay</font><font color="#CCCCCC"> my name is</font><font color="#E5E5E5"> Aaron</font><font color="#CCCCCC"> Leverett</font><font color="#E5E5E5"> this is</font>

2
00:00:06,970 --> 00:00:10,900
Bruce stunning

3
00:00:07,839 --> 00:00:13,960
we are CEOs of companies that<font color="#E5E5E5"> we just</font>

4
00:00:10,900 --> 00:00:15,639
<font color="#E5E5E5">made</font><font color="#CCCCCC"> up that's sort of true but</font>

5
00:00:13,960 --> 00:00:18,279
genuinely he's<font color="#E5E5E5"> a start-up I'm a</font><font color="#CCCCCC"> startup</font>

6
00:00:15,639 --> 00:00:20,650
<font color="#CCCCCC">that's</font><font color="#E5E5E5"> how it is so it's really late in</font>

7
00:00:18,279 --> 00:00:22,660
<font color="#E5E5E5">the day I was traveling for 24 hours 24</font>

8
00:00:20,650 --> 00:00:24,580
<font color="#E5E5E5">hours ago I was in Cleveland</font><font color="#CCCCCC"> so I'm kind</font>

9
00:00:22,660 --> 00:00:26,859
of exhausted<font color="#CCCCCC"> and a little bit you</font><font color="#E5E5E5"> know</font>

10
00:00:24,580 --> 00:00:28,720
<font color="#E5E5E5">fuzzy so if you give me</font><font color="#CCCCCC"> lots</font><font color="#E5E5E5"> of energy</font>

11
00:00:26,859 --> 00:00:31,330
<font color="#E5E5E5">I'll give you lots of energy</font><font color="#CCCCCC"> and Bruce</font>

12
00:00:28,720 --> 00:00:33,750
<font color="#CCCCCC">and I'll have some fun so how many of</font>

13
00:00:31,330 --> 00:00:35,829
<font color="#E5E5E5">you are still awake put your hand up</font>

14
00:00:33,750 --> 00:00:39,399
okay just checking<font color="#CCCCCC"> how many of you have</font>

15
00:00:35,829 --> 00:00:41,500
bosses<font color="#E5E5E5"> all right some of you how</font><font color="#CCCCCC"> many</font><font color="#E5E5E5"> of</font>

16
00:00:39,399 --> 00:00:46,300
you have<font color="#CCCCCC"> bosses that</font><font color="#E5E5E5"> like to invent</font>

17
00:00:41,500 --> 00:00:47,680
vaporware that you have to<font color="#CCCCCC"> implement you</font>

18
00:00:46,300 --> 00:00:49,209
know<font color="#E5E5E5"> why I'm about to do this</font>

19
00:00:47,680 --> 00:00:51,700
<font color="#CCCCCC">presentation that's that's what</font><font color="#E5E5E5"> this</font><font color="#CCCCCC"> is</font>

20
00:00:49,210 --> 00:00:53,079
all about my boss<font color="#E5E5E5"> at the Center for his</font>

21
00:00:51,700 --> 00:00:55,649
studies<font color="#CCCCCC"> in Cambridge is a really</font><font color="#E5E5E5"> really</font>

22
00:00:53,079 --> 00:00:58,780
clever guy but he doesn't<font color="#CCCCCC"> do the cybers</font>

23
00:00:55,649 --> 00:01:00,579
and he likes<font color="#E5E5E5"> to talk about a PT's and so</font>

24
00:00:58,780 --> 00:01:03,280
he does stuff<font color="#E5E5E5"> like ask me how many</font>

25
00:01:00,579 --> 00:01:04,869
people<font color="#CCCCCC"> are in</font><font color="#E5E5E5"> energetic bear you know</font>

26
00:01:03,280 --> 00:01:06,790
how much<font color="#E5E5E5"> money</font><font color="#CCCCCC"> did they spend</font><font color="#E5E5E5"> on this</font>

27
00:01:04,869 --> 00:01:09,040
type of ransomware<font color="#CCCCCC"> and I'm like how</font><font color="#E5E5E5"> the</font>

28
00:01:06,790 --> 00:01:11,110
<font color="#CCCCCC">hell would I know that</font><font color="#E5E5E5"> right</font>

29
00:01:09,040 --> 00:01:13,869
but then an idea<font color="#E5E5E5"> started to form this</font>

30
00:01:11,110 --> 00:01:15,340
idea of logistical budget<font color="#E5E5E5"> so basically</font>

31
00:01:13,869 --> 00:01:16,780
that's what<font color="#E5E5E5"> this entire presentation is</font>

32
00:01:15,340 --> 00:01:17,860
about Bruce is<font color="#E5E5E5"> going to tell you a</font>

33
00:01:16,780 --> 00:01:21,729
little bit<font color="#E5E5E5"> about the implementation</font>

34
00:01:17,860 --> 00:01:23,950
<font color="#E5E5E5">because I didn't have the time</font><font color="#CCCCCC"> to</font>

35
00:01:21,729 --> 00:01:25,659
implement stuff<font color="#E5E5E5"> so I used my speaker</font>

36
00:01:23,950 --> 00:01:27,189
fees at other conferences to get Bruce

37
00:01:25,659 --> 00:01:28,720
<font color="#E5E5E5">to do this work for me</font>

38
00:01:27,189 --> 00:01:30,220
partly because Bruce<font color="#CCCCCC"> taught me to</font>

39
00:01:28,720 --> 00:01:32,880
program and he's a<font color="#E5E5E5"> better programmer so</font>

40
00:01:30,220 --> 00:01:35,770
I'll<font color="#E5E5E5"> let him introduce some of these</font>

41
00:01:32,880 --> 00:01:40,199
okay so as<font color="#CCCCCC"> Erin</font><font color="#E5E5E5"> said we want to be able</font>

42
00:01:35,770 --> 00:01:42,820
<font color="#E5E5E5">to present stuff to non-technical people</font>

43
00:01:40,200 --> 00:01:46,140
so they<font color="#E5E5E5"> know which threats to</font>

44
00:01:42,820 --> 00:01:50,258
concentrate on and what<font color="#CCCCCC"> to concentrate</font>

45
00:01:46,140 --> 00:01:52,509
stuff on<font color="#E5E5E5"> which direct threat actors can</font>

46
00:01:50,259 --> 00:01:59,500
do the most<font color="#E5E5E5"> damage and save around</font>

47
00:01:52,509 --> 00:02:03,909
somewhere<font color="#CCCCCC"> they can get</font><font color="#E5E5E5"> over you from</font>

48
00:01:59,500 --> 00:02:06,670
reading<font color="#E5E5E5"> literature but what if we can</font>

49
00:02:03,909 --> 00:02:11,790
<font color="#E5E5E5">actually generate visualization directly</font>

50
00:02:06,670 --> 00:02:11,790
from risk data in an<font color="#CCCCCC"> easy-to-understand</font>

51
00:02:13,890 --> 00:02:18,250
data<font color="#CCCCCC"> to</font>

52
00:02:15,430 --> 00:02:29,980
to see how<font color="#E5E5E5"> threatened through structure</font>

53
00:02:18,250 --> 00:02:33,430
is changing<font color="#CCCCCC"> so has</font><font color="#E5E5E5"> anyone heard the the</font>

54
00:02:29,980 --> 00:02:37,840
<font color="#E5E5E5">the term logistical burden before</font><font color="#CCCCCC"> no</font>

55
00:02:33,430 --> 00:02:38,889
yeah<font color="#CCCCCC"> sort</font><font color="#E5E5E5"> of okay</font><font color="#CCCCCC"> so I was</font><font color="#E5E5E5"> working at</font>

56
00:02:37,840 --> 00:02:40,180
the Center for risk studies and they do

57
00:02:38,889 --> 00:02:44,079
all<font color="#CCCCCC"> kinds of risks they do environmental</font>

58
00:02:40,180 --> 00:02:46,150
<font color="#E5E5E5">risk they do you know labor unrest they</font>

59
00:02:44,079 --> 00:02:47,260
do interbank lending risk<font color="#E5E5E5"> whatever it</font>

60
00:02:46,150 --> 00:02:48,400
was great I got<font color="#E5E5E5"> to hang out with</font><font color="#CCCCCC"> all</font>

61
00:02:47,260 --> 00:02:49,328
these amazing<font color="#E5E5E5"> people and so I was</font>

62
00:02:48,400 --> 00:02:51,099
<font color="#E5E5E5">working with</font><font color="#CCCCCC"> these counterterrorism</font>

63
00:02:49,329 --> 00:02:52,689
<font color="#CCCCCC">professionals and they came to me</font>

64
00:02:51,099 --> 00:02:54,970
we were talking about adversarial risk

65
00:02:52,689 --> 00:02:57,010
like how do<font color="#E5E5E5"> you quantify adversaries</font>

66
00:02:54,970 --> 00:02:59,290
<font color="#CCCCCC">that change and adapt and think and do</font>

67
00:02:57,010 --> 00:03:01,480
stuff<font color="#CCCCCC"> right and they introduced</font><font color="#E5E5E5"> me to</font>

68
00:02:59,290 --> 00:03:04,060
the<font color="#CCCCCC"> concept of logistical burden</font><font color="#E5E5E5"> so you</font>

69
00:03:01,480 --> 00:03:06,790
go to a site<font color="#E5E5E5"> let's say</font><font color="#CCCCCC"> like a ship or a</font>

70
00:03:04,060 --> 00:03:08,620
building and you you take some<font color="#CCCCCC"> special</font>

71
00:03:06,790 --> 00:03:10,450
<font color="#E5E5E5">forces people and you ask them</font><font color="#CCCCCC"> to</font><font color="#E5E5E5"> ask me</font>

72
00:03:08,620 --> 00:03:12,040
<font color="#E5E5E5">how many people were to take to storm</font>

73
00:03:10,450 --> 00:03:13,929
<font color="#E5E5E5">this building or to drive a truck bomb</font>

74
00:03:12,040 --> 00:03:15,189
here<font color="#E5E5E5"> how much money would</font><font color="#CCCCCC"> it cost how</font>

75
00:03:13,930 --> 00:03:16,659
big<font color="#E5E5E5"> would the bomb need to be these</font>

76
00:03:15,189 --> 00:03:18,310
<font color="#CCCCCC">these kinds of questions right and</font><font color="#E5E5E5"> they</font>

77
00:03:16,659 --> 00:03:21,220
estimate the size of a threat<font color="#CCCCCC"> that</font><font color="#E5E5E5"> would</font>

78
00:03:18,310 --> 00:03:23,260
be<font color="#E5E5E5"> required for</font><font color="#CCCCCC"> a particular</font><font color="#E5E5E5"> target</font>

79
00:03:21,220 --> 00:03:24,879
right<font color="#E5E5E5"> now I didn't particularly want to</font>

80
00:03:23,260 --> 00:03:25,599
do that I realized we could do this<font color="#E5E5E5"> the</font>

81
00:03:24,879 --> 00:03:26,530
<font color="#CCCCCC">other way around</font>

82
00:03:25,599 --> 00:03:27,940
and that's what the rest<font color="#CCCCCC"> of this</font>

83
00:03:26,530 --> 00:03:30,819
<font color="#CCCCCC">presentation is</font><font color="#E5E5E5"> going to be about</font><font color="#CCCCCC"> it's</font>

84
00:03:27,940 --> 00:03:32,919
if we take indicators and<font color="#E5E5E5"> we assume</font><font color="#CCCCCC"> that</font>

85
00:03:30,819 --> 00:03:34,869
they<font color="#CCCCCC"> have a cost in</font><font color="#E5E5E5"> money manpower</font><font color="#CCCCCC"> time</font>

86
00:03:32,919 --> 00:03:37,090
<font color="#E5E5E5">then we can start to get</font><font color="#CCCCCC"> a sense of the</font>

87
00:03:34,870 --> 00:03:42,280
logistical budget of different apt

88
00:03:37,090 --> 00:03:45,819
actors right wanted to quickly

89
00:03:42,280 --> 00:03:49,689
<font color="#E5E5E5">prototypes and visualizations so we used</font>

90
00:03:45,819 --> 00:03:53,858
Primus<font color="#E5E5E5"> to grab data from</font><font color="#CCCCCC"> Aaron's Mizpah</font>

91
00:03:49,689 --> 00:03:56,198
server and pickle to cache it<font color="#CCCCCC"> locally so</font>

92
00:03:53,859 --> 00:03:59,799
<font color="#CCCCCC">that we can very quickly iterate through</font>

93
00:03:56,199 --> 00:04:02,549
stuff<font color="#CCCCCC"> so what we want to</font><font color="#E5E5E5"> do is scan</font>

94
00:03:59,799 --> 00:04:05,829
through<font color="#E5E5E5"> miss events and attributes</font><font color="#CCCCCC"> and</font>

95
00:04:02,549 --> 00:04:09,909
filter based on galaxies and date ranges

96
00:04:05,829 --> 00:04:14,319
and then accumulate score for the

97
00:04:09,909 --> 00:04:18,009
entities<font color="#CCCCCC"> that we found</font><font color="#E5E5E5"> we used</font><font color="#CCCCCC"> portly</font>

98
00:04:14,319 --> 00:04:21,728
initially for heat maps<font color="#CCCCCC"> because it's</font>

99
00:04:18,009 --> 00:04:26,159
really<font color="#CCCCCC"> easy to output data that plotly</font>

100
00:04:21,728 --> 00:04:28,330
understands and later on<font color="#CCCCCC"> a new plot for</font>

101
00:04:26,159 --> 00:04:42,729
a bit more<font color="#CCCCCC"> flick</font>

102
00:04:28,330 --> 00:04:44,258
but it has some drawbacks<font color="#CCCCCC"> I think so</font>

103
00:04:42,729 --> 00:04:47,909
first we generated heat maps for<font color="#CCCCCC"> a</font>

104
00:04:44,259 --> 00:04:50,110
threat<font color="#E5E5E5"> back to activity and then</font>

105
00:04:47,909 --> 00:04:53,469
generated<font color="#CCCCCC"> scorecards which are</font>

106
00:04:50,110 --> 00:04:56,020
comparable<font color="#CCCCCC"> with each other for threat</font>

107
00:04:53,470 --> 00:05:00,849
actors<font color="#E5E5E5"> but also ransomware because it</font>

108
00:04:56,020 --> 00:05:02,530
was a<font color="#E5E5E5"> really easy extension</font><font color="#CCCCCC"> one things I</font>

109
00:05:00,849 --> 00:05:04,630
struggled<font color="#CCCCCC"> with not having Aaron's</font>

110
00:05:02,530 --> 00:05:10,960
background in threat intelligence and

111
00:05:04,630 --> 00:05:15,240
this was domain knowledge<font color="#CCCCCC"> so after</font>

112
00:05:10,960 --> 00:05:19,000
grabbing the data from the server<font color="#E5E5E5"> we</font>

113
00:05:15,240 --> 00:05:21,610
quickly were a Python<font color="#CCCCCC"> script to dump the</font>

114
00:05:19,000 --> 00:05:25,449
fields and to count frequencies and so

115
00:05:21,610 --> 00:05:27,789
on that made it very<font color="#E5E5E5"> easy</font><font color="#CCCCCC"> to</font><font color="#E5E5E5"> get a</font>

116
00:05:25,449 --> 00:05:30,610
better<font color="#E5E5E5"> understanding of what data is in</font>

117
00:05:27,789 --> 00:05:33,750
Aaron Smith server and how we should<font color="#CCCCCC"> be</font>

118
00:05:30,610 --> 00:05:39,909
writing scoring functions<font color="#E5E5E5"> so this is a</font>

119
00:05:33,750 --> 00:05:41,560
kind of stuff go back<font color="#E5E5E5"> so this speaks</font>

120
00:05:39,909 --> 00:05:43,300
very much<font color="#CCCCCC"> to</font><font color="#E5E5E5"> your point</font><font color="#CCCCCC"> under s about</font>

121
00:05:41,560 --> 00:05:45,370
you know when<font color="#CCCCCC"> people first encounter a</font>

122
00:05:43,300 --> 00:05:46,539
<font color="#CCCCCC">Mis server</font><font color="#E5E5E5"> they don't know what the</font>

123
00:05:45,370 --> 00:05:47,830
fields are they<font color="#E5E5E5"> don't know what the data</font>

124
00:05:46,539 --> 00:05:49,870
looks like<font color="#CCCCCC"> and it's fine</font><font color="#E5E5E5"> if you're like</font>

125
00:05:47,830 --> 00:05:51,520
a front-end user using the GUI but you

126
00:05:49,870 --> 00:05:53,949
<font color="#E5E5E5">sometimes need</font><font color="#CCCCCC"> to dig around</font><font color="#E5E5E5"> and inside</font>

127
00:05:51,520 --> 00:05:56,109
the<font color="#CCCCCC"> mists</font><font color="#E5E5E5"> server to figure out what what</font>

128
00:05:53,949 --> 00:05:59,289
you've got<font color="#E5E5E5"> and</font><font color="#CCCCCC"> an</font><font color="#E5E5E5"> interesting point</font><font color="#CCCCCC"> here</font>

129
00:05:56,110 --> 00:06:01,120
is we<font color="#E5E5E5"> wanted to start with with things</font>

130
00:05:59,289 --> 00:06:04,240
<font color="#E5E5E5">that had attribution that had threat</font>

131
00:06:01,120 --> 00:06:05,949
actors attributed to the events<font color="#E5E5E5"> which is</font>

132
00:06:04,240 --> 00:06:07,330
not my<font color="#E5E5E5"> favorite thing to</font><font color="#CCCCCC"> work on like</font>

133
00:06:05,949 --> 00:06:09,490
attribution is essentially<font color="#CCCCCC"> a political</font>

134
00:06:07,330 --> 00:06:10,690
<font color="#E5E5E5">act and I find it very complicated</font><font color="#CCCCCC"> so</font>

135
00:06:09,490 --> 00:06:14,440
the<font color="#CCCCCC"> first thing we wanted</font><font color="#E5E5E5"> to know is</font>

136
00:06:10,690 --> 00:06:16,300
what percentage of of events inside my

137
00:06:14,440 --> 00:06:17,740
<font color="#E5E5E5">mr. server were attributed</font><font color="#CCCCCC"> to a</font>

138
00:06:16,300 --> 00:06:20,020
<font color="#CCCCCC">particular</font><font color="#E5E5E5"> threat actor and it was like</font>

139
00:06:17,740 --> 00:06:21,550
<font color="#CCCCCC">8% I imagine most</font><font color="#E5E5E5"> of</font><font color="#CCCCCC"> you it's fairly</font>

140
00:06:20,020 --> 00:06:23,500
<font color="#E5E5E5">similar</font><font color="#CCCCCC"> so one</font><font color="#E5E5E5"> of the things we can talk</font>

141
00:06:21,550 --> 00:06:25,180
<font color="#E5E5E5">about</font><font color="#CCCCCC"> later is how we might increase</font>

142
00:06:23,500 --> 00:06:26,770
that in the<font color="#E5E5E5"> future and some of the work</font>

143
00:06:25,180 --> 00:06:34,330
you were doing<font color="#CCCCCC"> would</font><font color="#E5E5E5"> work really well</font>

144
00:06:26,770 --> 00:06:37,389
<font color="#E5E5E5">with</font><font color="#CCCCCC"> that</font><font color="#E5E5E5"> right so so I could talk a bit</font>

145
00:06:34,330 --> 00:06:39,520
about the<font color="#E5E5E5"> scoring functions we really</font>

146
00:06:37,389 --> 00:06:40,140
want<font color="#E5E5E5"> to</font><font color="#CCCCCC"> discuss the scoring functions of</font>

147
00:06:39,520 --> 00:06:46,260
the community

148
00:06:40,140 --> 00:06:50,190
<font color="#E5E5E5">the kind of first stab they can be</font>

149
00:06:46,260 --> 00:06:53,400
approved<font color="#CCCCCC"> a great deal currently we're</font>

150
00:06:50,190 --> 00:06:56,219
<font color="#CCCCCC">looking at</font><font color="#E5E5E5"> context-free analysis</font><font color="#CCCCCC"> so</font>

151
00:06:53,400 --> 00:06:59,520
we're<font color="#E5E5E5"> looking at an event and events</font>

152
00:06:56,220 --> 00:07:05,550
attributes<font color="#CCCCCC"> with no</font><font color="#E5E5E5"> correlation of other</font>

153
00:06:59,520 --> 00:07:07,169
data within<font color="#CCCCCC"> less me saying a</font><font color="#E5E5E5"> few things</font>

154
00:07:05,550 --> 00:07:09,230
about this as well<font color="#CCCCCC"> so there's scoring</font>

155
00:07:07,170 --> 00:07:12,810
<font color="#E5E5E5">idea is essentially how do you translate</font>

156
00:07:09,230 --> 00:07:14,820
observables or iOS ease into<font color="#E5E5E5"> one of or</font>

157
00:07:12,810 --> 00:07:17,400
all three<font color="#E5E5E5"> of money manpower time and</font>

158
00:07:14,820 --> 00:07:19,560
it's<font color="#E5E5E5"> not as easy as it my team</font><font color="#CCCCCC"> right</font>

159
00:07:17,400 --> 00:07:21,539
<font color="#E5E5E5">like what</font><font color="#CCCCCC"> does</font><font color="#E5E5E5"> an ipv4 address worth to</font>

160
00:07:19,560 --> 00:07:23,820
an attacker<font color="#E5E5E5"> if an attacker switches for</font>

161
00:07:21,540 --> 00:07:26,880
<font color="#E5E5E5">one ipv4 address to another</font><font color="#CCCCCC"> what would</font>

162
00:07:23,820 --> 00:07:29,330
you say the cost is in<font color="#CCCCCC"> money come on be</font>

163
00:07:26,880 --> 00:07:33,240
interactive<font color="#E5E5E5"> I'm really exhausted</font>

164
00:07:29,330 --> 00:07:35,849
anybody fairly low right it's not it's

165
00:07:33,240 --> 00:07:37,110
not super hard<font color="#CCCCCC"> so I wanted to</font><font color="#E5E5E5"> put an</font>

166
00:07:35,850 --> 00:07:39,180
<font color="#CCCCCC">actual number on that and I</font><font color="#E5E5E5"> went digging</font>

167
00:07:37,110 --> 00:07:41,070
around<font color="#E5E5E5"> in ipv4 auctions and you can</font>

168
00:07:39,180 --> 00:07:43,290
basically buy a new ipv4 address for

169
00:07:41,070 --> 00:07:45,060
<font color="#CCCCCC">four bucks</font><font color="#E5E5E5"> so there's a number I</font><font color="#CCCCCC"> can</font><font color="#E5E5E5"> put</font>

170
00:07:43,290 --> 00:07:46,770
on it<font color="#E5E5E5"> right and we all agree that's not</font>

171
00:07:45,060 --> 00:07:49,470
<font color="#E5E5E5">the right number</font><font color="#CCCCCC"> but what I'm trying to</font>

172
00:07:46,770 --> 00:07:51,530
<font color="#E5E5E5">get here is</font><font color="#CCCCCC"> that we can put</font><font color="#E5E5E5"> a sort of</font>

173
00:07:49,470 --> 00:07:53,970
<font color="#CCCCCC">constant of scores on like how long</font>

174
00:07:51,530 --> 00:07:55,590
kilobyte<font color="#E5E5E5"> of binary takes to</font><font color="#CCCCCC"> write and</font>

175
00:07:53,970 --> 00:07:57,060
some<font color="#E5E5E5"> of you could go out and do further</font>

176
00:07:55,590 --> 00:07:59,190
research<font color="#E5E5E5"> on that which is what we want</font>

177
00:07:57,060 --> 00:08:00,660
to<font color="#E5E5E5"> talk</font><font color="#CCCCCC"> about</font><font color="#E5E5E5"> here but for now the point</font>

178
00:07:59,190 --> 00:08:02,400
is<font color="#CCCCCC"> that everybody</font><font color="#E5E5E5"> shares the same number</font>

179
00:08:00,660 --> 00:08:04,050
so when I was<font color="#E5E5E5"> in Center for risk studies</font>

180
00:08:02,400 --> 00:08:05,400
there was a brilliant counter<font color="#CCCCCC"> terrorism</font>

181
00:08:04,050 --> 00:08:08,190
risk professional<font color="#CCCCCC"> he's written a couple</font>

182
00:08:05,400 --> 00:08:10,169
books on the subject Gordon<font color="#E5E5E5"> whoo and and</font>

183
00:08:08,190 --> 00:08:13,469
he said<font color="#CCCCCC"> to me</font><font color="#E5E5E5"> all risks should be</font>

184
00:08:10,170 --> 00:08:15,090
<font color="#E5E5E5">comparable or all risks are comparable</font>

185
00:08:13,470 --> 00:08:16,980
or should<font color="#CCCCCC"> be</font><font color="#E5E5E5"> and I found that really</font>

186
00:08:15,090 --> 00:08:19,049
<font color="#E5E5E5">frustrating because</font><font color="#CCCCCC"> like you</font><font color="#E5E5E5"> know what</font>

187
00:08:16,980 --> 00:08:21,690
we do is special<font color="#E5E5E5"> it's different</font><font color="#CCCCCC"> it's</font>

188
00:08:19,050 --> 00:08:23,700
it's<font color="#E5E5E5"> not like other risks but if you've</font>

189
00:08:21,690 --> 00:08:25,380
really progressed in the risk world<font color="#E5E5E5"> then</font>

190
00:08:23,700 --> 00:08:27,030
you can be compared<font color="#CCCCCC"> to fire risk or you</font>

191
00:08:25,380 --> 00:08:28,710
can be compared to pandemic risk or you

192
00:08:27,030 --> 00:08:30,479
can be compared<font color="#E5E5E5"> to kidnapping ransom of</font>

193
00:08:28,710 --> 00:08:31,739
piracy<font color="#E5E5E5"> or whatever so that's the point</font>

194
00:08:30,480 --> 00:08:34,320
here<font color="#CCCCCC"> is by putting</font><font color="#E5E5E5"> some</font><font color="#CCCCCC"> of these numbers</font>

195
00:08:31,740 --> 00:08:35,909
<font color="#CCCCCC">on here all of these different apts and</font>

196
00:08:34,320 --> 00:08:37,770
all the different ransomware families

197
00:08:35,909 --> 00:08:39,240
can be compared<font color="#E5E5E5"> even if we know those</font>

198
00:08:37,770 --> 00:08:40,799
numbers<font color="#E5E5E5"> aren't exactly right the</font>

199
00:08:39,240 --> 00:08:42,570
constant is wrong for all<font color="#E5E5E5"> of them and we</font>

200
00:08:40,799 --> 00:08:46,160
<font color="#E5E5E5">can at least compare them so Bruce will</font>

201
00:08:42,570 --> 00:08:48,930
show you<font color="#E5E5E5"> more about how he achieved that</font>

202
00:08:46,160 --> 00:08:50,459
<font color="#E5E5E5">okay so the scoring</font><font color="#CCCCCC"> functions are kept</font>

203
00:08:48,930 --> 00:08:52,319
separate from<font color="#CCCCCC"> the mechanics so you don't</font>

204
00:08:50,460 --> 00:08:53,820
have to be an<font color="#E5E5E5"> expert</font>

205
00:08:52,320 --> 00:08:56,670
and how the mechanics work<font color="#E5E5E5"> to be able to</font>

206
00:08:53,820 --> 00:08:58,470
<font color="#E5E5E5">write scoring functions and as I said</font>

207
00:08:56,670 --> 00:09:01,050
<font color="#CCCCCC">before</font><font color="#E5E5E5"> the dump of</font><font color="#CCCCCC"> the attribute data</font><font color="#E5E5E5"> is</font>

208
00:08:58,470 --> 00:09:03,270
<font color="#E5E5E5">really useful</font><font color="#CCCCCC"> for</font><font color="#E5E5E5"> writing them that's</font>

209
00:09:01,050 --> 00:09:05,760
almost impossible<font color="#E5E5E5"> to read even for</font>

210
00:09:03,270 --> 00:09:08,010
<font color="#CCCCCC">myself</font><font color="#E5E5E5"> so but it's basically just a</font>

211
00:09:05,760 --> 00:09:11,910
really<font color="#CCCCCC"> simple piece</font><font color="#E5E5E5"> of Python that takes</font>

212
00:09:08,010 --> 00:09:14,569
in<font color="#E5E5E5"> event and the corresponding</font>

213
00:09:11,910 --> 00:09:18,150
attributes<font color="#E5E5E5"> and scan through</font><font color="#CCCCCC"> and</font>

214
00:09:14,570 --> 00:09:25,350
<font color="#E5E5E5">accumulates based on the attribute data</font>

215
00:09:18,150 --> 00:09:28,140
<font color="#E5E5E5">and then returns the score if you have a</font>

216
00:09:25,350 --> 00:09:29,730
URL it's got this much time to manage or

217
00:09:28,140 --> 00:09:31,620
this much money<font color="#CCCCCC"> if you've got an IP</font>

218
00:09:29,730 --> 00:09:33,510
address<font color="#E5E5E5"> it's worth this you get the idea</font>

219
00:09:31,620 --> 00:09:35,520
if you've got a binary<font color="#E5E5E5"> and it's of this</font>

220
00:09:33,510 --> 00:09:37,050
size then<font color="#CCCCCC"> you have some idea of like</font><font color="#E5E5E5"> how</font>

221
00:09:35,520 --> 00:09:40,680
<font color="#E5E5E5">much time the thread actor put into it</font>

222
00:09:37,050 --> 00:09:43,130
so<font color="#CCCCCC"> that's all</font><font color="#E5E5E5"> there and that could so</font>

223
00:09:40,680 --> 00:09:45,180
the<font color="#CCCCCC"> scorecards that I mentioned before</font>

224
00:09:43,130 --> 00:09:47,340
<font color="#CCCCCC">looks something like this so we're</font>

225
00:09:45,180 --> 00:09:51,180
trying<font color="#E5E5E5"> to estimate the organization size</font>

226
00:09:47,340 --> 00:09:56,700
and the amount that they're<font color="#E5E5E5"> spending in</font>

227
00:09:51,180 --> 00:10:00,000
<font color="#E5E5E5">for on infrastructure</font><font color="#CCCCCC"> the estimated</font><font color="#E5E5E5"> time</font>

228
00:09:56,700 --> 00:10:05,460
investment<font color="#CCCCCC"> and this is we're</font><font color="#E5E5E5"> going to</font>

229
00:10:00,000 --> 00:10:07,980
<font color="#E5E5E5">compare Dharma and want to cry</font><font color="#CCCCCC"> and you</font>

230
00:10:05,460 --> 00:10:13,560
can see we're giving some fuzziness to

231
00:10:07,980 --> 00:10:17,490
the to the actual<font color="#E5E5E5"> results but if we look</font>

232
00:10:13,560 --> 00:10:24,270
at<font color="#E5E5E5"> one a cry much bigger organization</font>

233
00:10:17,490 --> 00:10:26,850
size<font color="#CCCCCC"> spend and time investment so these</font>

234
00:10:24,270 --> 00:10:29,579
should<font color="#E5E5E5"> be noted these are</font><font color="#CCCCCC"> log graphs of</font>

235
00:10:26,850 --> 00:10:35,460
the<font color="#CCCCCC"> tics or a little bit disingenuous</font>

236
00:10:29,580 --> 00:10:37,560
but<font color="#E5E5E5"> they're</font><font color="#CCCCCC"> for different</font><font color="#E5E5E5"> score</font><font color="#CCCCCC"> cards</font>

237
00:10:35,460 --> 00:10:39,180
and that's important because some threat

238
00:10:37,560 --> 00:10:40,770
actors<font color="#E5E5E5"> operate it at like an insane</font>

239
00:10:39,180 --> 00:10:43,050
scale so like you look at the number<font color="#CCCCCC"> of</font>

240
00:10:40,770 --> 00:10:45,030
URLs involved in a sofa<font color="#CCCCCC"> C campaign and</font>

241
00:10:43,050 --> 00:10:46,530
it's just extreme so you have to do some

242
00:10:45,030 --> 00:10:48,449
of these things<font color="#CCCCCC"> on a log scale</font><font color="#E5E5E5"> right and</font>

243
00:10:46,530 --> 00:10:49,589
the score<font color="#E5E5E5"> across the</font><font color="#CCCCCC"> bottom for those of</font>

244
00:10:48,450 --> 00:10:51,810
you who can't read all<font color="#CCCCCC"> of these it's</font>

245
00:10:49,590 --> 00:10:53,760
estimated organizational size at the top

246
00:10:51,810 --> 00:10:55,709
<font color="#E5E5E5">that's the other one infrastructure</font>

247
00:10:53,760 --> 00:10:58,200
spend so the amount of<font color="#E5E5E5"> money is the red</font>

248
00:10:55,710 --> 00:11:00,150
one<font color="#CCCCCC"> time is the blue one and the</font><font color="#E5E5E5"> last</font>

249
00:10:58,200 --> 00:11:01,620
<font color="#E5E5E5">one that's in black is basically the</font>

250
00:11:00,150 --> 00:11:03,449
aggregation<font color="#E5E5E5"> of those three different</font>

251
00:11:01,620 --> 00:11:05,010
scores<font color="#E5E5E5"> right so if we click back</font><font color="#CCCCCC"> and</font>

252
00:11:03,450 --> 00:11:06,089
<font color="#E5E5E5">forth between these two you</font><font color="#CCCCCC"> just get the</font>

253
00:11:05,010 --> 00:11:07,379
<font color="#E5E5E5">idea that</font>

254
00:11:06,089 --> 00:11:09,660
<font color="#CCCCCC">Dharma probably spent less money</font>

255
00:11:07,379 --> 00:11:10,800
<font color="#E5E5E5">manpower and time than wanna cry and</font>

256
00:11:09,660 --> 00:11:12,809
<font color="#CCCCCC">that's all we really</font><font color="#E5E5E5"> wanted to do with</font>

257
00:11:10,800 --> 00:11:14,128
<font color="#E5E5E5">this but of</font><font color="#CCCCCC"> course you don't have to do</font>

258
00:11:12,809 --> 00:11:16,740
this<font color="#E5E5E5"> just</font><font color="#CCCCCC"> for ransomware you can do it</font>

259
00:11:14,129 --> 00:11:19,050
for<font color="#E5E5E5"> other things too</font><font color="#CCCCCC"> right so we also do</font>

260
00:11:16,740 --> 00:11:23,220
this<font color="#E5E5E5"> for the threat actors so we hit</font>

261
00:11:19,050 --> 00:11:31,109
here we have energetic bear<font color="#CCCCCC"> and equation</font>

262
00:11:23,220 --> 00:11:35,249
group<font color="#CCCCCC"> and then we have heat maps that we</font>

263
00:11:31,110 --> 00:11:40,499
generated<font color="#E5E5E5"> for the threat actors so this</font>

264
00:11:35,249 --> 00:11:45,689
is taking<font color="#CCCCCC"> threat actor events 15 bins of</font>

265
00:11:40,499 --> 00:11:49,949
30 days and then ranking them based on

266
00:11:45,689 --> 00:11:55,399
their aggregate score<font color="#CCCCCC"> so</font><font color="#E5E5E5"> we can get some</font>

267
00:11:49,949 --> 00:12:01,229
nice idea of bright points and

268
00:11:55,399 --> 00:12:10,639
corresponding dates<font color="#CCCCCC"> we can also do the</font>

269
00:12:01,230 --> 00:12:16,459
<font color="#E5E5E5">same</font><font color="#CCCCCC"> for weekly plots</font><font color="#E5E5E5"> 15 bins this is</font>

270
00:12:10,639 --> 00:12:19,399
the event but scaled based on their

271
00:12:16,459 --> 00:12:22,258
threat<font color="#E5E5E5"> levels so the high gets a</font>

272
00:12:19,399 --> 00:12:25,800
significantly higher score than<font color="#E5E5E5"> a medium</font>

273
00:12:22,259 --> 00:12:27,839
or low and we<font color="#E5E5E5"> didn't</font><font color="#CCCCCC"> want to put like</font>

274
00:12:25,800 --> 00:12:29,279
<font color="#E5E5E5">200 of these heat maps in here but we</font>

275
00:12:27,839 --> 00:12:31,019
can do them not just for<font color="#E5E5E5"> events we</font><font color="#CCCCCC"> can</font>

276
00:12:29,279 --> 00:12:33,059
also do<font color="#E5E5E5"> them for binaries or for</font>

277
00:12:31,019 --> 00:12:35,610
networks or for files<font color="#E5E5E5"> or for</font><font color="#CCCCCC"> whatever</font>

278
00:12:33,059 --> 00:12:37,019
<font color="#E5E5E5">and then we worked on a sort of scoring</font>

279
00:12:35,610 --> 00:12:38,939
function that<font color="#E5E5E5"> took all</font><font color="#CCCCCC"> of those into</font>

280
00:12:37,019 --> 00:12:41,249
<font color="#CCCCCC">account and made one</font><font color="#E5E5E5"> now it's worth</font>

281
00:12:38,939 --> 00:12:43,439
pointing<font color="#E5E5E5"> out here</font><font color="#CCCCCC"> that</font><font color="#E5E5E5"> the time bin</font>

282
00:12:41,249 --> 00:12:44,670
across the<font color="#E5E5E5"> bottom is detection time and</font>

283
00:12:43,439 --> 00:12:46,980
we all know that<font color="#CCCCCC"> dwell time can be</font>

284
00:12:44,670 --> 00:12:49,529
really high so I don't take the<font color="#E5E5E5"> time</font>

285
00:12:46,980 --> 00:12:52,139
<font color="#E5E5E5">line of</font><font color="#CCCCCC"> this entirely seriously</font><font color="#E5E5E5"> but I do</font>

286
00:12:49,529 --> 00:12:53,699
take the heat map to be<font color="#CCCCCC"> of interest</font><font color="#E5E5E5"> so</font>

287
00:12:52,139 --> 00:12:54,899
what I'm trying<font color="#CCCCCC"> to say there is</font><font color="#E5E5E5"> that you</font>

288
00:12:53,699 --> 00:12:56,998
know<font color="#CCCCCC"> this little</font><font color="#E5E5E5"> white spot here for</font>

289
00:12:54,899 --> 00:13:00,209
<font color="#CCCCCC">sofa C might have actually occurred</font><font color="#E5E5E5"> a</font>

290
00:12:56,999 --> 00:13:01,920
<font color="#E5E5E5">time</font><font color="#CCCCCC"> bin before</font><font color="#E5E5E5"> or before that in terms</font>

291
00:13:00,209 --> 00:13:03,719
of when the attack occurred<font color="#CCCCCC"> so this is</font>

292
00:13:01,920 --> 00:13:05,579
detection<font color="#E5E5E5"> time but it still it still</font>

293
00:13:03,720 --> 00:13:08,100
<font color="#E5E5E5">lets us know that</font><font color="#CCCCCC"> there was a lot more</font>

294
00:13:05,579 --> 00:13:10,258
<font color="#E5E5E5">indicators in that time period</font><font color="#CCCCCC"> that we</font>

295
00:13:08,100 --> 00:13:12,029
could use for<font color="#E5E5E5"> something so yeah this is</font>

296
00:13:10,259 --> 00:13:14,370
<font color="#E5E5E5">an idea of the code that Bruce is</font>

297
00:13:12,029 --> 00:13:16,049
<font color="#E5E5E5">written and we've made open source on</font>

298
00:13:14,370 --> 00:13:17,730
github

299
00:13:16,049 --> 00:13:19,860
we have other ideas of<font color="#E5E5E5"> how</font><font color="#CCCCCC"> we can</font>

300
00:13:17,730 --> 00:13:22,439
<font color="#E5E5E5">visualize like perhaps you would do</font>

301
00:13:19,860 --> 00:13:24,929
<font color="#E5E5E5">treemap sort of structure where the the</font>

302
00:13:22,439 --> 00:13:27,449
files will<font color="#CCCCCC"> be on one side</font><font color="#E5E5E5"> and like you</font>

303
00:13:24,929 --> 00:13:30,238
know the<font color="#E5E5E5"> the</font><font color="#CCCCCC"> network indicators</font><font color="#E5E5E5"> would be</font>

304
00:13:27,449 --> 00:13:32,248
on the other or we<font color="#CCCCCC"> can do heat maps for</font>

305
00:13:30,239 --> 00:13:34,439
ransomware<font color="#E5E5E5"> we've got a lot</font><font color="#CCCCCC"> of</font><font color="#E5E5E5"> ideas</font>

306
00:13:32,249 --> 00:13:36,749
about<font color="#CCCCCC"> how to visualize this data but we</font>

307
00:13:34,439 --> 00:13:38,519
probably need a little<font color="#CCCCCC"> bit</font><font color="#E5E5E5"> of help</font><font color="#CCCCCC"> and</font>

308
00:13:36,749 --> 00:13:39,629
then we want<font color="#E5E5E5"> to talk a lot</font><font color="#CCCCCC"> about scoring</font>

309
00:13:38,519 --> 00:13:42,269
functions so if you know<font color="#E5E5E5"> that there's</font>

310
00:13:39,629 --> 00:13:43,920
<font color="#CCCCCC">academic work</font><font color="#E5E5E5"> estimating the amount</font><font color="#CCCCCC"> of</font>

311
00:13:42,269 --> 00:13:46,319
time that<font color="#E5E5E5"> went</font><font color="#CCCCCC"> into a binary based</font><font color="#E5E5E5"> on</font>

312
00:13:43,920 --> 00:13:48,479
how many kilobytes it is or how much

313
00:13:46,319 --> 00:13:50,998
<font color="#E5E5E5">network infrastructure costs for</font>

314
00:13:48,480 --> 00:13:52,799
attackers<font color="#E5E5E5"> or so on</font><font color="#CCCCCC"> I'm also giving</font><font color="#E5E5E5"> a</font>

315
00:13:50,999 --> 00:13:54,059
talk tomorrow about ransomware<font color="#CCCCCC"> well</font>

316
00:13:52,799 --> 00:13:55,889
you'll see a little<font color="#E5E5E5"> bit more about where</font>

317
00:13:54,059 --> 00:13:59,100
some<font color="#E5E5E5"> of this came from and some of that</font>

318
00:13:55,889 --> 00:14:01,889
work is replicated there<font color="#E5E5E5"> in terms of how</font>

319
00:13:59,100 --> 00:14:11,489
much an incident costs by comparison<font color="#E5E5E5"> to</font>

320
00:14:01,889 --> 00:14:15,470
how much attackers made in ransoms<font color="#E5E5E5"> maybe</font>

321
00:14:11,489 --> 00:14:18,860
everything that you said<font color="#E5E5E5"> oh can</font><font color="#CCCCCC"> we use</font>

322
00:14:15,470 --> 00:14:25,709
unattributed<font color="#E5E5E5"> mess data in our</font>

323
00:14:18,860 --> 00:14:29,389
<font color="#E5E5E5">visualizations how does the community</font>

324
00:14:25,709 --> 00:14:32,388
feel about this how do you feel like

325
00:14:29,389 --> 00:14:32,389
<font color="#CCCCCC">sended</font>

326
00:14:35,880 --> 00:14:44,370
<font color="#CCCCCC">I mean</font><font color="#E5E5E5"> so this wasn't super expensive</font>

327
00:14:42,480 --> 00:14:46,080
<font color="#E5E5E5">like Bruce works really hard and he's</font>

328
00:14:44,370 --> 00:14:48,150
got a new company but like like I said

329
00:14:46,080 --> 00:14:51,030
this is<font color="#CCCCCC"> my speaker fees for a couple</font>

330
00:14:48,150 --> 00:14:52,560
months<font color="#E5E5E5"> right and I'm really glad about</font>

331
00:14:51,030 --> 00:14:54,480
<font color="#E5E5E5">that but we do think it could go a lot</font>

332
00:14:52,560 --> 00:14:56,099
further<font color="#E5E5E5"> so if you're</font><font color="#CCCCCC"> interested or you</font>

333
00:14:54,480 --> 00:14:57,450
have time<font color="#E5E5E5"> we don't</font><font color="#CCCCCC"> necessarily</font><font color="#E5E5E5"> need</font>

334
00:14:56,100 --> 00:15:00,510
money we also<font color="#E5E5E5"> just need</font><font color="#CCCCCC"> people to</font>

335
00:14:57,450 --> 00:15:02,190
<font color="#E5E5E5">contribute so you know we could just</font>

336
00:15:00,510 --> 00:15:03,180
<font color="#E5E5E5">give</font><font color="#CCCCCC"> it to you guys</font><font color="#E5E5E5"> and</font><font color="#CCCCCC"> you can</font><font color="#E5E5E5"> do</font>

337
00:15:02,190 --> 00:15:05,100
something<font color="#CCCCCC"> with it if you want that's</font>

338
00:15:03,180 --> 00:15:07,439
fine<font color="#E5E5E5"> too</font><font color="#CCCCCC"> but I'm also interested</font><font color="#E5E5E5"> in the</font>

339
00:15:05,100 --> 00:15:09,360
reaction from the<font color="#E5E5E5"> community like is this</font>

340
00:15:07,440 --> 00:15:10,920
total BS because<font color="#E5E5E5"> it's based on money</font>

341
00:15:09,360 --> 00:15:12,120
manpower<font color="#CCCCCC"> and time and</font><font color="#E5E5E5"> you don't like the</font>

342
00:15:10,920 --> 00:15:13,439
scoring function or do you actually

343
00:15:12,120 --> 00:15:15,750
think<font color="#CCCCCC"> this is useful</font><font color="#E5E5E5"> would you sit</font>

344
00:15:13,440 --> 00:15:21,510
<font color="#CCCCCC">around comparing apt groups</font><font color="#E5E5E5"> and</font>

345
00:15:15,750 --> 00:15:22,680
<font color="#E5E5E5">ransomware no I mean from</font><font color="#CCCCCC"> I think</font><font color="#E5E5E5"> from</font>

346
00:15:21,510 --> 00:15:23,850
our<font color="#E5E5E5"> perspective</font><font color="#CCCCCC"> it looks really</font>

347
00:15:22,680 --> 00:15:25,020
<font color="#CCCCCC">interesting</font><font color="#E5E5E5"> and maybe something that</font>

348
00:15:23,850 --> 00:15:27,990
<font color="#E5E5E5">could</font><font color="#CCCCCC"> be interesting as</font><font color="#E5E5E5"> well as</font>

349
00:15:25,020 --> 00:15:30,480
<font color="#E5E5E5">especially once you're refining your</font>

350
00:15:27,990 --> 00:15:31,710
<font color="#E5E5E5">scoring for the different types after a</font>

351
00:15:30,480 --> 00:15:33,300
while would you be interested<font color="#E5E5E5"> for</font>

352
00:15:31,710 --> 00:15:35,700
example in feeding the<font color="#E5E5E5"> data back into</font>

353
00:15:33,300 --> 00:15:38,790
<font color="#E5E5E5">the</font><font color="#CCCCCC"> frittata</font><font color="#E5E5E5"> galaxies because</font><font color="#CCCCCC"> this would</font>

354
00:15:35,700 --> 00:15:41,100
I think would be very valuable<font color="#E5E5E5"> for the</font>

355
00:15:38,790 --> 00:15:42,839
community out there to get<font color="#CCCCCC"> the cigarette</font>

356
00:15:41,100 --> 00:15:44,750
<font color="#CCCCCC">and then</font><font color="#E5E5E5"> for further developments we can</font>

357
00:15:42,840 --> 00:15:46,560
we<font color="#E5E5E5"> can</font><font color="#CCCCCC"> issue we should talk about</font><font color="#E5E5E5"> this</font>

358
00:15:44,750 --> 00:15:48,000
yeah that's the other<font color="#E5E5E5"> thing so we have</font>

359
00:15:46,560 --> 00:15:50,280
<font color="#CCCCCC">we basically have a bigger research</font>

360
00:15:48,000 --> 00:15:52,380
<font color="#E5E5E5">ongoing</font><font color="#CCCCCC"> for</font><font color="#E5E5E5"> the exploration of</font>

361
00:15:50,280 --> 00:15:53,819
indicators and we're looking<font color="#E5E5E5"> at</font>

362
00:15:52,380 --> 00:15:55,680
<font color="#CCCCCC">different components and different</font>

363
00:15:53,820 --> 00:15:57,030
things that<font color="#E5E5E5"> we can take into account so</font>

364
00:15:55,680 --> 00:15:57,420
<font color="#CCCCCC">which we could work</font><font color="#E5E5E5"> together on that as</font>

365
00:15:57,030 --> 00:16:03,089
well

366
00:15:57,420 --> 00:16:05,719
so yes I think there's another question

367
00:16:03,090 --> 00:16:05,720
<font color="#E5E5E5">back</font><font color="#CCCCCC"> here</font>

368
00:16:33,420 --> 00:16:36,020
yeah

369
00:16:36,399 --> 00:16:41,209
exactly so I'll repeat<font color="#E5E5E5"> the question</font><font color="#CCCCCC"> for</font>

370
00:16:39,140 --> 00:16:42,890
<font color="#E5E5E5">the cameras as I'm supposed</font><font color="#CCCCCC"> to even</font>

371
00:16:41,209 --> 00:16:43,880
though<font color="#E5E5E5"> I'm tired I remember the rules of</font>

372
00:16:42,890 --> 00:16:46,339
Cooper

373
00:16:43,880 --> 00:16:48,560
so essentially software<font color="#E5E5E5"> development</font>

374
00:16:46,339 --> 00:16:49,670
houses have that data already<font color="#E5E5E5"> and that's</font>

375
00:16:48,560 --> 00:16:51,018
<font color="#E5E5E5">the sort of thing that we should be</font>

376
00:16:49,670 --> 00:16:52,310
incorporating so once they've written a

377
00:16:51,019 --> 00:16:54,019
<font color="#E5E5E5">piece of software you could look at it</font>

378
00:16:52,310 --> 00:16:55,640
and work backwards and<font color="#E5E5E5"> say how many</font>

379
00:16:54,019 --> 00:16:58,820
<font color="#CCCCCC">people did you have on this</font><font color="#E5E5E5"> project for</font>

380
00:16:55,640 --> 00:17:01,399
<font color="#E5E5E5">how long</font><font color="#CCCCCC"> and how much did it cost and so</font>

381
00:16:58,820 --> 00:17:03,410
on<font color="#E5E5E5"> now the costing would</font><font color="#CCCCCC"> be the one I</font>

382
00:17:01,399 --> 00:17:05,750
would<font color="#E5E5E5"> question in terms of timing</font>

383
00:17:03,410 --> 00:17:07,399
that's probably<font color="#E5E5E5"> all</font><font color="#CCCCCC"> very accurate when</font>

384
00:17:05,750 --> 00:17:10,510
<font color="#E5E5E5">you can</font><font color="#CCCCCC"> player</font><font color="#E5E5E5"> malware and you compare</font>

385
00:17:07,400 --> 00:17:12,920
<font color="#E5E5E5">standard software</font><font color="#CCCCCC"> but in terms of</font><font color="#E5E5E5"> money</font>

386
00:17:10,510 --> 00:17:15,260
<font color="#CCCCCC">it might not be the same pay structure</font>

387
00:17:12,920 --> 00:17:17,360
<font color="#E5E5E5">and the underground</font><font color="#CCCCCC"> economy right</font><font color="#E5E5E5"> people</font>

388
00:17:15,260 --> 00:17:19,910
might be coding for a share of the<font color="#CCCCCC"> brand</font>

389
00:17:17,359 --> 00:17:21,079
<font color="#CCCCCC">some of</font><font color="#E5E5E5"> our profits or you know they</font>

390
00:17:19,910 --> 00:17:22,939
might<font color="#CCCCCC"> be</font><font color="#E5E5E5"> stealing other people's code</font>

391
00:17:21,079 --> 00:17:24,649
before<font color="#CCCCCC"> they get started there's a lot of</font>

392
00:17:22,939 --> 00:17:26,240
details in there but but<font color="#E5E5E5"> I absolutely</font>

393
00:17:24,650 --> 00:17:30,650
take your point the traditional software

394
00:17:26,240 --> 00:17:32,600
<font color="#CCCCCC">development studies are useful to this</font>

395
00:17:30,650 --> 00:17:33,650
<font color="#E5E5E5">and we didn't dig that deep into</font><font color="#CCCCCC"> this</font>

396
00:17:32,600 --> 00:17:34,730
<font color="#E5E5E5">because we just</font><font color="#CCCCCC"> wanted</font><font color="#E5E5E5"> the proof of</font>

397
00:17:33,650 --> 00:17:36,800
<font color="#E5E5E5">concept where</font><font color="#CCCCCC"> we could show you the</font>

398
00:17:34,730 --> 00:17:38,230
visualization first and then we could

399
00:17:36,800 --> 00:17:40,370
deep dive on each of those numbers

400
00:17:38,230 --> 00:17:43,610
<font color="#E5E5E5">especially if we</font><font color="#CCCCCC"> can get you</font><font color="#E5E5E5"> interested</font>

401
00:17:40,370 --> 00:17:45,879
to help<font color="#E5E5E5"> us with that so great idea next</font>

402
00:17:43,610 --> 00:17:45,879
question

403
00:17:52,790 --> 00:17:55,690
<font color="#E5E5E5">okay</font>

404
00:18:18,270 --> 00:18:37,900
yes so the the comment is<font color="#E5E5E5"> essentially</font>

405
00:18:35,440 --> 00:18:40,890
<font color="#E5E5E5">about</font><font color="#CCCCCC"> the associativity of tags inside</font>

406
00:18:37,900 --> 00:18:40,890
<font color="#CCCCCC">Misbah vents</font>

407
00:19:17,430 --> 00:19:21,490
yeah of<font color="#E5E5E5"> course I mean the more that the</font>

408
00:19:19,840 --> 00:19:24,040
correlation engines run<font color="#E5E5E5"> underneath the</font>

409
00:19:21,490 --> 00:19:25,540
more that we will have<font color="#E5E5E5"> possible to</font>

410
00:19:24,040 --> 00:19:27,760
visualize<font color="#E5E5E5"> right especially if you're</font>

411
00:19:25,540 --> 00:19:29,800
enriching events<font color="#CCCCCC"> where like</font><font color="#E5E5E5"> you happen</font>

412
00:19:27,760 --> 00:19:32,320
to know<font color="#E5E5E5"> this domain and this domain are</font>

413
00:19:29,800 --> 00:19:34,649
<font color="#E5E5E5">linked by Whois data and then it grows</font>

414
00:19:32,320 --> 00:19:34,649
right

415
00:20:06,590 --> 00:20:12,060
yes<font color="#CCCCCC"> I mean we know that we have a naming</font>

416
00:20:09,180 --> 00:20:14,850
convention problem for ransomware<font color="#E5E5E5"> and a</font>

417
00:20:12,060 --> 00:20:16,020
PT's<font color="#CCCCCC"> because it's essentially marketing</font>

418
00:20:14,850 --> 00:20:21,899
reports that we get most of<font color="#E5E5E5"> this</font>

419
00:20:16,020 --> 00:20:23,190
<font color="#E5E5E5">information from which is yes</font><font color="#CCCCCC"> in fact I</font>

420
00:20:21,900 --> 00:20:25,380
would counter this<font color="#E5E5E5"> entire conversation</font>

421
00:20:23,190 --> 00:20:27,480
with the fact that<font color="#E5E5E5"> you can run our code</font>

422
00:20:25,380 --> 00:20:29,850
on your<font color="#CCCCCC"> missing instance so</font><font color="#E5E5E5"> if your</font>

423
00:20:27,480 --> 00:20:32,490
confidence<font color="#CCCCCC"> in your misclassifications</font><font color="#E5E5E5"> is</font>

424
00:20:29,850 --> 00:20:35,159
better then you can do the visualization

425
00:20:32,490 --> 00:20:42,420
on your data that's why we wrote<font color="#E5E5E5"> it this</font>

426
00:20:35,160 --> 00:21:06,510
way so yeah any other questions or

427
00:20:42,420 --> 00:21:09,600
comments<font color="#E5E5E5"> yeah yeah I mean you did some</font>

428
00:21:06,510 --> 00:21:14,370
<font color="#CCCCCC">lightweight</font><font color="#E5E5E5"> analysis in that sort of</font>

429
00:21:09,600 --> 00:21:16,560
area<font color="#E5E5E5"> but not not in a scientifically</font>

430
00:21:14,370 --> 00:21:19,110
rigorous way and it's absolutely

431
00:21:16,560 --> 00:21:20,820
<font color="#E5E5E5">something we'd like to do it's just we</font>

432
00:21:19,110 --> 00:21:22,590
wanted<font color="#E5E5E5"> to prove the concept</font><font color="#CCCCCC"> with the</font>

433
00:21:20,820 --> 00:21:23,820
visualization<font color="#CCCCCC"> and then talk to people</font>

434
00:21:22,590 --> 00:21:26,220
about<font color="#E5E5E5"> how to do that so if you're</font>

435
00:21:23,820 --> 00:21:28,050
<font color="#E5E5E5">interested we'd love your help and I</font>

436
00:21:26,220 --> 00:21:32,830
think<font color="#CCCCCC"> I have to wrap up for</font><font color="#E5E5E5"> the next</font>

437
00:21:28,050 --> 00:21:38,389
speakers that's it from us

438
00:21:32,830 --> 00:21:38,389
[Applause]


