<
Loading Session...

Fail frequently to avoid disaster, or how to organically build a threat intel sharing standard

Session Information

Designing a successful standard for threat intel sharing is a daunting task, with a host of possible pitfalls. This talk aims to describe the journey, challenges and mistakes the MISP Project made while designing the MISP standard as we know it today. There are several paths that can lead to a well defined standard: early and prolonged requirement gathering versus starting small with rapid iterations, democratic and centralised driving forces, inclusive and exclusive ideologies. Our weapon of choice was an implementation driven, rapid iterative and real-world usage centric approach using the PMF methodology, which allowed us to experiment and fail often but also be aware of our failures before they became unrevokable disasters.

The speaker will attempt to compare and contrast the various methodologies and what lessons we've learned.

07 Dec 2017 11:00 AM - 11:45 AM(America/Chicago)
Venue : Bohemia Ballroom
20171207T1100 20171207T1145 America/Chicago Fail frequently to avoid disaster, or how to organically build a threat intel sharing standard

Designing a successful standard for threat intel sharing is a daunting task, with a host of possible pitfalls. This talk aims to describe the journey, challenges and mistakes the MISP Project made while designing the MISP standard as we know it today. There are several paths that can lead to a well defined standard: early and prolonged requirement gathering versus starting small with rapid iterations, democratic and centralised driving forces, inclusive and exclusive ideologies. Our weapon of choice was an implementation driven, rapid iterative and real-world usage centric approach using the PMF methodology, which allowed us to experiment and fail often but also be aware of our failures before they became unrevokable disasters. The speaker will attempt to compare and contrast the various methodologies and what lessons we've learned.

Bohemia Ballroom Borderless Cyber Conference and Technical Symposium / 6-8 Dec 2017 / Prague events@oasis-open.org
321 visits

Session Participants

User Online
Session speakers, moderators & attendees
Security Researcher
,
CIRCL (Computer Incident Response Center Luxembourg)
Core Team Member, MISP Project
,
CIRCL
Moderators public profile is disabled.
Attendees public profile is disabled.
14 attendees saved this session

Session Chat

Live Chat
Chat with participants attending this session

Questions & Answers

Answered
Submit questions for the presenters

Session Polls

Active
Participate in live polls

Need Help?

Technical Issues?

If you're experiencing playback problems, try adjusting the quality or refreshing the page.

Questions for Speakers?

Use the Q&A tab to submit questions that may be addressed in follow-up sessions.