tl;dr we have a synthetic dataset not correlated to actual attacks and we stand behind misleading people #DBIRhttp://blog.kennasecurity.com/2016/05/collaborative-data-science-inside-the-2016-verizon-dbir-vulnerability-section/ …
-
-
Replying to @dguido
"We scan for open vulns, successful exploitation is whenever a bunch of sensors triggers on them later"pic.twitter.com/3guK2RGICK
2 replies 7 retweets 4 likes -
Replying to @dguido
Using IDS sigs for successful exploitation is the kind of statistic that only a data scientist could love!
2 replies 10 retweets 8 likes -
Replying to @dguido
Kenna's top10 vulns match up to the top triggered sigs on every Snort install ever.pic.twitter.com/7z4W7LLo3p
2 replies 16 retweets 15 likes -
Replying to @dguido
That should have been a major hint that they weren't measuring anything at all, but somehow...pic.twitter.com/AAOneIzBws
1 reply 2 retweets 2 likes -
Replying to @dguido
If you missed that, Kenna thinks attackers are successfully exploiting FREAK and an RDP DoS and so you should prioritize them above new CVEs
2 replies 6 retweets 3 likes -
Replying to @dguido
This dataset and their analysis is misleading and harmful. Enterprises that follow that advice are worse off after reading it.
1 reply 7 retweets 3 likes -
Replying to @dguido
Dan Guido Retweeted thaddeus e. grugq
There's a total disconnect between real incident data and Kenna's synthetic dataset, here's another take on it:https://twitter.com/thegrugq/status/727002988250730496 …
Dan Guido added,
1 reply 5 retweets 1 like
Dan Guido Retweeted thaddeus e. grugq
Microsoft is combining crash data with on-host agent data here. They can track process execution. This data is REAL:https://twitter.com/thegrugq/status/727002988250730496 …
Dan Guido added,
-
-
Replying to @dguido
It still confuses me why Verizon didn't use their own incident data for tracking successful exploitation. It's concrete and reliable.
1 reply 3 retweets 1 like -
Replying to @dguido
If there are issues with quantity, then get your collaborators to improve their data collection until it's statistically reliable!
1 reply 1 retweet 0 likes - 3 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.