Collating Threat Intelligence for Zero Trust Future Using Open-Source Tools
Piyush John, Siva Suryanarayana Nittala, Suresh Chandanapalli · River Publishers eBooks · 2022
Organizations are taking the leap of faith with respect to digital adoption, oblivious to the perils of this journey. With the advancements in Big Data, it becomes vital to ensure that we are safeguarding our digital footprints. The ever-evolving IT landscape and the volatility, uncertainty, complexity, and ambiguity (VUCA) world makes it harder to be at the forefront and has shifted the focus to a perimeter-less architecture ensuring a Zero Trust Future. In recent times, there has been a growing interest in security and information protection for data across organizations. IT ecosystems encompass valuable data and resources that must be protected from attackers. Security experts often use honeypots and honeynets to protect network systems. Honeypot is an outstanding technology that security experts use to tap new hacking techniques from attackers and intruders. The project results show how open-source technologies can be used dynamically to add or modify hacking incidents in a research Honeynet system. The chapter outlines strategies for making honeypots more attractive for hackers to spend more time to provide hacking evidence. Threat intelligence is gathered to understand the emerging threat landscape and build resilience leading toward addressing threat and trust centric architecture for any enterprise. Additionally, this can be used for understanding the psyche of hackers to build intelligence to interpret threat behavior. Organizations with leaner budgets can build their strategy around these learnings for their first line of defense.