Cyberstudy
PDF p.26 In progress

Attributes of Threat Actors

Open PDF at p.26 15 flashcards

Summary

PDF p.26

Modern cybersecurity threats require profiling threat actors based on their attributes, including access level, sophistication, resources, and motivation. This helps in understanding and mitigating potential attacks.

In plain words

Supplementary — not from your PDF

Threat actors are described by whether they're already inside (internal or external), how skilled they are (sophistication), and how much money and people they have (resources).

Detailed explanation

PDF p.26
  • Internal/External
    • Definition: Refers to the degree of access a threat actor has before initiating an attack.
    • External Threat Actor: No authorized access; must infiltrate the system (e.g., hacking, physical break-in). Can attack remotely or on-premises.
    • Internal/Insider Threat Actor: Has authorized access (e.g., employees, contractors, business partners).
  • Level of Sophistication/Capability
    • Definition: The ability of a threat actor to use advanced exploit techniques and tools.
    • Low Sophistication: Uses widely available commodity attack tools.
    • High Sophistication: Creates new exploits in systems and may use non-cyber tools (e.g., political, military assets).
  • Resources/Funding
    • Definition: The support needed for a threat actor's capabilities.
    • Requirements: Customized attack tools, skilled personnel (strategists, designers, coders, hackers, social engineers).
    • Funding Sources: Nation-states, organized crime.

Important terms

taken from the text above
Internal/External
Refers to the degree of access a threat actor has before initiating an attack.
External Threat Actor
No authorized access; must infiltrate the system (e.g., hacking, physical break-in). Can attack remotely or on-premises.
Internal/Insider Threat Actor
Has authorized access (e.g., employees, contractors, business partners).
Level of Sophistication/Capability
The ability of a threat actor to use advanced exploit techniques and tools.
Low Sophistication
Uses widely available commodity attack tools.
High Sophistication
Creates new exploits in systems and may use non-cyber tools (e.g., political, military assets).
Resources/Funding
The support needed for a threat actor's capabilities.
Funding Sources
Nation-states, organized crime.

Examples & real-world scenarios

Supplementary — not from your PDF
  • External, low sophistication: someone using a ready-made tool found online.
  • Internal: a contractor with legitimate access to the network.
  • High resources: a team with custom tools, funded by a government or a crime group.

Scenario

After an incident, analysts note that the attacker used a never-before-seen exploit and kept access for months. This profile (high sophistication, high resources) points towards a well-funded group rather than a lone amateur.

Common mistakes

Supplementary — not from your PDF
  • Thinking 'internal' means physically inside the building. It means having authorized access.
  • Assuming every attacker is highly skilled. Most attacks use common tools.

Practical skills

Supplementary — not from your PDF
  • Profile a threat actor from clues about access, tools and persistence.

What I should remember

Key Points PDF p.26
  • Internal/External
    • External Threat Actor: No authorized access; infiltrates security.
    • Internal Threat Actor: Has authorized access; includes employees, contractors, partners.
  • Level of Sophistication/Capability
    • Low Sophistication: Uses common attack tools.
    • High Sophistication: Develops new exploits; may use non-cyber tools.
  • Resources/Funding
    • Support Needed: Customized tools, skilled personnel.
    • Funding Sources: Nation-states, organized crime.