Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 19 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Are you paying attention to your threat intelligence’s shelf life?

by The Gurus
March 6, 2017
in This Week's Gurus
Share on FacebookShare on Twitter

With each day that passes, threat intelligence platforms automatically absorb hundreds, thousands, potentially millions of indicators, forcing teams, and vendors, to quickly define a threat data lifecycle or expiration strategy. This has been a controversial discussion for most of my career. Much like attribution, expiration efforts are very subjective and depend entirely on tools, adversaries, feeds, and the teams’ sanity point between chasing false positives and precautionary due diligence alerts.
So what do we mean when we talk about expiration? Put simply, your threat intelligence has a shelf life and this means it needs to be kept track of, used before it goes off and got rid of when it’s past its best. Unfortunately, there is neither a well-defined industry standard on how to expire intelligence, nor do the intelligence providers themselves offer much assistance – at least not in any official capacity.  Luckily, there are strategies available you can use and continue to refine as your threat operations program matures.
An entry-level strategy
Let’s consider two core attributes of intelligence to begin with – source type and indicator type. Tying expiration to source alone is not enough as this assumes that all intelligence from a source is created equally, which simply isn’t true. Combining source and indicator type will provide you with a more complete view of your intelligence.
By considering source you can ensure you understand where your data is coming from; this is an important baseline for any strategy. Since all intelligence has a source, it’s a way to make sure that you are including all the intelligence you’re consuming in your expiration policy, which is essential for success. Source also helps you to take into account the confidence you have in that source and the quantity of intelligence the source distributes, which is important for predictability.
Indicator type is important because it speaks directly to your local environment as the indicator type determines which tools the intelligence is distributed to.  This is critical because different tools can consume different volumes of intelligence.
Starting with these two parameters is a great way to get the team on the same page. It is easy to compute, easy to understand, and introduces a multi-dimensional capability allowing teams to weigh and rank source and indicator type.
Refining your expiration strategy
Once your team is comfortable with source and indicator type, you can consider expanding your model to include applying “aging algorithms” to the intelligence. The entry-level strategy uses a linear approach and assumes that intelligence deteriorates at a uniform rate. But we know this isn’t true across the board. Different pieces of intelligence have different lifecycles. Aging algorithms use various methods to account for this.
For example, some types of intelligence deteriorate rapidly over a short period of time and then slow down. This type of intelligence is meant to be operational for hours or days at the most. Open source intelligence typically falls into this group, because even the bad guys monitor it to determine when they have been discovered and their probability of success exponentially decreases.
Some intelligence should never expire. For instance, although some domains and infrastructure tied to previous malicious activity might not pose an immediate threat, history shows it will always be a threat. Intelligence associated with certain adversaries may also be non-expiring because you know that at some point they will likely re-use that infrastructure.
Still, other pieces of intelligence are likely to be relevant for a longer period of time before dramatically decaying. Information provided by commercial feeds, ISAC consortiums, internal intelligence collection or gleaned from other sharing communities will likely fit this paradigm.
In order to be effective and successful as you add more sophisticated aging metrics to your approach, an expiration strategy must be simple, reliable, relatively predictable and easy to adjust. Most importantly, it must be applied to all intelligence in order to make sure that it is being used before it goes bad, resources are not wasted and risk in not being increased by threat intelligence that’s past its shelf life.

ShareTweet
Previous Post

For the government’s digital strategy to be a success bad security habits must be stamped out

Next Post

PSD2 and the e-commerce system

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

VerifyLabs.AI Brings Deepfake Detection to Android After a recent IOS release

June 18, 2026
Proton removes the last barrier to leaving Google Workspace

Proton removes the last barrier to leaving Google Workspace

June 17, 2026
partnership

Check Point and Illumio Deepen Alliance to Counter AI-Powered Cyberattacks

June 17, 2026
Staying Safe After a Cyber Attack

AI-Powered Attacks Become Top Concern for Security Professionals

June 17, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol