Loading…
BSidesLV 2015 has ended
Wednesday, August 5 • 11:00 - 11:55
TAPIOCA (TAPIOCA Automated Processing for IOC Analysis)

Sign up or log in to save this to your schedule and see who's attending!

These days, many security groups want to become "intel shops,” and threat intelligence is all the rage. An intel shop should ingest intel, analyze indicators, and pivot from correlated data. However, few understand how to begin the transition. How IS this accomplished? MAGIC, DAMNIT. Then again, if you’re not the slight of hand kind of guy or gal, we have an answer for you. Check behind your ear, and you’ll find a dollop of TAPIOCA!

In this talk, we will present our process for analyzing Indicators of Compromise (IOCs) at scale, correlating information from multiple sources, and pivoting to obtain information from deep within the bowels of our global network. We’ll talk about the technical challenges we have addressed in applying automated analysis to terabytes of data every day. We will also discuss the next-steps for this analysis, including applying machine learning techniques to help further classify our data. We are also releasing our automated IOC vetting tool, TAPIOCA (TAPIOCA Automated Processing for IOC Analysis), to help other security groups begin processing and benefiting from threat intelligence.

Speakers
avatar for Ryan J Chapman

Ryan J Chapman

Senior IR Analyst, Bechtel Corporation
Ryan Chapman works as a Senior Incident Response analyst. Prior to security, Ryan worked as a technical trainer. Ryan enjoys malware analysis, host/network-based forensics, and… just about everything else that has to do with blue team efforts. Outside of work, Ryan spends time with... Read More →
avatar for Moses Schwartz

Moses Schwartz

Staff Security Engineer, Box
Moses is a staff security engineer working for the Box security incident response team. He's part software developer and part security researcher, with over 10 years experience in industry and government. Nothing hurts him more than watching someone do a tedious, manual task that... Read More →


Wednesday August 5, 2015 11:00 - 11:55
Breaking Ground Florentine A

Attendees (0)