Detection: Challenging Paradigms cover image

Detection: Challenging Paradigms

Episode 37: Steve Luke and Roman Daszczyszak

Dec 22, 2023
MITRE's Center for Threat Informed Defense (CTID) members discuss Summiting the Pyramid project, analyzing adversary behaviors in cyber, trade-offs in attack analysis, making analytics robust, evasion and false positives in detection, balance between precision and recall, and encouraging user feedback.
01:12:10

Podcast summary created with Snipd AI

Quick takeaways

  • The Summiting the Pyramid project by MITRE's CTID provides a unified method of grading detection efficacy, allowing for improved detection programs in organizations.
  • Comprehending adversary behaviors is crucial for enhancing detection practices and building stronger defenses.

Deep dives

Analyzing cyber defenses and creating robust detections

The podcast episode focuses on creating robust and well-thought-out detections. The guests, Steve and Roman from MITRE's Center for Threat and Form Defense, discuss the summoning the pyramid project and its goal of improving understanding and implementation of robust analytics. The project breaks down analytics into different components, such as observables and telemetry sources, to evaluate their robustness. They use a 2D model to map the levels of analytics and event robustness, allowing for a more precise scoring and categorization of analytic effectiveness. By considering factors like data sources, behavior, and sensor robustness, defenders can develop more effective and resilient detection strategies.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode