FloCon 2017 has ended
Back To Schedule
Tuesday, January 10 • 9:30am - 10:00am
Assessing Targeted Attacks in Incident Response Threat Correlation

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

The current number of active cyber threats is astounding. Do you know which threats are targeting you right now and which threats are likely tocause greatest harm to your company?
This session examines how correlating network flow data with cyber threat information during incident response provides knowledge of not only what threats are active or targeting you, but which of your assets are being targeted before or during an incident. We examine the many data types used in commonly-shared indicators of compromise and explore which provide for automating correlation with network flow data. The pros and cons of common correlation algorithms are discussed with a focus towards their contributions and limitations to enhancing threat intelligence efforts. Proper network flow correlation should provide a foundation for performing risk-based mitigation that identifies the threats that are creating the
greatest loss of value for your organization rather than chasing down the threats deemed most harmful by the industry.

avatar for Jamison Day

Jamison Day

LookingGlass Cyber Solutions, Inc.
Jamison M. Day is a Decision Science PhD that was selected as 1 of 5 members nation-wide to serve on a Supply Chain Security Team for the U.S. Director of National Intelligence. His interactive analytics products have helped Microsoft and the Department of Homeland Security reduce... Read More →
avatar for Allan Thomson

Allan Thomson

LookingGlass Cyber Solutions, Inc.
As LookingGlass Chief Technology Officer, Allan Thomson has more than three decades of experience across network, security and distributed systems technologies. Allan leads technical strategy, architecture and product development across all LookingGlass Dynamic Threat Defense product... Read More →

Tuesday January 10, 2017 9:30am - 10:00am PST
Great Room V-VIII 7450 Hazard Center Dr.