<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p class="clear" style="font-size: 16px;"><span style="color: #000000; background-color: transparent;">Between limited resources, lack of trained professionals and the increasing quantity/quality of attacks, securing enterprises and responding to incidents has dealt defenders a bad hand in the digital arms race. Even managing the amounts of threat data and open-source intelligence has become a challenge.</span></p> <!--more--><p align="left"><br>John's talk will cover the possibilities and perils of integrating all various sources of threat intelligence data to protect an organization. With all the open-source and paid-source data, simply dumping it all into a firewall or DNS RPZ zone can be problematic. What to do about compromised websites or shared hosting environments? What about DGA domains that use full words and may collide with actual innocent websites? What about how to handle threat data that is lacking in context to make appropriate decisions on its validity and accuracy?</p> <p align="left">This talk will present several case studies in how these problems can be tackled and how using multi-domain analysis can help reduce the risk and maximize the value of automated protection using these types of data.</p> <p align="left"><strong>Session:</strong>&nbsp;<span style="background-color: transparent; font-size: 12px; color: #595a5a;">Tuesday, July 17th. 7:15 PM - 8:15 PM. Learn more <a href="https://www.sans.org/event/sansfire-2018/bonus-sessions/14450/" rel="noopener" target="_blank">here</a>.</span></p> <p align="left"><strong>About the Speaker</strong></p> <p align="left"><strong><img src="https://info.threatstop.com/hubfs/johnspeaking.jpg" alt="johnspeaking" width="202" style="width: 202px; float: left; margin: 0px 17px 7px 0px;"></strong></p> <p><span>John Bambenek is the VP of Security, Research and Intelligence at ThreatSTOP, Lecturer in the Department of Computer Science at the University of Illinois at Urbana-Champaign and a handler with the SANS Internet Storm Center.</span></p> <p><span>He has over 18 years experience in information security and leads several international investigative efforts tracking cyber criminals, some of which have led to high profile arrests and legal action.</span><span>&nbsp;</span></p> <p><span>He specializes in disruptive activities designed to greatly diminish the effectiveness of online criminal operations. He produces some of the largest bodies of open-source intelligence used by thousands of entities across the world</span></p></span>