{"id":11226,"date":"2018-01-24T16:17:01","date_gmt":"2018-01-25T00:17:01","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2018\/01\/24\/news-4997\/"},"modified":"2018-01-24T16:17:01","modified_gmt":"2018-01-25T00:17:01","slug":"news-4997","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/01\/24\/news-4997\/","title":{"rendered":"Chronicle: A Meteor Aimed At Planet Threat Intel?"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Wed, 24 Jan 2018 22:56:52 +0000<\/strong><\/p>\n<p><strong>Alphabet Inc.<\/strong>, the parent company of <strong>Google<\/strong>, said today it is in the process of rolling out a new service designed to help companies more quickly make sense of and act on the mountains of threat data produced each day by cybersecurity tools.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-42323\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/01\/chonicle.png\" alt=\"\" width=\"275\" height=\"217\" \/>Countless organizations rely on a hodgepodge of security software, hardware and services to find and detect cybersecurity intrusions before an incursion by malicious software or hackers has the chance to metastasize into a full-blown data breach.<\/p>\n<p>The problem is that the sheer volume of data produced by these tools is staggering and increasing each day, meaning already-stretched IT staff often miss key signs of an intrusion until it&#8217;s too late.<\/p>\n<p>Enter &#8220;<strong>Chronicle<\/strong>,&#8221; a nascent platform being developed by the tech giant&#8217;s &#8220;X&#8221; division, which is a separate entity tasked with tackling hard-to-solve problems with an eye toward leveraging the company&#8217;s core strengths: Massive data analytics and storage capabilities, machine learning and custom search capabilities.<\/p>\n<p>&#8220;We want to 10x the speed and impact of security teams\u2019 work by making it much easier, faster and more cost-effective for them to capture and analyze security signals that have previously been too difficult and expensive to find,&#8221; <a href=\"https:\/\/medium.com\/chronicle-blog\/give-good-the-advantage-75ab2c242e45\" target=\"_blank\" rel=\"noopener\">wrote<\/a> <strong>Stephen Gillett<\/strong>, CEO of the new venture.<\/p>\n<p>Few details have been released yet about how exactly Chronicle will work, although the company did say it would draw in part on data from <a href=\"https:\/\/www.virustotal.com\" target=\"_blank\" rel=\"noopener\">Virustotal<\/a>, a free service acquired by Google in 2012 that allows users to scan suspicious files against dozens of commercial antivirus tools simultaneously.<\/p>\n<p>Gillett said his division is already trialing the service with several Fortune 500 firms to test the preview release of Chronicle, but the company declined to name any of those participating.<\/p>\n<h4>ANALYSIS<\/h4>\n<p>It&#8217;s not terribly clear from Gillett&#8217;s post or <a href=\"https:\/\/blog.x.company\/graduation-day-introducing-chronicle-318d34b80cce\" target=\"_blank\" rel=\"noopener\">another blog post<\/a> from Alphabet&#8217;s X division by <strong>Astro Teller<\/strong> how exactly Chronicle will differentiate itself in such a crowded market for cybersecurity offerings. But it&#8217;s worth considering the impact that Virustotal has had over the years.<\/p>\n<p>Currently, Virustotal handles approximately one million submissions each day. The results of each submission get shared back with the entire community of antivirus vendors who lend their tools to the service &#8212; which allows each vendor to benefit by adding malware signatures for new variants that their tools missed but that a preponderance of other tools flagged as malicious.<\/p>\n<p>Naturally, cybercriminals have responded by creating their own criminal versions of Virustotal: So-called <a href=\"https:\/\/krebsonsecurity.com\/?s=%22virus+scanners+for+virus+authors%22&amp;x=0&amp;y=0\" target=\"_blank\" rel=\"noopener\">&#8220;no distribute&#8221; scanners<\/a>. These services cater to malware authors, and use the same stable of antivirus tools, except they prevent these tools from phoning home to the antivirus companies about new, unknown variants.<span id=\"more-42311\"><\/span><\/p>\n<p>On balance, it&#8217;s difficult to know whether the benefit that antivirus companies &#8212; and by extension their customers &#8212; gain by partnering with Virustotal outweighs the mayhem enabled by these no-distribute scanners. But it seems clear that Virustotal has helped antivirus companies and their customers do a better job focusing on threats that really matter, as opposed to chasing after (or cleaning up after) so-called &#8220;false positives,&#8221; &#8212; benign files that erroneously get flagged as malicious.<\/p>\n<p>And this is precisely the signal-to-noise challenge created by the proliferation of security tools used in a typical organization today: How to spend more of your scarce cybersecurity workforce, budget and time identifying and stopping the threats that matter and less time sifting through noisy but otherwise time-wasting alerts triggered by non-threats.<\/p>\n<p>I&#8217;m not a big listener of podcasts, but I do find myself increasingly making time to listen to <a href=\"https:\/\/risky.biz\/netcasts\/risky-business\/\" target=\"_blank\" rel=\"noopener\">Risky Business<\/a>, a podcast produced by Australian cybersecurity journalist <strong>Patrick Gray<\/strong>. Responding to today&#8217;s announcement on Chronicle, Gray said he likewise had few details about it but was looking forward to learning more.<\/p>\n<p>&#8220;Google has so much data and so many amazing internal resources that my gut reaction is to think this new company could be a meteor aimed at planet Threat Intel\u2122\ufe0f,&#8221; Gray <a href=\"http:\/\/twitter.com\/riskybusiness\/status\/956276917107269634\" target=\"_blank\" rel=\"noopener\">quipped on Twitter<\/a>, referring to the burgeoning industry of companies competing to help companies trying to identify new threats and attack trends.\u00a0&#8220;Imagine if other companies spin out their tools&#8230;Netflix, Amazon, Facebook etc. That could be a fundamentally reshaped industry.&#8221;<\/p>\n<p>Well said. I also look forward to hearing more about how Chronicle works and, more importantly, <em>if<\/em> it works.<\/p>\n<p>Full disclosure: Since <a href=\"https:\/\/krebsonsecurity.com\/2016\/09\/the-democratization-of-censorship\/\" rel=\"noopener\" target=\"_blank\">September 2016<\/a>, KrebsOnSecurity has received protection against massive online attacks from <a href=\"https:\/\/projectshield.withgoogle.com\/public\/\" target=\"_blank\" rel=\"noopener\">Project Shield<\/a>, a free anti-distributed denial-of-service (DDoS) offering provided by <strong>Jigsaw<\/strong> &#8212; another subsidiary of Google&#8217;s parent company.\u00a0Project Shield provides DDoS protection for news, human rights, and elections monitoring Web sites.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2018\/01\/chronicle-a-meteor-aimed-at-planet-threat-intel\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/01\/chonicle.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Wed, 24 Jan 2018 22:56:52 +0000<\/strong><\/p>\n<p>Alphabet Inc., the parent company of Google, said today it is in the process of rolling out a new service designed to help companies more quickly make sense of and act on the mountains of threat data produced each day by cybersecurity tools.    Countless organizations rely on a hodgepodge of security software, hardware and services to find and detect cybersecurity intrusions before an incursion by malicious software or hackers has the chance to metastasize into a full-blown data breach.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[16740,11443,17270,17271,1670,17272,17273,17220,17274,11599],"class_list":["post-11226","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-a-little-sunshine","tag-alphabet","tag-astro-teller","tag-chronicle","tag-google","tag-google-x","tag-no-distribute-scanner","tag-security-tools","tag-stephen-gillett","tag-virustotal"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11226"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11226\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}