{"id":31721,"date":"2019-10-31T21:42:43","date_gmt":"2019-10-31T18:42:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz\/"},"modified":"2019-10-31T21:42:43","modified_gmt":"2019-10-31T18:42:43","slug":"threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","title":{"rendered":"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>95% e k\u00ebrc\u00ebnimeve t\u00eb siguris\u00eb kibernetike jan\u00eb t\u00eb njohura, dhe mund t\u00eb mbrohemi nga to me mjete tradicionale si antivirus\u00eb, firewalle, IDS, WAF. 5% e tjera t\u00eb k\u00ebrc\u00ebnimeve jan\u00eb t\u00eb panjohura dhe m\u00eb t\u00eb rrezikshmet. Ato p\u00ebrb\u00ebjn\u00eb 70% t\u00eb rrezikut p\u00ebr kompanin\u00eb p\u00ebr shkak se \u00ebsht\u00eb shum\u00eb e v\u00ebshtir\u00eb t\u2019i zbulojm\u00eb dhe akoma m\u00eb keq t\u2019i mbrojm\u00eb nga to. Disa shembuj <noindex><a rel=\"nofollow\" href=\"https:\/\/www.nytimes.com\/2007\/04\/22\/books\/chapters\/0422-1st-tale.html?_r=0\">\u00abrahatat e zeza\u00bb<\/a><\/noindex> jan\u00eb epidemit\u00eb e ransomware-ve WannaCry, NotPetya\/ExPetr, minierat e kripto-moneda, \u00abarm\u00ebt kibernetike\u00bb Stuxnet (q\u00eb ka goditur objektet b\u00ebrthamore t\u00eb Iranit) dhe shum\u00eb (dhe ndonj\u00eb tjet\u00ebr e kujton Kido\/Conficker?) sulme t\u00eb tjera, nga t\u00eb cilat mbrojtja me mjete klasike nuk ka qen\u00eb shum\u00eb e suksesshme. Ne d\u00ebshirojm\u00eb t\u00eb flasim p\u00ebr m\u00ebnyrat p\u00ebr t\u00eb p\u00ebrballuar k\u00ebto 5% t\u00eb k\u00ebrc\u00ebnimeve me teknologjin\u00eb Threat Hunting.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/122d450514502e04bd5c9159dc5a5593.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n Zhvillimi i vazhduesh\u00ebm i sulmeve kibernetike k\u00ebrkon zbuluarje dhe kund\u00ebrveprim t\u00eb vazhduesh\u00ebm, \u00e7ka na \u00e7on p\u00ebrfundimisht n\u00eb mendimin e nj\u00eb gare t\u00eb pafund t\u00eb armatosjes mes sulmuesve dhe mbrojt\u00ebsve. Sistem\u00ebt klasike t\u00eb mbrojtjes nuk jan\u00eb m\u00eb t\u00eb afta p\u00ebr t\u00eb ofruar nj\u00eb nivel t\u00eb pranuesh\u00ebm mbrojtjeje, ku niveli i rrezikut nuk ndikon n\u00eb treguesit kryesor\u00eb t\u00eb kompanis\u00eb (ekonomike, politike, reputacion) pa u rregulluar p\u00ebr infrastruktur\u00ebn specifike, por n\u00eb p\u00ebrgjith\u00ebsi ato mbulojn\u00eb nj\u00eb pjes\u00eb t\u00eb rreziqeve. Gjat\u00eb procesit t\u00eb zbatimit dhe konfigurimit, sistemet moderne t\u00eb mbrojtjes jan\u00eb n\u00eb rol t\u00eb ndjek\u00ebsit dhe duhet t\u00eb p\u00ebrgjigjen ndaj sfidave t\u00eb koh\u00ebs s\u00eb re.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/eb1d64ee67c7e36a506f450f6bc36f60.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex>Burimi<\/noindex><\/p>\n<p>Nj\u00eb nga p\u00ebrgjigjet ndaj sfidave t\u00eb modernitetit p\u00ebr specialistin e siguris\u00eb kibernetike mund t\u00eb jet\u00eb teknologjia Threat Hunting. Termi Threat Hunting (n\u00eb vazhdim\u2014TH) u shfaq disa vjet m\u00eb par\u00eb. Teknologjia n\u00eb vetvete \u00ebsht\u00eb mjaft interesante, por ende nuk ka asnj\u00eb standard dhe rregulla t\u00eb pranuara gjer\u00ebsisht. Gjithashtu e komplikon situat\u00ebn ndryshueshm\u00ebria e burimeve t\u00eb informacionit dhe numri i vog\u00ebl i burimeve n\u00eb gjuh\u00ebn shqipe mbi k\u00ebt\u00eb tem\u00eb. P\u00ebr k\u00ebt\u00eb arsye, ne n\u00eb \u00abLANIT-Integrimi\u00bb vendos\u00ebm t\u00eb shkruajm\u00eb nj\u00eb p\u00ebrmbledhje t\u00eb k\u00ebsaj teknologjie. <\/p>\n<h2>R\u00ebnd\u00ebsia<\/h2>\n<p>\nTeknologjia TH mb\u00ebshtetet n\u00eb proceset e monitorimit t\u00eb infrastruktur\u00ebs.<noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/mssp-mdr.html\"> Ekzistojn\u00eb dy skenar\u00eb kryesor\u00eb t\u00eb monitorimit t\u00eb brendsh\u00ebm \u2013 Alerting dhe Hunting<\/a><\/noindex>Alerting (in the style of MSSP services) is a traditional method that involves searching for previously developed signatures and signs of attacks and responding to them. This scenario is successfully executed by traditional signature-based protection tools. Hunting (an MDR-type service) is a monitoring method that answers the question, 'Where do the signatures and rules come from?'. This is the process of creating correlation rules by analyzing hidden or previously unknown indicators and signs of attacks. Threat Hunting relates to this type of monitoring.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/5e1620075bc3ca68e5f42ed7ed91f730.gif\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nBy combining both types of monitoring, we achieve near-ideal protection, but there always remains a certain level of residual risk.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/2b89edcf2141c1ea3ad789908a02819d.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Protection using two types of monitoring<\/i><\/p>\n<p>And here's why TH (and hunting as a whole!) will become increasingly relevant:<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/4c27001f933e017550d38672089da08f.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Threats, protective measures, risks.<\/i> <noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/threat-hunting.html\">Burimi<\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/threat-hunting.html\">95% of all threats are well-studied<\/a><\/noindex>. These include types such as spam, DDoS, viruses, rootkits, and other classic malware. Protection from these threats can be achieved using the same classic protection tools.<\/p>\n<p>In the course of any project<noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%97%D0%B0%D0%BA%D0%BE%D0%BD_%D0%9F%D0%B0%D1%80%D0%B5%D1%82%D0%BE\"> 20% of the time takes 80% of the work<\/a><\/noindex>, while the remaining 20% of work takes 80% of the time. Similarly, among the entire landscape of threats, 5% of new-type threats will account for 70% of the risk for the company. In a company where information security management processes are organized, we can manage 30% of the risk of known threats in one way or another, either avoiding (forgoing wireless networks altogether), accepting (implementing necessary protection measures), or transferring (for example, to an integrator) this risk. However, protecting against<noindex><a rel=\"nofollow\" href=\"https:\/\/threatpost.ru\/windows-0day-patched-by-third-party\/30640\/\"> zero-day vulnerabilities<\/a><\/noindex>, APT attacks, phishing,<noindex><a rel=\"nofollow\" href=\"https:\/\/www.cloudav.ru\/mediacenter\/news\/business-risks-supply-chain-attacks\/\"> supply chain attacks<\/a><\/noindex>, cyber espionage, and national operations, as well as from a large number of other attacks, is already much more complex. The consequences of these 5% of threats will be much more serious (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.group-ib.ru\/brochures\/gib-buhtrap-report.pdf\">the average loss amount for the bank from the buhtrap group is 143 million<\/a><\/noindex>), than the consequences of spam or viruses, from which antivirus software protects.<\/p>\n<p>Everyone has to deal with 5% of threats. Recently, we had to set up an open-source solution that uses an application from the PEAR repository (PHP Extension and Application Repository). The attempt to install this application via pear install failed, as<noindex><a rel=\"nofollow\" href=\"http:\/\/pear.php.net\/\"> faqen<\/a><\/noindex> ishte i paarritsh\u00ebm (tani ka nj\u00eb penges\u00eb mbi t\u00eb), duhej ta instalonim nga GitHub. Dhe sapo u zbulua se PEAR u b\u00eb viktim\u00eb e<noindex><a rel=\"nofollow\" href=\"https:\/\/threatpost.ru\/intruders-modified-pear-installer\/30665\/\"> nj\u00eb sulmi p\u00ebrmes zinxhirit t\u00eb furnizimit<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/8fd5d8332c5f859fa07e4405a1bc3c73.gif\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Mund t\u00eb kujtojm\u00eb gjithashtu<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cloud4y\/blog\/338980\/\"> sulmin q\u00eb p\u00ebrdori CCleaner<\/a><\/noindex>, epidemin\u00eb e ransomware-it NePetya p\u00ebrmes moduli t\u00eb p\u00ebrdit\u00ebsimit t\u00eb programit p\u00ebr menaxhimin e raportimit tatimor<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/cloud4y\/blog\/338980\/\"> M.E.Doc<\/a><\/noindex>. K\u00ebto k\u00ebrc\u00ebnime po b\u00ebhen gjithnj\u00eb e m\u00eb t\u00eb sofistikuara, dhe lind pyetja logjike \u2013 \"Si t\u00eb p\u00ebrballojm\u00eb k\u00ebto 5% t\u00eb k\u00ebrc\u00ebnimeve?\"<\/p>\n<h2>Definicioni i Threat Hunting<\/h2>\n<p>\nPra, Threat Hunting \u00ebsht\u00eb nj\u00eb proces proaktiv dhe iterativ i k\u00ebrkimit dhe zbulimit t\u00eb k\u00ebrc\u00ebnimeve t\u00eb avancuara, t\u00eb cilat nuk mund t\u00eb zbulohen nga mjetet tradicionale t\u00eb siguris\u00eb. K\u00ebrc\u00ebnimet e avancuara p\u00ebrfshijn\u00eb, p\u00ebr shembull, sulme si APT, sulme n\u00eb dob\u00ebsit\u00eb 0-day, Living off the Land dhe t\u00eb tjera.<\/p>\n<p>Gjithashtu mund t\u00eb rip\u00ebrkufizohet q\u00eb TH \u00ebsht\u00eb nj\u00eb proces verifikimi t\u00eb hipotezave. Ky \u00ebsht\u00eb kryesisht nj\u00eb proces manual me elemente automatizimi, n\u00eb t\u00eb cilin analisti, duke u mb\u00ebshtetur n\u00eb njohurit\u00eb dhe kualifikimin e tij, shflet n\u00ebp\u00ebr sasi t\u00eb m\u00ebdha informacioni n\u00eb k\u00ebrkim t\u00eb shenjave t\u00eb komprometimit, n\u00eb p\u00ebrputhje me hipotez\u00ebn e fillestar q\u00eb ka t\u00eb b\u00ebj\u00eb me pranin\u00eb e nj\u00eb k\u00ebrc\u00ebnimi t\u00eb caktuar. Karakteristika e ve\u00e7ant\u00eb e tij \u00ebsht\u00eb larmia e burimeve t\u00eb informacionit.<\/p>\n<p>Duhet theksuar se Threat Hunting nuk \u00ebsht\u00eb ndonj\u00eb produkt softuerik apo harduerik. Nuk jan\u00eb alarme q\u00eb mund t\u00eb shihen n\u00eb ndonj\u00eb zgjidhje. Nuk \u00ebsht\u00eb nj\u00eb proces k\u00ebrkimi p\u00ebr IOC (identifikuesit e komprometimit). Dhe nuk \u00ebsht\u00eb ndonj\u00eb aktivitet pasiv q\u00eb zhvillohet pa pjes\u00ebmarrjen e analist\u00ebve t\u00eb siguris\u00eb. Threat Hunting, para s\u00eb gjithash, \u00ebsht\u00eb nj\u00eb proces.<\/p>\n<h2>Komponent\u00ebt e Threat Hunting<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/c80d0ff7d7446b0976013043b48be7c3.gif\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nTre komponent\u00ebt kryesor\u00eb t\u00eb Threat Hunting: t\u00eb dh\u00ebnat, teknologjit\u00eb, njer\u00ebzit.<\/p>\n<p><b>T\u00eb dh\u00ebnat (\u00e7far\u00eb?)<\/b>, duke p\u00ebrfshir\u00eb Big Data. T\u00eb gjitha llojet e pikave t\u00eb trafikut, informacioni mbi APT-t\u00eb e m\u00ebparshme, analiza, t\u00eb dh\u00ebnat mbi aktivitetin e p\u00ebrdoruesve, t\u00eb dh\u00ebnat rrjet\u00ebrore, informacioni nga punonj\u00ebsit, informacioni n\u00eb dark web dhe shum\u00eb t\u00eb tjera.<\/p>\n<p><b>Teknologjit\u00eb (si?)<\/b> p\u00ebrpunimi i k\u00ebtyre t\u00eb dh\u00ebnave \u2013 t\u00eb gjitha m\u00ebnyrat e mundshme p\u00ebr p\u00ebrpunimin e k\u00ebtyre t\u00eb dh\u00ebnave, duke p\u00ebrfshir\u00eb Machine Learning.<\/p>\n<p><b>Njer\u00ebzit (kush?)<\/b> \u2013 ata q\u00eb kan\u00eb p\u00ebrvoj\u00eb t\u00eb madhe n\u00eb analizimin e sulmeve t\u00eb ndryshme, intuicion t\u00eb zhvilluar dhe aft\u00ebsin\u00eb p\u00ebr t\u00eb zbuluar nj\u00eb sulm. Zakonisht, k\u00ebta jan\u00eb analist\u00eb t\u00eb siguris\u00eb s\u00eb informacionit q\u00eb duhet t\u00eb ken\u00eb aft\u00ebsin\u00eb p\u00ebr t\u00eb gjeneruar hipoteza dhe p\u00ebr t\u00eb gjetur konfirmimin e tyre. Ata jan\u00eb elementi kryesor i procesit.<\/p>\n<h2>Modeli PARIS<\/h2>\n<p>\nAdam Bejtman<noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/blog\/the-paris-model\/\"> p\u00ebrshkruan<\/a><\/noindex> modeli PARIS p\u00ebr procesin ideal TH. Emri si\u00e7 duket ka nj\u00eb aluzion n\u00eb nj\u00eb atraksion t\u00eb njohur n\u00eb Franc\u00eb. Ky model mund t\u00eb shihet n\u00eb dy drejtime \u2013 nga e sip\u00ebrmja dhe nga e poshtmja.<\/p>\n<p>N\u00eb procesin e gjuetis\u00eb ndaj k\u00ebrc\u00ebnimeve, duke iu qasur modelit nga e poshtmja lart, ne do t\u00eb kemi t\u00eb b\u00ebjm\u00eb me shum\u00eb prova t\u00eb aktivitetit t\u00eb d\u00ebmsh\u00ebm. \u00c7do prov\u00eb ka nj\u00eb mas\u00eb si besueshm\u00ebria \u2013 nj\u00eb karakteristik\u00eb q\u00eb pasqyron pesh\u00ebn e k\u00ebsaj prove. Ekzistojn\u00eb d\u00ebshmi \"m\u00eb t\u00eb forta\", prova t\u00eb drejtp\u00ebrdrejta t\u00eb aktivitetit t\u00eb d\u00ebmsh\u00ebm, p\u00ebrmes t\u00eb cilave mund t\u00eb arrijm\u00eb menj\u00ebher\u00eb n\u00eb maj\u00ebn e piramid\u00ebs dhe t\u00eb krijojm\u00eb nj\u00eb njoftim faktik p\u00ebr nj\u00eb infeksion t\u00eb njohur. Dhe ka prova indirekte, shumica e t\u00eb cilave mund t\u00eb na \u00e7ojn\u00eb gjithashtu n\u00eb maj\u00ebn e piramid\u00ebs. Si gjithmon\u00eb, ka shum\u00eb m\u00eb tep\u00ebr prova indirekte sesa t\u00eb drejtp\u00ebrdrejta, ndaj duhen renditur dhe analizuar, b\u00ebr\u00eb k\u00ebrkime t\u00eb m\u00ebtejshme dhe \u00ebsht\u00eb e preferueshme q\u00eb kjo t\u00eb automatizohet.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/05de6420a8dec35f0bec3002ee812cdc.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Modeli PARIS.<\/i> <noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/blog\/the-paris-model\/\">Burimi<\/a><\/noindex><\/p>\n<p>Pjesa e sip\u00ebrme e modelit (1 dhe 2) bazohet n\u00eb teknologjit\u00eb e automatizimit dhe analitik\u00ebn e diversifikuar, nd\u00ebrsa pjesa e poshtme (3 dhe 4) mbi njer\u00ebzit me kualifikim t\u00eb caktuar q\u00eb menaxhojn\u00eb procesin. Ky model mund t\u00eb konsiderohet nga e sip\u00ebrmja posht\u00eb, ku n\u00eb pjes\u00ebn e sip\u00ebrme blu kemi njoftime nga mjete tradicionale mbrojt\u00ebse (antivirus, EDR, firewall, n\u00ebnshkrime) me nj\u00eb nivel t\u00eb lart\u00eb besueshm\u00ebrie dhe besnik\u00ebrie, nd\u00ebrsa m\u00eb posht\u00eb shenjat (IOC, URL, MD5 dhe t\u00eb tjera) q\u00eb kan\u00eb nj\u00eb nivel m\u00eb t\u00eb ul\u00ebt besueshm\u00ebrie dhe k\u00ebrkojn\u00eb studim t\u00eb m\u00ebtejsh\u00ebm. Dhe niveli m\u00eb i ul\u00ebt dhe m\u00eb i trash\u00eb (4) \u2013 gjenerimi i hipotezave, krijimi i skenar\u00ebve t\u00eb rinj t\u00eb pun\u00ebs p\u00ebr mjete tradicionale mbrojt\u00ebse. Ky nivel nuk kufizohet vet\u00ebm n\u00eb burimet e p\u00ebrmendura t\u00eb hipotezave. Sa m\u00eb i ul\u00ebt niveli, aq m\u00eb shum\u00eb k\u00ebrkesa ka p\u00ebr kualifikimin e analistit.<\/p>\n<p>\u00cbsht\u00eb shum\u00eb e r\u00ebnd\u00ebsishme q\u00eb analist\u00ebt t\u00eb mos kontrollojn\u00eb thjesht nj\u00eb grup t\u00eb caktuar hipotezash, por t\u00eb punojn\u00eb vazhdimisht p\u00ebr t\u00eb gjeneruar hipoteza t\u00eb reja dhe mund\u00ebsi t\u00eb verifikimit t\u00eb tyre.<\/p>\n<h2>Modeli i pjekuris\u00eb n\u00eb p\u00ebrdorimin e TH<\/h2>\n<p>\nN\u00eb nj\u00eb bot\u00eb ideale, TH \u00ebsht\u00eb nj\u00eb proces i vazhduesh\u00ebm. Por, duke qen\u00eb se nuk ka nj\u00eb bot\u00eb ideale, le t\u00eb analizojm\u00eb<noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/blog\/threat-hunting-maturity-model\/\"> modelin e pjekuris\u00eb<\/a><\/noindex> dhe metodat n\u00eb kontekstin e njer\u00ebzve, proceseve dhe teknologjive t\u00eb p\u00ebrdorura. Le t\u00eb shqyrtojm\u00eb modelin ideal t\u00eb sfer\u00ebs TH. Ka 5 nivele t\u00eb p\u00ebrdorimit t\u00eb k\u00ebsaj technologie. Le t\u00eb shohim ato n\u00eb shembullin e evolucionit t\u00eb nj\u00eb ekipi t\u00eb ve\u00e7ant\u00eb t\u00eb analist\u00ebve.<\/p>\n<p><b>Nivelet e pjekuris\u00eb<\/b><br \/>\n<b>Njer\u00ebzit<\/b><br \/>\n<b>Proceset<\/b><br \/>\n<b>Teknologjit\u00eb<\/b><\/p>\n<p><b>Niveli 0<\/b><br \/>\nAnalist\u00ebt SOC<br \/>\n24\/7<br \/>\nMjete tradicionale:<\/p>\n<p>Tradicional<br \/>\nGrupi i alerteve<br \/>\nMonitorimi pasiv<br \/>\nIDS, AV, Sandboxing,<\/p>\n<p><i>Pa TH<\/i><br \/>\nPunimi me alertet<\/p>\n<p>mjetet e analizes me n\u00ebnshkrim, t\u00eb dh\u00ebnat Threat Intelligence.<\/p>\n<p><b>Niveli 1<\/b><br \/>\nAnalist\u00ebt SOC<br \/>\nTH i rastit<br \/>\nEDR<\/p>\n<p>Eksperimental<br \/>\nNjohuri baz\u00eb mbi forenzik\u00ebn<br \/>\nK\u00ebrkimi i IOC<br \/>\nOfrim t\u00eb pjessh\u00ebm t\u00eb t\u00eb dh\u00ebnave nga pajisjet rrjet<\/p>\n<p><i>Eksperimentet me TH<\/i><br \/>\nNjohuri t\u00eb mira t\u00eb rrjeteve dhe pjes\u00ebs aplikative<\/p>\n<p>P\u00ebrdorim i pjessh\u00ebm<\/p>\n<p><b>Niveli 2<\/b><br \/>\nAngazhimi i p\u00ebrkohsh\u00ebm<br \/>\nSprintet<br \/>\nEDR<\/p>\n<p>Periodike<br \/>\nNjohuri t\u00eb mesme mbi forenzik\u00ebn<br \/>\nJava n\u00eb muaj<br \/>\nP\u00ebrdorim i plot\u00eb<\/p>\n<p><i>TH p\u00ebrkoh\u00ebsor<\/i><br \/>\nNjohuri t\u00eb shk\u00eblqyera t\u00eb rrjeteve dhe pjes\u00ebs aplikative<br \/>\nTH i rregullt<br \/>\nAutomatizim i plot\u00eb i p\u00ebrdorimit t\u00eb t\u00eb dh\u00ebnave EDR<\/p>\n<p>P\u00ebrdorim i pjessh\u00ebm i mund\u00ebsive t\u00eb avancuara EDR<\/p>\n<p><b>Niveli 3<\/b><br \/>\nEkip i dedikuar p\u00ebr TH<br \/>\n24\/7<br \/>\nMund\u00ebsi t\u00eb pjesshme p\u00ebr t\u00eb verifikuar hipotezat e TH<\/p>\n<p>Preventiv<br \/>\nNjohuri t\u00eb shk\u00eblqyera mbi forenzik\u00ebn dhe malware<br \/>\nTH preventiv<br \/>\nP\u00ebrdorim i plot\u00eb i mund\u00ebsive t\u00eb avancuara EDR<\/p>\n<p><i>Rastet e ve\u00e7anta t\u00eb TH<\/i><br \/>\nNjohuri t\u00eb shk\u00eblqyera t\u00eb an\u00ebs sulmuese<br \/>\nRastet e ve\u00e7anta t\u00eb TH<br \/>\nP\u00ebrmbushje e plot\u00eb e t\u00eb dh\u00ebnave nga pajisjet rrjet<\/p>\n<p>Konfigurim sipas nevojave<\/p>\n<p><b>Niveli 4<\/b><br \/>\nEkip i dedikuar p\u00ebr TH<br \/>\n24\/7<br \/>\nMund\u00ebsi e plot\u00eb p\u00ebr t\u00eb verifikuar hipotezat e TH<\/p>\n<p>P\u00ebrgjegj\u00ebs<br \/>\nNjohuri t\u00eb shk\u00eblqyera mbi forenzik\u00ebn dhe malware<br \/>\nTH preventiv<br \/>\nNiveli 3, plus:<\/p>\n<p><i>P\u00ebrdorimi i TH<\/i><br \/>\nNjohuri t\u00eb shk\u00eblqyera t\u00eb an\u00ebs sulmuese<br \/>\nVerifikimi, automatizimi dhe verifikimi i hipotezave t\u00eb TH<br \/>\nintegrimi i ngusht\u00eb i burimeve t\u00eb t\u00eb dh\u00ebnave;<\/p>\n<p>Kapaciteti p\u00ebr k\u00ebrkime<\/p>\n<p>zhvillimi sipas nevojave dhe p\u00ebrdorimi i improvizuar i API.<\/p>\n<p><i>Nivelet e pjekuris\u00eb t\u00eb TH n\u00eb kontekstin e njer\u00ebzve, proceseve dhe teknologjive<\/i><\/p>\n<p><b>Niveli 0:<\/b> tradicional, pa p\u00ebrdorimin e TH. Analist\u00ebt e zakonsh\u00ebm punojn\u00eb me nj\u00eb grup standard alesh n\u00eb nj\u00eb m\u00ebnyr\u00eb pasive monitorimi me p\u00ebrdorim t\u00eb mjeteve dhe teknologjive standarde: IDS, AV, kuti r\u00ebre, mjete t\u00eb analizes me n\u00ebnshkrim.<\/p>\n<p><b>Niveli 1:<\/b> eksperimentale, duke p\u00ebrdorur TH. T\u00eb nj\u00ebjtit analist\u00eb me njohuri baz\u00eb mbi forenzik\u00ebn dhe k\u00ebrkesa t\u00eb mira p\u00ebr rrjetet dhe pjes\u00ebn praktike mund t\u00eb realizojn\u00eb nj\u00eb k\u00ebrkim t\u00eb nj\u00ebhersh\u00ebm Threat Hunting p\u00ebrmes k\u00ebrkimit t\u00eb treguesve t\u00eb komprometimit. Veglat p\u00ebrfshijn\u00eb EDR me mbulimin e pjessh\u00ebm t\u00eb t\u00eb dh\u00ebnave nga pajisjet rrjet\u00ebsore. Veglat aplikohen pjes\u00ebrisht.<\/p>\n<p><b>Niveli 2:<\/b> periodik, p\u00ebrkohsh\u00ebm TH. T\u00eb nj\u00ebjt\u00ebve analist\u00eb, t\u00eb cil\u00ebt tashm\u00eb kan\u00eb avancuar njohurit\u00eb e tyre mbi forenzik\u00ebn, rrjetet dhe aspektin praktik, u ngarkohet detyra e angazhimit t\u00eb rregullt (sprint) n\u00eb Threat Hunting, le t\u00eb themi, nj\u00eb jav\u00eb n\u00eb muaj. N\u00eb mjetet shtohet nj\u00eb studim i plot\u00eb i t\u00eb dh\u00ebnave nga pajisjet rrjet\u00ebrore, automatizimi i analiz\u00ebs s\u00eb t\u00eb dh\u00ebnave nga EDR dhe p\u00ebrdorimi i pjessh\u00ebm i mund\u00ebsive t\u00eb avancuara t\u00eb EDR.<\/p>\n<p><b>Niveli 3:<\/b> preventiv, raste t\u00eb shpeshta TH. Analist\u00ebt tan\u00eb u organizuan n\u00eb nj\u00eb ekip t\u00eb ve\u00e7ant\u00eb, duke fituar njohuri t\u00eb shk\u00eblqyera n\u00eb forenzik\u00eb dhe malware, si dhe njohuri mbi metodat dhe taktikat e pun\u00ebs s\u00eb an\u00ebtar\u00ebve t\u00eb sulmit. Procesi tashm\u00eb realizohet n\u00eb m\u00ebnyr\u00eb 24\/7. Ekipi \u00ebsht\u00eb n\u00eb gjendje t\u00eb kontrolloj\u00eb pjes\u00ebrisht hipotezat TH, duke p\u00ebrdorur plot\u00ebsisht mund\u00ebsit\u00eb e avancuara t\u00eb EDR me mbulimin e plot\u00eb t\u00eb t\u00eb dh\u00ebnave nga pajisjet rrjet\u00ebsore. Po ashtu, analist\u00ebt jan\u00eb n\u00eb gjendje t\u00eb konfiguroni veglat sipas nevojave t\u00eb tyre.<\/p>\n<p><b>Niveli 4:<\/b> liderues, p\u00ebrdorimi i TH. E nj\u00ebjta ekip ka fituar aft\u00ebsi hulumtimi, aft\u00ebsin\u00eb p\u00ebr t\u00eb gjeneruar dhe automatizuar procesin e verifikimit t\u00eb hipotezave TH. Tani veglat p\u00ebrfshijn\u00eb integrimin e ngusht\u00eb t\u00eb burimeve t\u00eb t\u00eb dh\u00ebnave, zhvillimin e softuerit sipas nevojave dhe p\u00ebrdorimin e pazakont\u00eb t\u00eb API.<\/p>\n<h2>Teknikat e Threat Hunting<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/2ce2c8a58773444790a03f7d0c163d76.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Teknikat e baz\u00ebs s\u00eb Threat Hunting<\/i><\/p>\n<p>N\u00eb<noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/Cyber-Threat-Hunting-Data-Science\"> teknikat<\/a><\/noindex> TH n\u00eb rendin e pjekuris\u00eb s\u00eb teknologjis s\u00eb p\u00ebrdorur i p\u00ebrkasin: k\u00ebrkimi baz\u00eb, analiza statistikore, teknikat e vizualizimit, agregatet e thjeshta, m\u00ebsimi i makineris\u00eb dhe metodat bayesiane. <\/p>\n<p>Metoda m\u00eb e thjesht\u00eb \u00ebsht\u00eb k\u00ebrkimi bazik, i cili p\u00ebrdoret p\u00ebr t\u00eb ngushtuar fush\u00ebn e studimit me ndihm\u00ebn e k\u00ebrkesave t\u00eb caktuara. Analiza statistike aplikohet, p\u00ebr shembull, p\u00ebr t\u00eb nd\u00ebrtuar nj\u00eb model t\u00eb aktiviteteve tipike t\u00eb p\u00ebrdoruesve ose t\u00eb rrjeteve si nj\u00eb model statistikor. Teknikat e vizualizimit p\u00ebrdoren p\u00ebr t\u00eb paraqitur dhe thjeshtuar analiz\u00ebn e t\u00eb dh\u00ebnave n\u00eb form\u00ebn e grafik\u00ebve dhe diagrameve, ku \u00ebsht\u00eb shum\u00eb m\u00eb e leht\u00eb t\u00eb kuptohen tendencat n\u00eb mostrat. Teknikat e agregimit t\u00eb thjesht\u00eb sipas fushave ky\u00e7e p\u00ebrdoren p\u00ebr t\u00eb optimizuar k\u00ebrkimin dhe analiz\u00ebn. Sa m\u00eb i lart\u00eb t\u00eb jet\u00eb niveli i pjekuris\u00eb q\u00eb arrihet n\u00eb nj\u00eb organizat\u00eb, aq m\u00eb relevant b\u00ebhet p\u00ebrdorimi i algoritmeve t\u00eb m\u00ebsimit t\u00eb makin\u00ebs. Ato gjithashtu p\u00ebrdoren gjer\u00ebsisht, p\u00ebrfshir\u00eb p\u00ebr filtrimin e spamit, zbuluarjen e trafikut t\u00eb d\u00ebmsh\u00ebm dhe identifikimin e veprimeve mashtruese. Nj\u00eb lloj m\u00eb i avancuar i algoritmeve t\u00eb m\u00ebsimit t\u00eb makin\u00ebs jan\u00eb metodat bayesiane, t\u00eb cilat lejojn\u00eb klasifikimin, reduktimin e dimensionit t\u00eb mostrav\u00eb dhe modelimin tematik.<\/p>\n<h2>Modeli i diamantit dhe strategjit\u00eb e TH<\/h2>\n<p>\nSergio Kaltagiron, Andrew Pendegast dhe Christopher Betz n\u00eb punimin e tyre \"<noindex><a rel=\"nofollow\" href=\"https:\/\/digital-forensics.sans.org\/summit-archives\/cti_summit2014\/The_Diamond_Model_for_Intrusion_Analysis_A_Primer_Andy_Pendergast.pdf\">Modeli i Diamandit t\u00eb Analiz\u00ebs s\u00eb Infiltrimit<\/a><\/noindex>\" treguan p\u00ebrb\u00ebr\u00ebsit kryesor\u00eb t\u00eb \u00e7do aktiviteti t\u00eb d\u00ebmsh\u00ebm dhe lidhjen themelore midis tyre.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/2c6c165553be60a836383b1b52cb8987.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Modeli i diamantit p\u00ebr aktivitetet e d\u00ebmshme<\/i><\/p>\n<p>Sipas k\u00ebtij modeli, jan\u00eb 4 strategji t\u00eb Threat Hunting, t\u00eb cilat mb\u00ebshteten n\u00eb p\u00ebrb\u00ebr\u00ebsit ky\u00e7 t\u00eb p\u00ebrshtatsh\u00ebm.<\/p>\n<p>1. Strategjia e orientuar drejt viktim\u00ebs. Si supozim, ndonj\u00ebher\u00eb viktima ka armiq, dhe ata do t\u00eb ofrojn\u00eb \"mund\u00ebsi\" p\u00ebrmes post\u00ebs elektronike. K\u00ebrkojm\u00eb t\u00eb dh\u00ebna mbi armiqt\u00eb n\u00eb e-mail. K\u00ebrkoni lidhje, opsione etj. K\u00ebrkojm\u00eb konfirmimin e k\u00ebsaj hipoteze p\u00ebr nj\u00eb periudh\u00eb t\u00eb caktuar (nj\u00eb muaj, dy jav\u00eb), n\u00ebse nuk e gjejm\u00eb, at\u00ebher\u00eb hipoteza nuk ka funksionuar.<\/p>\n<p>2. Strategjia e orientuar ndaj infrastruktur\u00ebs. Ekzistojn\u00eb disa metoda p\u00ebr t\u00eb p\u00ebrdorur k\u00ebt\u00eb strategji. N\u00eb var\u00ebsi t\u00eb aksesit dhe pamjes, disa prej tyre jan\u00eb m\u00eb t\u00eb lehta se t\u00eb tjerat. P\u00ebr shembull, ne monitorojm\u00eb server\u00ebt e emrave t\u00eb domenit, t\u00eb njohur p\u00ebr hostimin e domen\u00ebve t\u00eb d\u00ebmsh\u00ebm. Ose realizojm\u00eb nj\u00eb proces p\u00ebr ndjekjen e t\u00eb gjitha regjistrimeve t\u00eb reja t\u00eb emrave t\u00eb domenit p\u00ebr nj\u00eb model t\u00eb njohur t\u00eb p\u00ebrdorur nga armiku.<\/p>\n<p>3. Strat\u00e9gjia e orientuar drejt mund\u00ebsive. P\u00ebrve\u00e7 strategjis\u00eb s\u00eb orientuar ndaj viktimave, q\u00eb p\u00ebrdoret nga shumica e mbrojt\u00ebsve t\u00eb rrjetit, ekziston nj\u00eb strategji e orientuar drejt mund\u00ebsive. Kjo \u00ebsht\u00eb e dyta m\u00eb e popullarizuar dhe fokusohet n\u00eb identifikimin e mund\u00ebsive nga kund\u00ebrshtari, p\u00ebrkat\u00ebsisht 'softuer\u00ebve t\u00eb d\u00ebmsh\u00ebm' dhe mund\u00ebsin\u00eb e p\u00ebrdorimit nga kund\u00ebrshtari t\u00eb mjeteve t\u00eb legjitime si psexec, powershell, certutil dhe t\u00eb tjera.<\/p>\n<p>4. Strat\u00e9gjia e orientuar ndaj kund\u00ebrshtarit. Qasja e orientuar ndaj kund\u00ebrshtarit fokusohet te vet\u00eb kund\u00ebrshtari. K\u00ebtu p\u00ebrfshihen p\u00ebrdorimi i informacionit publik nga burimet e hapura (OSINT), mbledhja e t\u00eb dh\u00ebnave mbi kund\u00ebrshtarin, teknikat dhe metodat e tij (TTP), analizimi i incidenteve t\u00eb kaluar dhe t\u00eb dh\u00ebnave p\u00ebr Threat Intelligence, etj.<\/p>\n<h2>Burimet e informacionit dhe hipotezat n\u00eb TH<\/h2>\n<p>\n<img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/d2d586c4e52ee73a45c7eb151298e866.gif\" style=\"display:block;margin: 0 auto;\" \/><i>Disa burime informacioni p\u00ebr Threat Hunting<\/i><\/p>\n<p>Burimet e informacionit mund t\u00eb jen\u00eb shum\u00eb. Analist\u00ebt e p\u00ebrsosur duhet t\u00eb jen\u00eb n\u00eb gjendje t\u00eb nxjerrin informacion nga gjith\u00e7ka q\u00eb i rrethon. Burimet tipike n\u00eb \u00e7do infrastruktur\u00eb do t\u00eb jen\u00eb t\u00eb dh\u00ebnat nga mjetet e mbrojtjes: DLP, SIEM, IDS\/IPS, WAF\/FW, EDR. Po ashtu, burime tipike informacioni do t\u00eb jen\u00eb indikator\u00ebt e ndryshimit t\u00eb siguris\u00eb, sh\u00ebrbimet e Threat Intelligence, t\u00eb dh\u00ebnat nga CERT dhe OSINT. P\u00ebr m\u00eb tep\u00ebr, mund t\u00eb p\u00ebrdoret informacioni nga darknet (p\u00ebr shembull, papritur ka nj\u00eb porosi p\u00ebr t\u00eb thyer kutin\u00eb e post\u00ebs elektronike t\u00eb udh\u00ebheq\u00ebsit t\u00eb organizat\u00ebs, ose aktiviteti juaj ka nxjerr\u00eb n\u00eb pah nj\u00eb kandidat p\u00ebr pozit\u00ebn e inxhinierit t\u00eb rrjetit), informacioni i marr\u00eb nga HR (prapaskenat p\u00ebr kandidat\u00ebt nga vendet e tyre t\u00eb m\u00ebparshme t\u00eb pun\u00ebs), informacioni nga sh\u00ebrbimi i siguris\u00eb (p\u00ebr shembull, rezultatet e kontrollit t\u00eb partner\u00ebve).<\/p>\n<p>Por para se t\u00eb p\u00ebrdoren t\u00eb gjitha burimet e disponueshme, \u00ebsht\u00eb e nevojshme t\u00eb ket\u00eb t\u00eb pakt\u00ebn nj\u00eb hipotez\u00eb.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/2169b4ac3393626d1810770c9d107f90.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\">Burimi<\/a><\/noindex><\/p>\n<p>P\u00ebr t\u00eb verifikuar hipotezat, ato duhet s\u00eb pari t\u00eb formulohen. Dhe p\u00ebr t\u00eb formuluar shum\u00eb hipoteza cil\u00ebsore, \u00ebsht\u00eb e nevojshme t\u00eb aplikohet nj\u00eb qasje sistematike. Procesi i gjenerimit t\u00eb hipotezave \u00ebsht\u00eb p\u00ebrshkruar n\u00eb m\u00ebnyr\u00eb m\u00eb t\u00eb detajuar n\u00eb<noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\"> artikulli yn\u00eb<\/a><\/noindex>, bazuar n\u00eb procesin e formulimit t\u00eb hipotezave \u00ebsht\u00eb e p\u00ebrshtatshme t\u00eb merrni k\u00ebt\u00eb skem\u00eb.<\/p>\n<p>Burimi kryesor i hipotezave do t\u00eb jet\u00eb <b>matrica ATT&amp;CK<\/b> (Taktika, Teknikat dhe Njohuri t\u00eb zakonshme Adversariale). Ajo, n\u00eb thelb, \u00ebsht\u00eb nj\u00eb baz\u00eb e njohurive dhe nj\u00eb model p\u00ebr vler\u00ebsimin e sjelljes s\u00eb akter\u00ebve t\u00eb keq, t\u00eb cil\u00ebt realizojn\u00eb aktivitat e tyre n\u00eb hapat e fundit t\u00eb sulmit, zakonisht p\u00ebrshkruar me konceptin e Kill Chain. N\u00eb thelb, n\u00eb fazat pas infiltrimit t\u00eb akterit t\u00eb keq n\u00eb rrjetin e brendsh\u00ebm t\u00eb nj\u00eb kompanie ose n\u00eb nj\u00eb pajisje celulare. Fillimisht, baza e njohurive p\u00ebrfshinte p\u00ebrshkrimin e 121 taktikave dhe teknikave t\u00eb p\u00ebrdorura gjat\u00eb sulmit, secila prej t\u00eb cilave \u00ebsht\u00eb p\u00ebrshkruar n\u00eb detaje n\u00eb formatin Wiki. Nj\u00eb burim i mir\u00eb p\u00ebr gjenerimin e hipotezave \u00ebsht\u00eb analiza e larmishme e Threat Intelligence. E ve\u00e7anta \u00ebsht\u00eb analiza e infrastruktur\u00ebs dhe testet e infiltrimit - k\u00ebto jan\u00eb t\u00eb dh\u00ebna shum\u00eb t\u00eb vlefshme, t\u00eb cilat mund t\u00eb na ofrojn\u00eb hipoteza t\u00eb forta p\u00ebr shkak se ato mb\u00ebshteten n\u00eb nj\u00eb infrastruktur\u00eb t\u00eb caktuar me defektet e saj specifike.<\/p>\n<h2>Procesi i verifikimit t\u00eb hipotezave<\/h2>\n<p>\nSergei Soldatov paraqiti<noindex><a rel=\"nofollow\" href=\"http:\/\/reply-to-all.blogspot.com\/2016\/10\/bis-summit.html\"> nj\u00eb diagram t\u00eb mir\u00eb<\/a><\/noindex> me nj\u00eb p\u00ebrshkrim t\u00eb detajuar t\u00eb procesit, ai ilustron procesin e verifikimit t\u00eb hipotezave TH n\u00eb nj\u00eb sistem t\u00eb ve\u00e7ant\u00eb. Do t\u00eb p\u00ebrmend hapat kryesor\u00eb me nj\u00eb p\u00ebrshkrim t\u00eb shkurt\u00ebr.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/62721f0baea687467566949b4d22c4d2.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\">Burimi<\/a><\/noindex> <\/p>\n<p><b>Hapi 1: TI Farm<\/b><\/p>\n<p>N\u00eb k\u00ebt\u00eb hap, \u00ebsht\u00eb e nevojshme t\u00eb identifikohen <b>objektet<\/b> (duke i analizuar ata s\u00eb bashku me t\u00eb gjitha t\u00eb dh\u00ebnat p\u00ebr k\u00ebrc\u00ebnimet) duke u dh\u00ebn\u00eb etiketat e karakteristikave t\u00eb tyre. Kjo \u00ebsht\u00eb nj\u00eb skedar, URL, MD5, proces, utilitar, ngjarje. Duke i kaluar ata p\u00ebrmes sistemeve t\u00eb Threat Intelligence, \u00ebsht\u00eb e nevojshme t\u00eb ngjiten etiketat. Pra, ky website u vu re n\u00eb CNC n\u00eb vitin e caktuar, ky MD5 ishte i lidhur me nj\u00eb malware t\u00eb caktuar, ky MD5 u shkarkua nga nj\u00eb website q\u00eb shp\u00ebrndante malware.<\/p>\n<p><b>Hapi 2: Raste<\/b><\/p>\n<p>N\u00eb hapin e dyt\u00eb, shikojm\u00eb nd\u00ebrveprimin nd\u00ebrmjet k\u00ebtyre objekteve dhe identifikojm\u00eb lidhjet mes t\u00eb gjitha k\u00ebtyre objekteve. Marrim sisteme t\u00eb etiketuar, t\u00eb cilat b\u00ebjn\u00eb di\u00e7ka t\u00eb keqe.<\/p>\n<p><b>Hapi 3: Analisti<\/b><\/p>\n<p>N\u00eb hapin e tret\u00eb, rasti i kalon nj\u00eb analisti me p\u00ebrvoj\u00eb, i cili ka nj\u00eb p\u00ebrvoj\u00eb t\u00eb madhe n\u00eb analiz\u00eb, dhe ai jep verdiktin. Ai analizon deri n\u00eb bit, \u00e7far\u00eb, nga ku, si, p\u00ebrse dhe pse e b\u00ebn ky kod. Ky trup ishte malware, kjo kompjuter ishte infektuar. Zbulon lidhjet mes objekteve, merr n\u00eb shqyrtim rezultatet e prov\u00ebs p\u00ebrmes sandbox.<\/p>\n<p>Rezultatet e pun\u00ebs s\u00eb analistit transmetohen m\u00eb tej. Digital Forensics shqyrton imazhet, Malware Analysis heton \u00abtrupat\u00bb e gjetur, nd\u00ebrsa ekipi i Incident Response mund t\u00eb shkonte n\u00eb vend dhe t\u00eb hetonte di\u00e7ka atje. Rezultati i pun\u00ebs do t\u00eb jet\u00eb nj\u00eb hipotez\u00eb e konfirmuar, nj\u00eb sulm i identifikuar dhe rrug\u00ebt p\u00ebr t'i b\u00ebr\u00eb ball\u00eb k\u00ebtij sulmi.<\/p>\n<p><img decoding=\"async\" alt=\"Threat Hunting, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve\" src=\"\/wp-content\/uploads\/2019\/04\/94dcee9918011a6f7c32551c09a6e600.gif\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" href=\"https:\/\/www.flickr.com\/photos\/megane_wakui\/22066181186\/\">Burimi<\/a><\/noindex><br \/>\n \u00a0<\/p>\n<h2>P\u00ebrfundime<\/h2>\n<p>\nThreat Hunting \u00ebsht\u00eb nj\u00eb teknologji relativisht e re, e cila \u00ebsht\u00eb n\u00eb gjendje t\u00eb p\u00ebrballet efektivisht me k\u00ebrc\u00ebnime t\u00eb personalizuara, t\u00eb reja dhe jo-standard, e cila ka perspektiva t\u00eb m\u00ebdha duke marr\u00eb parasysh rritjen e numrit t\u00eb k\u00ebtyre k\u00ebrc\u00ebnimeve dhe kompleksitetin n\u00eb infrastruktur\u00ebn korporative. K\u00ebsaj teknologjie i nevojiten tre p\u00ebrb\u00ebr\u00ebs: t\u00eb dh\u00ebnat, mjetet dhe analist\u00ebt. P\u00ebrdorimi i Threat Hunting nuk kufizohet vet\u00ebm n\u00eb parandalimin e k\u00ebrc\u00ebnimeve. Nuk duhet t\u00eb harrojm\u00eb se gjat\u00eb procesit t\u00eb k\u00ebrkimit n\u00eb infrastruktur\u00ebn ton\u00eb, ne analizojm\u00eb pika t\u00eb dob\u00ebta nga k\u00ebndv\u00ebshtrimi i nj\u00eb analisti specialist n\u00eb fush\u00ebn e siguris\u00eb dhe mund t'i forcojm\u00eb ato m\u00eb tej.<\/p>\n<p>Hapat e par\u00eb q\u00eb, sipas mendimit ton\u00eb, duhet t\u00eb nd\u00ebrmerren p\u00ebr t\u00eb filluar procesin e TH n\u00eb organizat\u00ebn tuaj.<\/p>\n<ol>\n<li>T\u00eb kujdesesh p\u00ebr mbrojtjen e pikave t\u00eb fundit dhe infrastruktur\u00ebs rrjetore. T\u00eb kujdesesh p\u00ebr dukshm\u00ebrin\u00eb (NetFlow) dhe kontrollin (firewall, IDS, IPS, DLP) t\u00eb t\u00eb gjitha proceseve n\u00eb rrjetin tuaj. T\u00eb njoh\u00ebsh rrjetin t\u00ebnd nga routeri kufitar deri te hosti m\u00eb i fundit.<\/li>\n<li>Studioni.<noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/\"> MITRE ATT&amp;CK<\/a><\/noindex>.<\/li>\n<li>T\u00eb kryeni teste t\u00eb rregullta pen-test t\u00eb t\u00eb pakt\u00ebn burimeve t\u00eb jashtme ky\u00e7e, t\u00eb analizoni rezultatet e tij, t\u00eb identifikoni objektivat kryesore p\u00ebr sulm dhe t\u00eb mbyllni vulnerabilitetet e tyre.<\/li>\n<li>T\u00eb implementoni nj\u00eb sistem Threat Intelligence me kod burimor t\u00eb hapur (p\u00ebr shembull, MISP, Yeti) dhe t\u00eb b\u00ebni analiz\u00ebn e log\u00ebve s\u00eb bashku me t\u00eb.<\/li>\n<li>T\u00eb zhvilloni nj\u00eb platform\u00eb p\u00ebr reagimin ndaj incidenteve (IRP): R-Vision IRP, The Hive, nj\u00eb sandbox p\u00ebr analizimin e skedar\u00ebve t\u00eb dyshimt\u00eb (FortiSandbox, Cuckoo).<\/li>\n<li>T\u00eb automatizoni proceset rutin\u00eb. Analiza e log\u00ebve, hapja e incidenteve, njoftimi i personelit \u2013 nj\u00eb fush\u00eb e madhe p\u00ebr automatizim.<\/li>\n<li>T\u00eb m\u00ebsoni t\u00eb bashk\u00ebpunoni efektivisht me inxhinier\u00ebt, zhvilluesit, mb\u00ebshtetje teknike p\u00ebr t\u00eb punuar s\u00eb bashku mbi incidentet.<\/li>\n<li>T\u00eb dokumentoni t\u00eb gjith\u00eb procesin, pikat ky\u00e7e, rezultatet e arritura, n\u00eb m\u00ebnyr\u00eb q\u00eb t\u00eb ktheheni tek ato m\u00eb von\u00eb ose t\u00eb ndani k\u00ebto t\u00eb dh\u00ebna me koleg\u00ebt;<\/li>\n<li>T\u00eb kujdeseni p\u00ebr aspektin social: q\u00ebndroni t\u00eb informuar p\u00ebr at\u00eb \u00e7far\u00eb ndodh me punonj\u00ebsit tuaj, k\u00eb keni pun\u00ebsuar dhe kujt i jepni akses te burimet informacionit t\u00eb organizat\u00ebs.<\/li>\n<li>T\u00eb jeni n\u00eb dijeni t\u00eb trendeve n\u00eb fush\u00ebn e k\u00ebrc\u00ebnimeve t\u00eb reja dhe m\u00ebnyrave p\u00ebr t'u mbrojtur, p\u00ebr t\u00eb rritur nivelin tuaj t\u00eb njohurive teknike (p\u00ebrfshir\u00eb n\u00eb pun\u00ebn e sh\u00ebrbimeve IT dhe sistemeve), t\u00eb vizitoni konferenca dhe t\u00eb flisni me koleg\u00ebt.<\/li>\n<\/ol>\n<p>\nJam i gatsh\u00ebm t\u00eb diskutoj organizimin e procesit TH n\u00eb komentet.<\/p>\n<p><b class=\"spoiler_title\">Ose ejani t\u00eb punoni me ne!<\/b><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-31.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Konsulenti kryesor p\u00ebr sigurin\u00eb informacionit<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-163.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Arkitekti i sistemit p\u00ebr sigurin\u00eb e informacionit<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-4.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Inxhinieri kryesor i siguris\u00eb rrjetit<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-136.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Inxhinieri kryesor i siguris\u00eb s\u00eb informacionit (SIEM)<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/job.lanit.ru\/vacancy\/Pages\/MM-100.aspx?utm_source=habr&amp;utm_medium=post-2019-04-16&amp;utm_campaign=dsi\">Arkitekti i siguris\u00eb (aplikues)<\/a><\/noindex><\/li>\n<\/ul>\n<p>\n<b class=\"spoiler_title\">Burimet dhe materialet p\u00ebr studim<\/b><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"http:\/\/threathunter.guru\/\">threathunter.guru<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/attack.mitre.org\/\">attack.mitre.org<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/digital-forensics.sans.org\/summit-archives\/cti_summit2014\/The_Diamond_Model_for_Intrusion_Analysis_A_Primer_Andy_Pendergast.pdf\">digital-forensics.sans.org<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/resources.infosecinstitute.com\/category\/enterprise\/threat-hunting\/\">resources.infosecinstitute.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.redcanary.com\/blog\/threat-hunting-not-a-magical-unicorn\/\">www.redcanary.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.cybereason.com\/blog\/blog-the-eight-steps-to-threat-hunting\">www.cybereason.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/generation-hypotheses-Threat-Hunting\">www.anti-malware.ru<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.anti-malware.ru\/analytics\/Technology_Analysis\/Cyber-Threat-Hunting-Data-Science\">www.anti-malware.ru<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"http:\/\/reply-to-all.blogspot.com\/2016\/10\/bis-summit.html\">reply-to-all.blogspot.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/lukatsky.blogspot.com\/2016\/11\/threat-hunting.html\">lukatsky.blogspot.com<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/whitepapers.theregister.co.uk\/paper\/view\/6965\/threat-hunting-for-dummies\">whitepapers.theregister.co.uk<\/a><\/noindex><\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/lanit\/blog\/447580\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435. \u041e\u043d\u0438 \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0442 70% \u0440\u0438\u0441\u043a\u0430 \u0434\u043b\u044f \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0432 \u0441\u0438\u043b\u0443 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u043e\u0447\u0435\u043d\u044c \u043d\u0435\u043f\u0440\u043e\u0441\u0442\u043e \u0438\u0445 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0442\u044c \u0438 \u0443\u0436 \u0442\u0435\u043c \u0431\u043e\u043b\u0435\u0435 \u043e\u0442 \u043d\u0438\u0445 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f. \u041f\u0440\u0438\u043c\u0435\u0440\u0430\u043c\u0438 \u00ab\u0447\u0435\u0440\u043d\u044b\u0445 \u043b\u0435\u0431\u0435\u0434\u0435\u0439\u00bb \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u044d\u043f\u0438\u0434\u0435\u043c\u0438\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043b\u044c\u0449\u0438\u043a\u043e\u0432 WannaCry, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23622,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-31721","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Threat Hunting, \u0438\u043b\u0438 \u041a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 5% \u0443\u0433\u0440\u043e\u0437 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:42:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:42:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47K\u00ebrkimi i K\u00ebrc\u00ebnimeve, ose Si t\u00eb mbrohesh nga 5% e k\u00ebrc\u00ebnimeve | ProHoster","description":"95% e k\u00ebrc\u00ebnimeve t\u00eb siguris\u00eb informacionit jan\u00eb t\u00eb njohura, dhe mund t\u00eb mbrohesh prej tyre me mjete tradicionale si antivirus\u00ebt, firewalled, IDS, WAF. 5% e tjera e k\u00ebrc\u00ebnimeve jan\u00eb t\u00eb panjohura dhe m\u00eb t\u00eb rrezikshme.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Threat Hunting, \u0438\u043b\u0438 \u041a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 5% \u0443\u0433\u0440\u043e\u0437 | ProHoster","og:description":"95% \u0443\u0433\u0440\u043e\u0437 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u043c\u0438, \u0438 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c\u0441\u044f \u043e\u0442 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0442\u0438\u043f\u0430 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043e\u0432, \u043c\u0435\u0436\u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432, IDS, WAF. \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0435 5% \u0443\u0433\u0440\u043e\u0437 \u2013 \u043d\u0435\u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 \u0438 \u0441\u0430\u043c\u044b\u0435 \u043e\u043f\u0430\u0441\u043d\u044b\u0435.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/threat-hunting-ili-kak-zashhititsya-ot-5-ugroz","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:42:43+00:00","article:modified_time":"2019-10-31T18:42:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31721","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 07:30:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:12:32","updated":"2026-01-21 07:30:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/31721","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=31721"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/31721\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/23622"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=31721"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=31721"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=31721"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}