COVER story
The biggest change we are seeing is the speed at which attackers can operate. An attacker can research a target, identify its infrastructure, operationalise a vulnerability and rotate to new infrastructure much faster than before. We have seen research citing around 29 minutes as the time it can take an attacker to complete an attack.
That speed puts enormous pressure on SOC teams. We speak to customers who tell us that their analysts can spend days, weeks or even months conducting investigations. Even after that effort, they may still lack the context required to make a decision confidently and back it up with facts.
If an analyst receives an alert relating to an IP address or domain, a reputation score alone is no longer sufficient. By the time they investigate that IP address, the infrastructure may have disappeared or the attacker may already have moved elsewhere.
SOC teams therefore need to understand the infrastructure behind the attack. What else is associated with it? How has it changed over time? Does it connect to broader malicious activity? Is it a one-off incident or part of a larger campaign?
That is where Internet intelligence becomes part of the investigation itself.
At Censys, we do not look at an IP address in isolation. We correlate information to identify the wider infrastructure and context associated with an attack. This gives analysts the external context they need for faster triage, more effective investigations and better defence decisions.
It also means analysts can work with real-time intelligence rather than relying solely on outdated information that may no longer be relevant. If an analyst needs to look back in time to see what an IP address looked like during the attack, Censys gives you the ability to see 2 + years of historical Internet intelligence so that you can see how the IP address and underlying infrastructure has changed over time. They can then hunt beyond the original indicators and identify related infrastructure that could represent additional risk.
For example, an organisation might initially identify malicious activity from one IP address. By understanding the infrastructure associated with that activity, we can surface additional IP addresses and indicators that security teams can investigate, flag or potentially block.
Ultimately, Internet intelligence is about giving SOC teams the context and visibility they need to move at the speed of the attacker, enabling them to respond faster and, in some cases, stop an attack before it happens.
Exposure management has traditionally been about identifying and managing known assets. Do you think that approach is still sufficient? How significant is the challenge posed by unknown or unmanaged Internet-facing assets?
An internal asset inventory represents an organisation’ s management view. You know which assets you are managing and whether they require upgrades, patching or other security measures. But that is not necessarily the same as having an Internet view.
Many organisations tell us they already have asset management, but that is not enough because assets can be missed. When we conduct assessments for customers, we sometimes find that between 25 % and 30 % of assets have been overlooked. That is not because security teams are not doing their jobs. Assets can simply fall outside the organisation’ s management view.
Cloud infrastructure is a good example. Someone might spin up a cloud instance for a proof of concept and expect to shut it down after a week. The POC ends, but nobody closes the instance. It remains Internet-facing without the appropriate security measures, creating potential risk.
The same applies when developers launch services, companies make acquisitions or domains are forgotten. Something can disappear from an internal process without disappearing from the Internet.
That is where Censys’ outside-in discovery becomes valuable. We identify assets that belong, or may belong, to an organisation and are visible on the Internet. Crucially, we are looking at them from the same perspective as an attacker.
This addresses the first part of our approach: know yourself. But we do not stop at attack surface management. The same Internet intelligence supports security operations, investigations, adversary intelligence and thirdparty risk.
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 17