Configuring Indicator Confidence Deprecation

Last Updated: Oct 29, 2018 02:17PM EDT
Organization Administrator
None

Overview

Indicator Confidence Deprecation is a great way to allow ThreatConnect® Indicators to drop in Confidence Rating over time if the Confidence Rating is not being maintained and updated. Deprecation is used in the case of an Indicator, such as an IP Address, that is no longer being used for any malicious activity for a certain amount of time. ThreatConnect will drop the Confidence Rating, assuming that the Indicator is dormant or that the threat actor has ceased using it.

NOTE: The only factor that affects Indicator Confidence Deprecation is Confidence Rating. If the Confidence Rating for an Indicator is not updated within the amount of time configured in the applicable Deprecation Rule, then the Confidence Rating will be deprecated accordingly.

Steps

  1. On the top navigation bar (Figure 1), hover the cursor over the Settings icon and select ORG CONFIG from the dropdown menu (Figure 2).
  2. The Organization Config screen will appear (Figure 3).
  3. Click the Deprecation Rules tab, and the Deprecation Rules screen will appear (Figure 4).
  4. To create a new Deprecation Rule, click the + NEW button, and the Create/Edit Deprecation Rule window will appear (Figure 5).
    • Indicator Type: Use the dropdown menu to choose the type of Indicator to which the Deprecation Rule is to apply.
    • Confidence: Use the plus and minus buttons to enter the amount by which the Confidence Rating should decrease if not updated by a ThreatConnect user. The number may also be entered manually.
    • Percentage: Check this box to use the value entered in the Confidence box as a percentage instead of a numerical value. For example, if the Confidence is 5 and Percentage is unchecked, the Confidence Rating will drop by a value of 5 (e.g., from 60 to 55) when it is deprecated. If the Confidence is 5 and Percentage is checked, the Confidence Rating will drop by 5% (e.g., from 60 to 57).
    • Action at Minimum: Use the dropdown menu to select the action that should be taken when the Confidence Rating of the Indicator drops to 0. The options are None, Set Inactive (see Indicator Status for more information), and Delete.
    • Interval: Use the plus and minus buttons to enter the number of days after which the Confidence Rating should decrease if not updated by a ThreatConnect user. The number may also be entered manually.
    • Recurring: Check this box for the Deprecation Rule to be applied on a recurring basis instead of just once.
  5. Click the SAVE button to create the new Deprecation Rule.

20039-07 EN Rev. B

Contact Us

  • ThreatConnect, Inc.
    3865 Wilson Blvd.
    Suite 550
    Arlington, VA 22203

    Toll Free:   1.800.965.2708
    Local: +1.703.229.4240
    Fax +1.703.229.4489

    Email Us



https://cdn.desk.com/
false
desk
Loading
seconds ago
a minute ago
minutes ago
an hour ago
hours ago
a day ago
days ago
about
false
Invalid characters found
/customer/en/portal/articles/autocomplete