Secure Firewall Threat Intelligence Director
Secure Firewall Threat Intelligence Director is a threat defense feature that
-
operationalizes threat intelligence data to help aggregate intelligence data and configure defensive actions,
-
analyzes threats in your environment, and
-
supplements other Secure Firewall functionality, offering an additional line of defense against threats.
Threat intelligence data flow and components
When configured on your hosting platform, Threat Intelligence Director ingests data from threat intelligence sources and publishes the data to all configured managed devices (elements.) For more information about the hosting platforms and elements supported in this release, refer to Platform, element, and license requirements.
Sources contain indicators, which contain observables. An indicator conveys all characteristics associated with a threat. Individual observables represent specific characteristics associated with the threat, such as an SHA-256 value.
-
Simple indicators: Contain a single observable
-
Complex indicators: Contain two or more observables
Observables and the AND/OR operators between them form an indicator's pattern, as illustrated in this example.

After the observables are published to the elements, the elements monitor traffic and report observations to the Firewall Management Center when the system identifies observables in traffic.
The Firewall Management Center collects observations from all elements, evaluates the observations against Threat Intelligence Director indicators, and generates or updates incidents associated with the observable's parent indicator(s).
An incident is fully realized when an indicator's pattern is fulfilled. An incident is partially realized if traffic matches one or more observables in the indicator but not the entire pattern. For more information, see Observation and incident generation.
This diagram shows data flow in a sample system configuration.

When a Threat Intelligence Director incident is fully or partially realized, the system takes the configured action (monitor, block, partially block, or no action). For details, refer to Factors that affect the action taken.
Threat Intelligence Director and Security Intelligence
Security Intelligence is a threat blocking feature that uses reputation intelligence to quickly block connections to or from IP addresses, URLs, and domains as part of your access control policy.
Security Intelligence uniquely provides access to industry-leading threat intelligence from Talos Intelligence Group. For more information on Security Intelligence, refer to Security intelligence.
Threat Intelligence Director enhances the system's ability to block connections based on security intelligence from third-party sources as follows:
-
Threat Intelligence Director supports additional traffic filtering criteria—Security Intelligence allows you to filter traffic based on IP address, URL, and (if DNS policy is enabled) domain name. Threat Intelligence Director also supports filtering by these criteria and adds support for filtering on SHA-256 hash values.
-
Threat Intelligence Director supports additional intelligence ingestion methods—With both Security Intelligence and Threat Intelligence Director, you can import threat intelligence into the system by either manually uploading flat files or configuring the system to retrieve flat files from a third-party host. Threat Intelligence Director provides increased flexibility in managing those flat files. In addition, Threat Intelligence Director can retrieve and ingest intelligence provided in Structured Threat Information eXpression (STIX™) format.
-
Threat Intelligence Director provides granular control of filtering actions—With Security Intelligence, you can specify filtering criteria by network, URL, or DNS object. Security Intelligence objects, especially lists and feeds, can contain multiple IP addresses, URLs, or DNS domain names, but you can only block or not block based on entire objects, not on individual components of an object. With Threat Intelligence Director, you can configure filtering actions for individual criteria (that is, simple indicators or individual observables).
-
Threat Intelligence Director configuration changes do not require redeployment—After you modify Security Intelligence settings in the access control policy, you must redeploy the changed configuration to managed devices. With Threat Intelligence Director, after initial deployment of the access control policy to the managed devices, you can configure sources, indicators, and observables without redeploying, and the system automatically publishes new Threat Intelligence Director data to the elements.
For information about what the system does when either Security Intelligence or Threat Intelligence Director could handle a particular incident, refer to Threat Intelligence Director - Firewall Management Center action prioritization.
Performance impact of Threat Intelligence Director
This reference provides information about the performance impacts that may occur when using Threat Intelligence Director with your security infrastructure.
Secure Firewall Management Center
In some cases, you may notice the following:
-
The system may experience minor performance issues while ingesting particularly large STIX sources, and ingestion may take longer than expected to finish.
-
The system may take up to 15 minutes to publish new or modified Threat Intelligence Director data down to elements.
Managed device
There is no exceptional performance impact. Threat Intelligence Director impacts performance identically to the Secure Firewall Management Center Security Intelligence feature.


)
)

)
)
Feedback