Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ASN Related Enrichment Suggestions for Trustworthy Email Reports using WhoIs #147

Open
1 task
brian-chesney-usps opened this issue Feb 9, 2024 · 0 comments

Comments

@brian-chesney-usps
Copy link

Some suggestions for enrichment of the ASN information in the Trustworthy Email Reports dmarc_failures.csv using WhoIs lookups#

We would like to see additional data added that would enrich the usage of the ASN information and reduce manual enrichment and analysis efforts by SOC personnel.

Motivation and context

The ASN information is valuable but requires additional manual work to make it more useful.

This would be useful because...the ASN information is extremely helpful in aggregating the network information, identifying the owner of the source for DMARC failures, and developing historical trends. This additional information helps us pursue DMARC failures that are indicative of campaign activity.

Implementation notes

We would like to see the following.

  1. Error checking for the ASN value that would identify and adjust when the ASN lookup in the BGP routing tables have empty return values. This has happened to us because a Microsoft owned network ASN was not propagated in BGP routing tables. When a blank ASN value is detected, we suggest an additional check using a tool like WhoIs to identify the applicable ASN for the source IP address.

  2. Enrich Report using other information from WhoIs. This would help reduce manual enrichment by applying columns for Organization owner names and country of origin for the ASNs. This information helps us identify when entities of interest are triggering DMARC failures. Our security teams are very interested in DMARC failures that are sourced from atypical entities like foreign countries. While they are failures, they also represent a higher likelihood of malicious Email campaigns that could provide valuable OPSEC information.

Acceptance criteria

How do we know when this work is done?
When we see additional columns added to the dmarc_failures.csv that we can use in PIVOT tables and other tools to help identify trends and anomalies.

  • Criterion - Nothing to add.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant