Thursday, September 22, 2011

Seek First to Understand

Taking a step back and truly understanding what you're looking at when analyzing network traffic is extremely important.  There are quite a few people who can look for and analyze a well-defined, known threat.  But what happens when attackers change tactics, or a new type of attack is encountered for the first time?  It requires the analyst to take a step back, think deeply, and truly understand what is going on.  This is a rare skill, but one that is invaluable.  This type of thinking/mindset is what we as a community need more of in order to rise to the challenges we are confronted with on a continual basis.  Long live the deep thinker.

