Observable Confidence in ThreatStream

Observable details pages often aggregate information about an observable coming from multiple sources. Feeds, trusted circles, user imports, sandbox detonations, and more can provide varying data on the same observable value. Confidence—the confidence a data source has that the observable exhibits or is connected to malicious behavior—is one such data piece. Therefore, confidence appears in multiple places on observable details pages. This article describes what each of these confidence scores are, where they come from, and how to use them.

Taken together with severity, which gauges the potential impact of the indicator type the observable is thought to be associated with, confidence helps form a high-level judgment on individual observables that can be used for prioritizing threat research. Indicator types in ThreatStream are mapped to one of four severity values: low, medium, high, and very-high.

Overview Confidence

The first confidence score you see on observable details pages is the score included in the overview section at the top of the page.

This confidence score is assigned to the observable by ThreatStream. If the page includes information from multiple sources, the overview section displays the highest confidence score of the available instances in active state. See ThreatStream Assigned Confidence for information on how these values are calculated.

Confidence in the Intelligence Table

The Intelligence table on observable details pages displays all available instances of a single observable as reported by various sources. Each instance has a Confidence score and a Source Reported Confidence score.

ThreatStream Assigned Confidence

Values in the Confidence column are assigned to the observable instance by ThreatStream. These confidence values are determined either in part or in whole by Anomali ThreatStream's machine learning-based threat intelligence engine.

With regard to observables imported directly into ThreatStream or from a user-created stream, the ThreatStream assigned confidence score is determined entirely by Anomali’s machine learning algorithms—unless users manually specify a confidence value and select Override System Confidence during import or stream creation.

Note: Anomali machine learning algorithms only score observables assigned Domain, IP, and URL indicator types. When all other observables—those assigned email, hash, or string indicator types—are imported through the import assistant or a feed, confidence values specified on the confidence slider are used, even if Override System Confidence is not selected.

With regard to observables ingested from premium or open-source threat intelligence feeds which are not configured by users, the ThreatStream assigned confidence score is a combination of the confidence score calculated by machine learning algorithms and the Source Reported Confidence score. Each feed or source is assigned a weight at which the source and ThreatStream machine learning confidence scores are mixed. This ratio is set by Anomali and varies across sources.

Source Reported Confidence

Source Reported Confidence, as indicated by its name, is a confidence value assigned to an observable by its source. As alluded to above, data originates from an array of sources. Therefore, Source Reported Confidence values can be assigned by premium feed providers, open source feeds, or individual analysts manually importing data—among others. ThreatStream ingests Source Reported Confidence scores and displays the values to users as-is, without alteration.