https://media.blackhat.com/bh-us-12/Briefings/Flynn/bh-us-12...
The high-level takeaway is that they developed a response methodology (modeled after a military killchain) that breaks up an attack into different phases, and they then have protection (and more importantly, detection) processes in place for each phase.
The idea is that for an attack to be successful (ie: data is exfiltrated, which is predominantly the type of attack they are concerned with) that doesn't just magically happen. Each phase of the kill chain has to be bypassed, so you have multiple places to detect (and hopefully prevent) it.
You also have the benefit of asymmetrical information, which is to say, that when you stop an attack inside the kill chain, you have all the information that got them to that point, whereas they don't necessarily know why the attack was unsuccessful. That allows you to build a knowledge base specific to the attacker so that future attacks can be stopped earlier on in the process.
Lockheed's kill chain implementation (and ours as well) is lacking the last phase of response that is present in the military one (mainly: they can launch a missile strike or send tanks, whereas we are obviously slightly more limited in our response).
Basically, this process came about as a reaction to reality of the defense situation (which is that for all intents and purposes you can't actually stop them from getting into the network, you have to have a response plan to mitigate attack success that includes your systems getting compromised).
It's also not clear how Kill Chain helped at all. If they discovered the user, then they could have deactivated his credentials, right? Or are they alluding to that they use live user activity as a sorta honeypot to see if there are other compromised users?
This quote was pretty funny: "An attacker only has one time to be right to get that information out of the network" -- really? Cause I thought usually we think of it the other way around: the defenders have to only mess up once to lose.
There's lots of commercial software that will help you do this. First you have network appliances throughout your network that monitor traffic. Then you create rules and policies on the device that tracks the user, its defined role, what it should have access to, and what it is attempting to access. Then you define actions (logging, dropping the packet, ignoring it, etc) based on the rules/policies.
You can do this using open source software, too, but it takes a bit more glue code usually. A long set of iptables rules (along with free tools like Snort) could tag traffic based on the user, layer 7 protocol, and network access, and alerts could be mailed to the admins when a user over-reaches in their access.
It also seems to be in somewhat common use in secops, there's a 4-part series from 2009[2] that looks much more interesting than the indefinite article posted.
Another article from Tripwire[3] defines it as: The phrase “kill chain” describes the structure of the intrusion, and the corresponding model guides analysis to inform actionable security intelligence.
There's actually a whitepaper (PDF, ~12 pages)[4] from Lockheed-Martin about their 'kill chain' APT defence, which would be another good read about it. From their paper,
"Conventional network defense tools such as intrusion detection systems and anti-virus focus on the vulnerability component of risk, and traditional incident response methodology presupposes a successful intrusion."
and instead, they want to study analytics on the assumption the attacker can or has got in already, and wants to do something with their access. They can detect suspicious actions and do something about them, rather than keep everything suspicious out.
[1] http://www.jargondatabase.com/Category/Military/Air-Force-Ja...
[2] http://computer-forensics.sans.org/blog/2009/07/22/security-...
[3] http://www.tripwire.com/state-of-security/it-security-data-p...
[4] http://www.lockheedmartin.com/content/dam/lockheed/data/corp...
https://media.blackhat.com/bh-us-12/Briefings/Flynn/bh-us-12...
Other commenters have pointed out good resources. I particularly enjoyed reading the lockheed martin whitepaper, that comes up as the first google result for "lockheed martin kill chain", but i had to used the google cached copy as the link is now 404ing. Edit - its the same paper fname links below.
Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains -- https://www.vita.virginia.gov/uploadedFiles/VITA_Main_Public...