Cyber Security Summit 2012: Notes from Conference

Last week I attended the second annual Cyber Security Summit in downtown Minneapolis. It was well attended by Government and private sector IT folks. I tried to take fairly complete notes – and I will include those below but I wanted to include a quicker summary of major themes and recommendations that seemed to emerge.

Several speakers alluded to profiles of attacks or attackers:

  • Terrorists – persistent, determined, organized
  • Warring Nations – motivated, well sponsored, relentless, targeted
  • Hackivists, such as Anonymous – unorganized, random, irrational
  • Cyber Criminals – looking for monetary gain
  • Corporate Espionage

They outlined the anatomy of an attack:

  • Choose your target
  • Study, analyze identify
  • Plan
  • Implement (and re-use your library of pre-weaponized exploits) and test
  • Execute

They outlined some steps to take as precautions:

  • Demand better software. When you write RFPs or upgrade systems – ask for the best in terms of security.
  • Deploy pro-active defenses and total vulnerability management
  • Test what you have for unknown vulnerabilities.
  • Fuzz – process of sending intentionally invalid data to product in the hopes of the triggering an effort condition or fault.
  • Create a contingency plan
  • Deploy data-centric not system-centric security
  • Crowdsource security!
  • Use positive social engineering
  • Show value to mission by allowing risks

Cyber Security Plan:

  1. Anticipate
  2. Plan
  3. Implement and Adapt
  4. Improvise

And spoke about the kill chain analysis:

Kill Chain Analysis – Reconnaissance – Weaponization – Delivery – Exploitation – Installation – C2 – Actions

They spoke a lot about users being a weak link – both in terms of making mistakes and being lured by nefarious sources to share information they shouldn’t. And mistakes are made at all levels, low level users who don’t know the risk and IT folks who get complacent.

And there was talk of security at a higher level. Everyone expressed a need for communication among security professionals. It’s important to share information on attacks or disruptions both in terms of helping recognize trends and in terms of sharing warning and advice with others. There was a lot of discussion about how much info to share. No one wants to give away any trade secrets or admit to too much damage. There was also talk of the role of government. Everyone seemed to agree that there is a role for government – but is that role to coordinate communication efforts not necessarily to actually mandate security standards.

In a funny way it was like listening to parents of grade school kids. When someone else’s kid is sick or maybe a better analogy, has lice – I want the school to make them stay at home until it’s fixed and I want to know exactly how close that kid got to mine. When my kid gets lice, I’m hoping for discretion. And the truth is while some discretion is kind, unless you want kids infecting (and re-infecting) each other parents need to know the dangers and the signs. Same as with cyber  security.

It was heartening to hear of some of the efforts that are happening, such as:

  • Center for Internet Security: a not-for-profit organization focused on enhancing the cyber security readiness and response of public and private sector entities, with a commitment to excellence through collaboration. Through its three divisions–Security Benchmarks, Multi-State ISAC and Trusted Purchasing Alliance–CIS serves as a central resource in the development and delivery of high-quality, timely products and services to assist our partners in government, academia, the private sector and the general public in improving their cyber security posture.
  • US-CERT: mission is to improve the nation’s cybersecurity posture, coordinate cyber information sharing, and proactively manage cyber risks to the nation while protecting the constitutional rights of Americans. US-CERT’s vision is to be a trusted global leader in cybersecurity – collaborative, agile, and responsive in a complex environment.

Both offer a range of services to public and private entities – such a personalized security scans and bulk email lists for sharing more general incidents and risks.

Finally it sounds like cyber security is big business. Folks were interested in developing a cluster in the Twin Cities. It would require trained people, access to research, access to businesses. To get the ball rolling, the FBI announced that they had just received word to hire new staff (Computer Science person) quickly. Contact Minneapolis FBI for more info.

And here are my more complete notes – offered asis…

Gopal Khanna

Cyber security involves all of us – it can’t be left to government. We all have a stake in managing the threat.

Massoud Amin (Technological Leadership Institute)– Building New American Prosperity through Smarter and More Secure Critical Infrastructure

18 Critical Infrastructures

  1. Ag & Food
  2. Defense Industrial Base
  3. Energy
  4. Public Health & Healthcare
  5. National Monuments & Icons
  6. Banking & financing
  7. Drinking water & Water Treatment
  8. Transportation
  9. Government Facilities
  10. Chemical
  11. Commercial Facilities
  12. Dams
  13. Emergency Services
  14. Commercial Nuclear Reactors
  15. Materials & Waste
  16. Information Technology
  17. Communication
  18. Postal & Shipping

Can enhance security and reliability?

Cyber Security Plan: Anticipate, Plan, Implement and Adapt & Improvise

MIKKO VARIPIOLA – Cyber Threat Identification – Framing the Issues

What makes us vulnerable?

  • Immature/malfunctioning processes
  • Poorly implemented software (know and unknown)

Programmers are not known for writing secure code.

What are we defending against?

  1. terrorists – persistent, determined, organized
  2. Warring Nations – motivated, well sponsored, relentless, targeted
  3. Anonymous – unorganized, random, irrational

Anatomy of a Hack

  • Choose your target
  • Study, analyze identify
  • Plan
  • Implement (and re-use your library of pre-weaponized exploits) & test
  • Execute

Why are they after us?

  • Cyber Crime is big business
  • National interests, hackivists (idealists, anarchists…)
  • Cost of entry is non-existent
  • And they may not be after you specifically

“We have strict gun laws – but no laws on who can use or buy a computer – barrier to entry for cyber-crime is low” – Mikko Varpiola

Best Practices that Aren’t Perfect: Antivirus, isolated networks, firewalls

The threats are always changing – so many layers of defense ward against threats of the past. At best they are useless.

People should recognize reasonable care with cyber security. But where is the line between best effort and negligence or liability?

We will be better off if we are self-regulated or it will get political. But that means we need to be prudent now.

How do I protect myself?

  • Demand better software. When you write RFPs or upgrade systems – ask for the best in terms of security.
  • Deploy pro-active defenses and total vulnerability management
  • Test what you have for unknown vulnerabilities.
  • Fuzz – process of sending intentionally invalid data to product in the hopes of the triggering an effort condition or fault.
  • Create a contingency plan

FAYYAZ RAJPARI – Future Opportunities in Cyber Security

Security Issues at Play

  • Strategic Importance of Information
  • Evolving Infrastructure
  • Increasing Complexity
  • Challenging Threat Landscape

APTs (Advanced Persistent Threats) have emerged and remain top of mind

  • Adversaries are evolving
  • Attack surface growing
  • Private is now public

What is APT?

  • Active, targeted, long-term campaign
  • Tries to remain in place
  • Includes multiple kill changes to ensure success
  • Mutates and adapts to evade detection
  • Very well organized
  • Embedded spy

What is a targeted attack?

  • An individual attack (drive-by-download, SQL injection)
  • Often “smash and grab” by cybercriminals for financial gain
  • May be well organized and resources
  • Like bank robber

ANDREW BORENE – Emerging Business Opportunities in Cybersecurity & Robotics

Minnesota has as many high school robotics teams as hockey teams – Andrew Borene

TINA MEIER – Protecting our Children

A wonderful presentation on the need to stop cyber bullying in the schools from the founder of Megan Meier Foundation, named for her child who committed suicide after some extreme cyber bullying. Her presentation was definitely different from the rest of the session – but a good reminder that the Internet isn’t just for government and commerce – people live real lives on the Internet too.

RESEARCH TO REALITY

Should we establish a cyber-security hub in the Twin Cities? What are the barriers?

  • Shortage of cyber-security experts
    • Dep of Defense pays for cyber-security degrees
    • National Security Agency – sponsoring programs all over US
    • NSA – has intern programs & fellowships for students
    • Make it attractive for programs to come into Minnesota
    • Money makes things happen
      • Not as easy
      • CFIOs should get together to talk about biggest problems
      • Hire new professions who have cyber-security PhDs
      • Require every software/engineer graduate to take cyber-security classes and hacking classes

In the startup world – most cyber-security companies are in Silicon Valley, Boston, and Washington DC corridor.

Core companies spin off talent.

Is there a need for cyber-security concentration in MN?

  • NSA is focused on fundamental science. And they look at interdisciplinary programs

Patrick Reidy, CISO, Federal Bureau of Investigation

Evolution Information Assurance

Bots & Viruses – people who want to make us a zombie-bot

  • 40% of incidents
  • 10% of time
  • Addresses with automated recovery is pretty easy
  • 99% of email traffic coming at FBI is spam and trash

Accidental Data Loss

  • 24% of incidents
  • 35% of time
  • Addressed with training, campaigns and social engineering

Cyber Intrusion

  • 12% of incidents
  • 10% of time
  • Criminal groups
  • Less of a concern to FBI than private sector

Hackivists (Anonymous)

  • 15% of incidents
  • 5% of time
  • Mass organization of previous disparate groups
  • Increased capabilities through automation of DDOS attacks

APT

  • 5% of incidents
  • 10% of time (I think – hard for me to read)
  • Intelligence operation against your organization
  • The have personal knowledge of org or person
  • Their techniques aren’t necessarily advanced

The Insider

  • 18% of incidents
  • 22% of time
  • Not the most common threat, but most damaging
  • The most challenging to combat

Rapid Technology Adoption

  • Cloud – that means outsourcing your data
  • Intellectual Property loses something in the cloud

Solutions

  • Evolved beyond cyber
  • Deploy data-centric not system-centric security
  • Crowdsource security!!
  • Use positive social engineering
  • Show value to mission by allowing risks

How do they deal with risks:

Threats use same tactics. Lots of variability early on, but as attack advances, variability drops. Enables kill-chain analysis.

Kill Chain Analysis – Reconnaissance – Weaponization – Delivery – Exploitation – Installation – C2 – Actions

http://www.lockheedmartin.com/content/dam/lockheed/data/corporate/documents/LM-White-Paper-Intel-Driven-Defense.pdf

Know your people.

Know your data.

Show value.

Next Evolution of Threats

  • Move toward mobile
  • APT organization and advancement targeting business and government
  • Criminal elements learning from APT: increased intelligence operations

Summary

  • Spam is spam
  • APT is an intelligence operation against you
  • The insider is the most damaging potential threat
  • Focus on threats and their capabilities
  • Crowdsource security.

What’s the US advantage?

The US has some of the best thought leaders. We have a competitive advantage. There are other nations that are active. Think quality vs quantity.

THOMAS DUFFY – Center for Internet Security

Multi-State ISAC

  • Every state is required to have a homeland security advisor.
  • Have focused on state government in last few years
  • Now we’re looking at local governments
    • Started with state capitals and larger counties
    • 25% of US population is part of the org
    • Develop trust and share info
    • Provide support, keep repositories of issues and fixes
    • No cost to members
    • Want to share info with other sectors
    • Strict rules for sharing info shared by members
      • Share, share without attribution, share with attribution
      • Color-coded map of states tracks security issues in real time
      • Will help monitor your system and will send very specific and detailed reports
      • Will help provide responses to attacks.

National Security = Cyber security + Economic security + Homeland security

Who is behind threats?

  • Cyber Criminals
  • Hackivists
  • Corporate Espionage
  • Nation States

How do they get into our networks?

  • Software Vulnerability
  • Insecure Applications
  • Phishing
    • Getting sophisticated and personalized
    • 1 in 8 sites related to Emma Watson has malware
    • Gullible Users

Security of mobile medical devices

National Cybersecurity and Communications Integration Center

  • Survey what’s happening across the country
  • Big players in telecommunications are there
  • It’s about sharing information
    • Difficult for private sector

What are criminals looking for from government?

  • Personal records (birth cert, SSN, school, medical…)
  • System File Access Attempts increased by 91% (US, Poland France)
  • Brute Force Logins increased 36% (US, Korea)

Top Concerns for State and Local Governments

  • Law Enforcement (start with Law Enforcement Associations – hoping someone will use the same username/password for work system)
    • Remind staff not to use work password anywhere else
    • Bank Account Compromise
      • Zeus – targets credentials used for financial institutions
      • Think about who is authorized to make wire transfers
      • No triggers for overseas deposits
      • Europe requires two forms of verification
      • Ransomeware
        • Your computer is frozen
        • A message appears that all your files are encrypted and it will cost you $200 for the encryption key

Summary

  • Don’t become complacent
  • Have policies in place and methods to monitor compliance
  • Be a champion for cyber security in your organization – and encourage security at home!
  • Cyber Security is everyone’s responsibility

NICK SELBY – Building

Intelligence is sharing info and talking to each other.

Legislative Intelligence – pay attention

Small Business v Bank à Zeus ACH à Not commercially reasonable à US Bank

  • Have a direction
  • You need to know what you’re looking for!
  • Look for patterns, need to throw away bad stuff.
  • Iterative process
  1. Plan – Set the Strategy
    1. What do you want your intelligence to do? Start with an easy win.
    2. Somebody has to run the effort (get someone with experience)
    3. Leverage
    4. Gather – Define and augment sources
      1. Know the people who have info  that they aren’t sharing
      2. Think of how it can feed your strategy
      3. www.Policeledintelligence.com

i.      OSINT (Open Source Intelligence)

ii.      Google Hacking for penetration testers

  1. Analyze – Understand the limitations (what don’t I see?)
    1. Look for info you can leverage
    2. Make sure you don’t have info before you pay for it
    3. Put yourself in the middle
    4. Encourage and Train
    5. Empower Analysis
    6. Staff Right
    7. Disseminate – People have to read it
      1. Give it to someone with respect
      2. Aim small, miss small
      3. Presented soberly

Common Barriers

  • Executive buy in
  • Lack of metrics
  • Chambers of Excellence
  • Lack of Planning
  • Lack of analysis
  • Dissemination

Regular way

  • Shut it down
  • Peasant revolt
  • Acceptance

Social media is good for right of boom information

NEW SESSION: TRUST IN THE CLOUD – http://www.nist.gov/nstic/

What do you see as biggest challenge to creating ID ecosystem?

James S –

  • Liability
    • You accept an ID from a third party – who is liable
    • Bad addresses cost UPS $2 million; who do I blame for bad chipped in address?
    • Business needs
    • Find clear value proposition

James R –

  • Getting stakeholders to agree
  • We have to understand each other

Ian –

  • Technology innovators think they have the protocol we need
  • Policy innovators aren’t so sure

Thoughts on what need to be done to garner trust

James R –

  • Outsourcing agreement– it will describe terms of liability
  • Now there’s be a third party in the middle of the transaction, that means everyone has outsourced a portion of the transaction
  • In business we trust contracts

Ian –

  • Trust framework is nominal agreement for rules of engagement
    • They are scaffolding and as such the general public doesn’t need to know about it
    • Will need cultural lessons – how do we normalize the behavior
      • Make yourself ready to credential others
      • Right now Facebook is a sort of a third party

James S –

  • Get representatives from a variety of sectors
  • The tools here come from private sector
  • We’ve progresses from ATMs that only suit certain cards – not ATM use is pretty ubiquitous
  • Online stores are losing business when they require shoppers to create an account

This is a people’s plan – the government and private sector are involved but the government is not driving it!

Centralizing data – been happening in private sector for years.

FORTUNE 500 PRESPECTIVE

  • We’re OK with physical threats – less good with cyber security
  • People want to know the solutions, not so much the problems
  • We don’t compete on security
  • There are ways to share info without giving away the game

Best Practices

  • Helpful to get info in terms of “what are other people doing”
    • Be nice to have a more efficient way to do that
    • Getting info on what’s happening with our industry
      • Eg. What are others dong with patient data?
      • Unstructured sharing/communication is helpful
      • Trends and real time (Strategic/operational) are the two facets
      • Need custom solutions

How do you decide what will work for you?

  • Verizon annual data breech reports
    • Threats are different for each sector
    • Give me a way to be knowledgeable with what the options are (need toolkit with treatment options)
    • Also valuable to know what didn’t work

What keeps you from being open

  • Don’t want to give away intellectual property
  • Don’t want to explain ourselves
  • Regulation (HIPPA)

What’s the time issue

  • We want responses in seconds in private sector so we need automation, which requires availability
    • How secure vs how available?
    • Data can travel quickly knowledge can’t
    • We can’t move fast enough but we’re getting faster
    • More people care about security now – it’s part of everyone’s job
    • Security is everyone’s responsibility – pointing out spam and computer anomalies
    • Companies are as fast as they have to be
      • Sharing include 3 things: Common language, info has to be available to everyone, needs an incentive

NOTE: Homeland security has set up a number of tools to help coordinate sharing

  • Business ISAC – (SFISAC) pretty active – people are sharing very specific and detailed info
  • RENISAC – for universities
  • The ISAC model is effective
  • Not many heterogeneous groups – but good in sectors

Data can travel quickly knowledge can’t – perhaps that’s where security automation/data trends recognition tools come in?

  • Important to research failures/incidents
  • Failure is in the eye of the beholder – the incident may cost $100,000; the prevention may cost $1 million

What are the protocols of what to share?

  • Regulation
  • How much I trust the person is receiving it?
  • There may be a contract to decide
  • It’s difficult
  • When we share strategic info – we don’t necessarily need to use names. We just need enough details to be applicable.
  • Anonymity is easier with larger numbers

How do you measure how severe something is?

  • Determine how pervasive it is vs total population
  • Does lack of sharing come back to bite you?
  • Technical attacks are easier to report because they are more generic
  • The personalized attacks are more difficult to report because it reveals more about the org

Tips

  • You have to share
  • Give a full picture – including context
  • You should be inquisitive, quick learner, ask why, why, why?

Challenges

  • Integrating info in a way that makes sense – we have more data than we can deal with
    • Standardization of data is helpful
    • Need more people to insist on readability
    • Industry consolidation will help
    • Don’t be a dumbass

MARK WEATHERFORD

US Cert – can work with private companies http://www.us-cert.gov/

  • 106,000 incident reports in 2011
  • Average 14 alerts per day
  • Malware analysis

Cyber Physical Nexus is getting more attention

Media are watching cyber-security

There are key parts of the government that are dependent on private sector for electricity, food…

Industrial Control Assistance

Cyber Security Valuation

Cyber Education program called NICE (w/NIST)

This entry was posted in Conferences, MN, Policy by Ann Treacy. Bookmark the permalink.

About Ann Treacy

Librarian who follows rural broadband in MN and good uses of new technology (blandinonbroadband.org), hosts a radio show on MN music (mostlyminnesota.com), supports people experiencing homelessness in Minnesota (elimstrongtowershelters.org) and helps with social justice issues through Women’s March MN.

Leave a Reply