Last week I attended the second annual Cyber Security Summit in downtown Minneapolis. It was well attended by Government and private sector IT folks. I tried to take fairly complete notes – and I will include those below but I wanted to include a quicker summary of major themes and recommendations that seemed to emerge.
Several speakers alluded to profiles of attacks or attackers:
- Terrorists – persistent, determined, organized
- Warring Nations – motivated, well sponsored, relentless, targeted
- Hackivists, such as Anonymous – unorganized, random, irrational
- Cyber Criminals – looking for monetary gain
- Corporate Espionage
They outlined the anatomy of an attack:
- Choose your target
- Study, analyze identify
- Plan
- Implement (and re-use your library of pre-weaponized exploits) and test
- Execute
They outlined some steps to take as precautions:
- Demand better software. When you write RFPs or upgrade systems – ask for the best in terms of security.
- Deploy pro-active defenses and total vulnerability management
- Test what you have for unknown vulnerabilities.
- Fuzz – process of sending intentionally invalid data to product in the hopes of the triggering an effort condition or fault.
- Create a contingency plan
- Deploy data-centric not system-centric security
- Crowdsource security!
- Use positive social engineering
- Show value to mission by allowing risks
Cyber Security Plan:
- Anticipate
- Plan
- Implement and Adapt
- Improvise
And spoke about the kill chain analysis:
Kill Chain Analysis – Reconnaissance – Weaponization – Delivery – Exploitation – Installation – C2 – Actions
They spoke a lot about users being a weak link – both in terms of making mistakes and being lured by nefarious sources to share information they shouldn’t. And mistakes are made at all levels, low level users who don’t know the risk and IT folks who get complacent.
And there was talk of security at a higher level. Everyone expressed a need for communication among security professionals. It’s important to share information on attacks or disruptions both in terms of helping recognize trends and in terms of sharing warning and advice with others. There was a lot of discussion about how much info to share. No one wants to give away any trade secrets or admit to too much damage. There was also talk of the role of government. Everyone seemed to agree that there is a role for government – but is that role to coordinate communication efforts not necessarily to actually mandate security standards.
In a funny way it was like listening to parents of grade school kids. When someone else’s kid is sick or maybe a better analogy, has lice – I want the school to make them stay at home until it’s fixed and I want to know exactly how close that kid got to mine. When my kid gets lice, I’m hoping for discretion. And the truth is while some discretion is kind, unless you want kids infecting (and re-infecting) each other parents need to know the dangers and the signs. Same as with cyber security.
It was heartening to hear of some of the efforts that are happening, such as:
- Center for Internet Security: a not-for-profit organization focused on enhancing the cyber security readiness and response of public and private sector entities, with a commitment to excellence through collaboration. Through its three divisions–Security Benchmarks, Multi-State ISAC and Trusted Purchasing Alliance–CIS serves as a central resource in the development and delivery of high-quality, timely products and services to assist our partners in government, academia, the private sector and the general public in improving their cyber security posture.
- US-CERT: mission is to improve the nation’s cybersecurity posture, coordinate cyber information sharing, and proactively manage cyber risks to the nation while protecting the constitutional rights of Americans. US-CERT’s vision is to be a trusted global leader in cybersecurity – collaborative, agile, and responsive in a complex environment.
Both offer a range of services to public and private entities – such a personalized security scans and bulk email lists for sharing more general incidents and risks.
Finally it sounds like cyber security is big business. Folks were interested in developing a cluster in the Twin Cities. It would require trained people, access to research, access to businesses. To get the ball rolling, the FBI announced that they had just received word to hire new staff (Computer Science person) quickly. Contact Minneapolis FBI for more info.
And here are my more complete notes – offered asis…
Gopal Khanna
Cyber security involves all of us – it can’t be left to government. We all have a stake in managing the threat.
Massoud Amin (Technological Leadership Institute)– Building New American Prosperity through Smarter and More Secure Critical Infrastructure
18 Critical Infrastructures
- Ag & Food
- Defense Industrial Base
- Energy
- Public Health & Healthcare
- National Monuments & Icons
- Banking & financing
- Drinking water & Water Treatment
- Transportation
- Government Facilities
- Chemical
- Commercial Facilities
- Dams
- Emergency Services
- Commercial Nuclear Reactors
- Materials & Waste
- Information Technology
- Communication
- Postal & Shipping
Can enhance security and reliability?
Cyber Security Plan: Anticipate, Plan, Implement and Adapt & Improvise
MIKKO VARIPIOLA – Cyber Threat Identification – Framing the Issues
What makes us vulnerable?
- Immature/malfunctioning processes
- Poorly implemented software (know and unknown)
Programmers are not known for writing secure code.
What are we defending against?
- terrorists – persistent, determined, organized
- Warring Nations – motivated, well sponsored, relentless, targeted
- Anonymous – unorganized, random, irrational
Anatomy of a Hack
- Choose your target
- Study, analyze identify
- Plan
- Implement (and re-use your library of pre-weaponized exploits) & test
- Execute
Why are they after us?
- Cyber Crime is big business
- National interests, hackivists (idealists, anarchists…)
- Cost of entry is non-existent
- And they may not be after you specifically
“We have strict gun laws – but no laws on who can use or buy a computer – barrier to entry for cyber-crime is low” – Mikko Varpiola
Best Practices that Aren’t Perfect: Antivirus, isolated networks, firewalls
The threats are always changing – so many layers of defense ward against threats of the past. At best they are useless.
People should recognize reasonable care with cyber security. But where is the line between best effort and negligence or liability?
We will be better off if we are self-regulated or it will get political. But that means we need to be prudent now.
How do I protect myself?
- Demand better software. When you write RFPs or upgrade systems – ask for the best in terms of security.
- Deploy pro-active defenses and total vulnerability management
- Test what you have for unknown vulnerabilities.
- Fuzz – process of sending intentionally invalid data to product in the hopes of the triggering an effort condition or fault.
- Create a contingency plan
FAYYAZ RAJPARI – Future Opportunities in Cyber Security
Security Issues at Play
- Strategic Importance of Information
- Evolving Infrastructure
- Increasing Complexity
- Challenging Threat Landscape
APTs (Advanced Persistent Threats) have emerged and remain top of mind
- Adversaries are evolving
- Attack surface growing
- Private is now public
What is APT?
- Active, targeted, long-term campaign
- Tries to remain in place
- Includes multiple kill changes to ensure success
- Mutates and adapts to evade detection
- Very well organized
- Embedded spy
What is a targeted attack?
- An individual attack (drive-by-download, SQL injection)
- Often “smash and grab” by cybercriminals for financial gain
- May be well organized and resources
- Like bank robber
ANDREW BORENE – Emerging Business Opportunities in Cybersecurity & Robotics
Minnesota has as many high school robotics teams as hockey teams – Andrew Borene
TINA MEIER – Protecting our Children
A wonderful presentation on the need to stop cyber bullying in the schools from the founder of Megan Meier Foundation, named for her child who committed suicide after some extreme cyber bullying. Her presentation was definitely different from the rest of the session – but a good reminder that the Internet isn’t just for government and commerce – people live real lives on the Internet too.
RESEARCH TO REALITY
Should we establish a cyber-security hub in the Twin Cities? What are the barriers?
- Shortage of cyber-security experts
- Dep of Defense pays for cyber-security degrees
- National Security Agency – sponsoring programs all over US
- NSA – has intern programs & fellowships for students
- Make it attractive for programs to come into Minnesota
- Money makes things happen
- Not as easy
- CFIOs should get together to talk about biggest problems
- Hire new professions who have cyber-security PhDs
- Require every software/engineer graduate to take cyber-security classes and hacking classes
In the startup world – most cyber-security companies are in Silicon Valley, Boston, and Washington DC corridor.
Core companies spin off talent.
Is there a need for cyber-security concentration in MN?
- NSA is focused on fundamental science. And they look at interdisciplinary programs
Patrick Reidy, CISO, Federal Bureau of Investigation
Evolution Information Assurance
Bots & Viruses – people who want to make us a zombie-bot
- 40% of incidents
- 10% of time
- Addresses with automated recovery is pretty easy
- 99% of email traffic coming at FBI is spam and trash
Accidental Data Loss
- 24% of incidents
- 35% of time
- Addressed with training, campaigns and social engineering
Cyber Intrusion
- 12% of incidents
- 10% of time
- Criminal groups
- Less of a concern to FBI than private sector
Hackivists (Anonymous)
- 15% of incidents
- 5% of time
- Mass organization of previous disparate groups
- Increased capabilities through automation of DDOS attacks
APT
- 5% of incidents
- 10% of time (I think – hard for me to read)
- Intelligence operation against your organization
- The have personal knowledge of org or person
- Their techniques aren’t necessarily advanced
The Insider
- 18% of incidents
- 22% of time
- Not the most common threat, but most damaging
- The most challenging to combat
Rapid Technology Adoption
- Cloud – that means outsourcing your data
- Intellectual Property loses something in the cloud
Solutions
- Evolved beyond cyber
- Deploy data-centric not system-centric security
- Crowdsource security!!
- Use positive social engineering
- Show value to mission by allowing risks
How do they deal with risks:
Threats use same tactics. Lots of variability early on, but as attack advances, variability drops. Enables kill-chain analysis.
Kill Chain Analysis – Reconnaissance – Weaponization – Delivery – Exploitation – Installation – C2 – Actions
Know your people.
Know your data.
Show value.
Next Evolution of Threats
- Move toward mobile
- APT organization and advancement targeting business and government
- Criminal elements learning from APT: increased intelligence operations
Summary
- Spam is spam
- APT is an intelligence operation against you
- The insider is the most damaging potential threat
- Focus on threats and their capabilities
- Crowdsource security.
What’s the US advantage?
The US has some of the best thought leaders. We have a competitive advantage. There are other nations that are active. Think quality vs quantity.
THOMAS DUFFY – Center for Internet Security
Multi-State ISAC
- Every state is required to have a homeland security advisor.
- Have focused on state government in last few years
- Now we’re looking at local governments
- Started with state capitals and larger counties
- 25% of US population is part of the org
- Develop trust and share info
- Provide support, keep repositories of issues and fixes
- No cost to members
- Want to share info with other sectors
- Strict rules for sharing info shared by members
- Share, share without attribution, share with attribution
- Color-coded map of states tracks security issues in real time
- Will help monitor your system and will send very specific and detailed reports
- Will help provide responses to attacks.
National Security = Cyber security + Economic security + Homeland security
Who is behind threats?
- Cyber Criminals
- Hackivists
- Corporate Espionage
- Nation States
How do they get into our networks?
- Software Vulnerability
- Insecure Applications
- Phishing
- Getting sophisticated and personalized
- 1 in 8 sites related to Emma Watson has malware
- Gullible Users
Security of mobile medical devices
National Cybersecurity and Communications Integration Center
- Survey what’s happening across the country
- Big players in telecommunications are there
- It’s about sharing information
- Difficult for private sector
What are criminals looking for from government?
- Personal records (birth cert, SSN, school, medical…)
- System File Access Attempts increased by 91% (US, Poland France)
- Brute Force Logins increased 36% (US, Korea)
Top Concerns for State and Local Governments
- Law Enforcement (start with Law Enforcement Associations – hoping someone will use the same username/password for work system)
- Remind staff not to use work password anywhere else
- Bank Account Compromise
- Zeus – targets credentials used for financial institutions
- Think about who is authorized to make wire transfers
- No triggers for overseas deposits
- Europe requires two forms of verification
- Ransomeware
- Your computer is frozen
- A message appears that all your files are encrypted and it will cost you $200 for the encryption key
Summary
- Don’t become complacent
- Have policies in place and methods to monitor compliance
- Be a champion for cyber security in your organization – and encourage security at home!
- Cyber Security is everyone’s responsibility
NICK SELBY – Building
Intelligence is sharing info and talking to each other.
Legislative Intelligence – pay attention
Small Business v Bank à Zeus ACH à Not commercially reasonable à US Bank
- Have a direction
- You need to know what you’re looking for!
- Look for patterns, need to throw away bad stuff.
- Iterative process
- Plan – Set the Strategy
- What do you want your intelligence to do? Start with an easy win.
- Somebody has to run the effort (get someone with experience)
- Leverage
- Gather – Define and augment sources
- Know the people who have info that they aren’t sharing
- Think of how it can feed your strategy
- www.Policeledintelligence.com
i. OSINT (Open Source Intelligence)
ii. Google Hacking for penetration testers
- Analyze – Understand the limitations (what don’t I see?)
- Look for info you can leverage
- Make sure you don’t have info before you pay for it
- Put yourself in the middle
- Encourage and Train
- Empower Analysis
- Staff Right
- Disseminate – People have to read it
- Give it to someone with respect
- Aim small, miss small
- Presented soberly
Common Barriers
- Executive buy in
- Lack of metrics
- Chambers of Excellence
- Lack of Planning
- Lack of analysis
- Dissemination
Regular way
- Shut it down
- Peasant revolt
- Acceptance
Social media is good for right of boom information
NEW SESSION: TRUST IN THE CLOUD – http://www.nist.gov/nstic/
What do you see as biggest challenge to creating ID ecosystem?
James S –
- Liability
- You accept an ID from a third party – who is liable
- Bad addresses cost UPS $2 million; who do I blame for bad chipped in address?
- Business needs
- Find clear value proposition
James R –
- Getting stakeholders to agree
- We have to understand each other
Ian –
- Technology innovators think they have the protocol we need
- Policy innovators aren’t so sure
Thoughts on what need to be done to garner trust
James R –
- Outsourcing agreement– it will describe terms of liability
- Now there’s be a third party in the middle of the transaction, that means everyone has outsourced a portion of the transaction
- In business we trust contracts
Ian –
- Trust framework is nominal agreement for rules of engagement
- They are scaffolding and as such the general public doesn’t need to know about it
- Will need cultural lessons – how do we normalize the behavior
- Make yourself ready to credential others
- Right now Facebook is a sort of a third party
James S –
- Get representatives from a variety of sectors
- The tools here come from private sector
- We’ve progresses from ATMs that only suit certain cards – not ATM use is pretty ubiquitous
- Online stores are losing business when they require shoppers to create an account
This is a people’s plan – the government and private sector are involved but the government is not driving it!
Centralizing data – been happening in private sector for years.
FORTUNE 500 PRESPECTIVE
- We’re OK with physical threats – less good with cyber security
- People want to know the solutions, not so much the problems
- We don’t compete on security
- There are ways to share info without giving away the game
Best Practices
- Helpful to get info in terms of “what are other people doing”
- Be nice to have a more efficient way to do that
- Getting info on what’s happening with our industry
- Eg. What are others dong with patient data?
- Unstructured sharing/communication is helpful
- Trends and real time (Strategic/operational) are the two facets
- Need custom solutions
How do you decide what will work for you?
- Verizon annual data breech reports
- Threats are different for each sector
- Give me a way to be knowledgeable with what the options are (need toolkit with treatment options)
- Also valuable to know what didn’t work
What keeps you from being open
- Don’t want to give away intellectual property
- Don’t want to explain ourselves
- Regulation (HIPPA)
What’s the time issue
- We want responses in seconds in private sector so we need automation, which requires availability
- How secure vs how available?
- Data can travel quickly knowledge can’t
- We can’t move fast enough but we’re getting faster
- More people care about security now – it’s part of everyone’s job
- Security is everyone’s responsibility – pointing out spam and computer anomalies
- Companies are as fast as they have to be
- Sharing include 3 things: Common language, info has to be available to everyone, needs an incentive
NOTE: Homeland security has set up a number of tools to help coordinate sharing
- Business ISAC – (SFISAC) pretty active – people are sharing very specific and detailed info
- RENISAC – for universities
- The ISAC model is effective
- Not many heterogeneous groups – but good in sectors
Data can travel quickly knowledge can’t – perhaps that’s where security automation/data trends recognition tools come in?
- Important to research failures/incidents
- Failure is in the eye of the beholder – the incident may cost $100,000; the prevention may cost $1 million
What are the protocols of what to share?
- Regulation
- How much I trust the person is receiving it?
- There may be a contract to decide
- It’s difficult
- When we share strategic info – we don’t necessarily need to use names. We just need enough details to be applicable.
- Anonymity is easier with larger numbers
How do you measure how severe something is?
- Determine how pervasive it is vs total population
- Does lack of sharing come back to bite you?
- Technical attacks are easier to report because they are more generic
- The personalized attacks are more difficult to report because it reveals more about the org
Tips
- You have to share
- Give a full picture – including context
- You should be inquisitive, quick learner, ask why, why, why?
Challenges
- Integrating info in a way that makes sense – we have more data than we can deal with
- Standardization of data is helpful
- Need more people to insist on readability
- Industry consolidation will help
- Don’t be a dumbass
MARK WEATHERFORD
US Cert – can work with private companies http://www.us-cert.gov/
- 106,000 incident reports in 2011
- Average 14 alerts per day
- Malware analysis
Cyber Physical Nexus is getting more attention
Media are watching cyber-security
There are key parts of the government that are dependent on private sector for electricity, food…
Industrial Control Assistance
Cyber Security Valuation
Cyber Education program called NICE (w/NIST)
