 
              (IN)SECURITY , RISK & THE LIFECYCLE OF VULNERABILITIES Dr. Stefan Frei Security Architect at Swisscom frei@techzoom.net Twitter @stefan_frei
Cyber & Networking Security § Networking security has become critical issue for all types of industries § But in many aspects, cyber security differs fundamentally from past challenges NetSec 2015 Slide 2
What makes the cyber world special? § Communication between people, machines and devices § Increase of computing performance § Price erosion § Software eats the world NetSec 2015 Slide 3
Technology & Innovation In just two decades, new technologies and the Internet transformed society and businesses alike We had little time to learn or adopt – as individuals, society or industry We have to adopt to permanent change and high dynamics 1 Million Years 50 Years NetSec 2015 Slide 4
The Environment Internet usage has grown to more than three billion users The number of targets, revenue per target and type of exploitation has also evolved rapidly: § Networking evolved from dedicated point to point connections to ubiquitous communication between people, platforms, and applications § Vulnerabilities in applications and devices are now globally exposed and accessible NetSec 2015 Slide 5
Why is network security an issue? Infinite Interactions, Protocols, Service, Apps § Economy and our life increasingly depend on the Internet § Distributed information systems have become critical infrastructures Open Systems § technology is standardized and is no longer a secret Insecurity driven by organized adversaries § Entirely new «business models» NetSec 2015 Slide 6
Security has become critical § Security § Security is one of the hidden building blocks of the Internet § The limits of security imply the limits of the Internet § Growing online business attracts attackers § Attackers increase the cost of doing business online § But the business opportunities of being on the Internet far outweigh the risks Market acceptance Serious Use of Internet (since 2000) Time Early Hype Trough of Adoption (late 90s) Disillusionment (mid 90s) (2000-2003) NetSec 2015 Slide 7
Internet Security Evolution Figure courtesy Engin Kirda, Northwestern University NetSec 2015 Slide 8
The Threat Environment Fast growing segment Personal Theft Gain Motivation Author Tools created by of Personal experts are used Fame Tools by less-skilled Vandalism criminals, for personal gain Curiosity Script- Hobbyist Expert Kiddy Hacker Attackers’ Expertise NetSec 2015 Slide 9
complexity • complexity and interaction between systems is growing continously • complexity is the worst enemy of security
Network of People, Devices, and Services The increasing number of new ways of interaction also create novel attack paths which are not predictable by definition NetSec 2015 Slide 11
Complex Adaptive System (CAS) § Connectivity A decision on one part will affect all other related parts § Co-Evolution Elements can change based on their interaction between one another and the environment § Sensitive Dependence Sensitivity to initial conditions (non-linearity, cascades) § Emergent Order Potential for emergent and unpredictable behaviour Source: http://web.mit.edu/esd.83/www/notebook/Complex%20Adaptive%20Systems.pdf NetSec 2015 Slide 12
Strategies to Handle Unpredictability Men Nature, Evolution § Predict and model risks § No attempt to predict risks Prevent Shocks Absorb Shocks § Relies on accuracy of § Relies on redundancy and models and probabilities robustnes § Optimization: § Absorption: short term gain, efficiency long term survival, diversity > fragile > anti-fragile Source: Antifragile: Things That Gain from Disorder, by Nassim Nicholas Taleb NetSec 2015 Slide 13
Innovation & Price Erosion § Continued miniaturisation and price erosion § Today’s transistors are 90,000x more efficient and 60,000x cheaper than in 1971 § A car today would cost USD 0.25 and consume 0.2 ml/100 km of fuel Source: The Economist, The End of Moore's Law NetSec 2015 Slide 14
today attackers can afford functionality and tools that were beyond their reach a decade ago
Innovation & Price Erosion Nonexistent or previously unavailable technologies become common goods Software Defined Radio 15 Years USD 500 USD 500,000 Revalidate security assumptions based on the (A) limited availability, (B) unaffordability, or (B) limited performance of a technology NetSec 2015 Slide 16
Examples of new Attack Vectors § Software Defined Radios (SDR) § All radio communication and protocols without hard crypto protection are highly exposed § Drones § Drones easily bypass perimeters to sniff or insert eavesdropping devices § Robots § Robots can access areas not accessible by humans. Remotely controlled to manipulate, monitor, or take other actions NetSec 2015 Slide 17
Playground for Software Defined Radios (SDR) § Unsecured communication and networks are exposed NetSec 2015 Slide 18
WHO ARE THE ATTACKERS?
Attacker Motivation § Ego § Show the world what one can do, impress peers § To live some fantasy of omnipotence § Revenge, destruction, creation of fear § Cyber warfare § Terrorism § Secret service activities (Stuxnet 2010, Snowden/NSA 2013) § Revenge (e.g. a disgruntled employee)  § Criminal intent § Blackmail, racketeering (Schutzgelderpressung) § Credit card fraud § Infiltrating e-banking § Spamming, phishing NetSec 2015 Slide 20
What can attackers do? § Attack flow of information § Abuse Systems § Send fake messages § Infiltrate system with attack code § Replay messages § Modify web pages § Modify messages in transit § change content § Denial of service (DOS) § place attack code § Overload system resources § Hijack sessions § Internet infrastructure § E-banking § DNS, BGP, ARP § Identity theft § Unauthorized access to § Social engineering services § Break crypto § Infiltrate security protocols § etc. or processes (e.g. MITM) NetSec 2015 Slide 21
Where are the attack targets? § Local Attacks: Client-side attacks dominate § Browser attacks targeting plug-ins § IFrame based attacks are now prevalent § Attacks of all shapes and sizes § Anti-virus worms § Social networking attacks – Twitter & Facebook § Phishing - banking industry is target #1 § Web mines - www.goggle.com rather than www.google.com § Documents - PDFs are not safe! § Data stored on end-points is often most valuable and the least protected! NetSec 2015 Slide 22
Actors & Attackers Attacker Objectives Resources Proceeding • Information • Enormous • Build & buy know-how • Fighting Crime/ financial resources • Persistent & well Nation States, Terrorism • Focus on result, hidden attacks Agencies • Espionage not cost • Subversion of supply • Sabotage chain Targeted • Damage • Considerable • Buy know-how on • Attention financial resources black market • Manipulation of politics • Potentially large • Physical attacks Terrorists • Fear Uncertantity and network of Doubt (FUD) supporters • Financial • Business • Exsisting gangs • Make money in • Per case groups of (Organized) long term specialists Crime • Profit/loss driven • Bribery • Mass attention • Minimal financial • Highly motivated Opportunistic • Damage resources amateurs & Hacktivists, • Denounce • Large reach specialists Groups vulnerabilities in • Develops systems/organizations unpredictable momentum • Fame • Minimal financial • Available tools Vandals, • Reputation resources and Script Kiddies know-how NetSec 2015 Slide 23
Actor: Nation States § Nation States § Virtually unlimited resources § The have a mandate by law to do certain things § Access (technical or legal) to critical components of the Internet infrastructure (like backbone) § Attacks on the integrity of the supply chain § Espionage and sabotage NetSec 2015 Slide 24
Actor: Terrorists § Terrorists § Maximize attention/publicity § Spread Uncertainty Doubt and Fear (FUD) § Misuse of services with large number of followers/large audience (Twitter, Facebook, TV, ..) § Targeting large events (Sports, conferences, ..) NetSec 2015 Slide 25
Cyber | Crime – All New? § Crime & Organized Crime § The first law code ever edited (code of Hammurabi) documents that organized crime was very real 4000 years ago Long history of the dark that developed itself in the middle of people, and society Code of Hammurabi § Cyber § Term coined by Norbert Wiener in 1948, used in reference to the control of complex systems § Today: Mesh of computers, networks, and lots of people Cyber Threats Short history of new technologies NetSec 2015 Slide 26
Recommend
More recommend