1
National Cybersecurity preparation to deal with Cyber Attacks
- Dr. Chaichana Mitrpant
Assistant Executive Director, Electronic Transactions Development Agency (ETDA)
National Cybersecurity preparation to deal with Cyber Attacks Dr. - - PowerPoint PPT Presentation
National Cybersecurity preparation to deal with Cyber Attacks Dr. Chaichana Mitrpant Assistant Executive Director, Electronic Transactions Development Agency (ETDA) 1 Analog to Digital Era Over all Internet usage in Thailand
1
Assistant Executive Director, Electronic Transactions Development Agency (ETDA)
2
(facebook) e-Transaction
1) e-Payment 4) e-Certificate 2) e-Trading & service 5) e-Medical record 3) e-Filing and e-Reporting
(e-Commerce = 56%, e-Auction = 44%)
3
1980: Physical Attack 1990: Network Attack Physical attack is normally in the past 20-30 years. Nowadays, it becomes Network attack.
4
2000s: Wireless 2000s: Application
In the past 10 years, the threat is more complicate. The most common is email phishing, unauthorized wireless access and attack via vulnerability of Web Application.
5
2010s: Client-Side 2010s: Social Networking 2010s: Client-Side (Malware)
Malware is usually transmitted via PDF, Mobile Application and Social Media Software
6
North Korea behind hacking attack in March, claims Seoul South says computers in North were used for
TV stations and disrupted banks
7
In 2012, There were 772,938 IP addresses of all IP numbers 8,559,616 (9%) of computers in Thailand that compromised and malicious used as the tools for DDoS attack. In 2012, There were 534 websites reported as fraudulent financial. From January to March 2013, 707 websites were attacked and change data (Defacement). An approximately 50%
8
9
10
11
National Cyber Security
& Security Council
& Army.
& Security Council
& Army.
12
Thailand Cybersecurity Policy
(Draft) Thailand Computer Crime Act (Second Edition)
Prevention & suppression.
ISO/IEC 27001:2005
Driving Law Compliance. Develop standard according to Electronic Transactions Act
National BCP
Develop plan to support the availability of emergency or
from NESDB)
Security Professional Standard
Enhance professional skill / Increase number
Compensation
Urgent tasks (Prepare and develop framework)
Other Messures
Infrastructure to encourage.
CERTs
Monitoring
Archive (e-Authen tication)
Internal Security Operations Command National Security Council
Policy/Promotion/ Regulator
คกก. นโยบายรักษา ความปลอดภัยแห่งชาติ
คกก.คดีพิเศษ ดูแลการดําเนินคดี อาญาที่เป็นคดีพิเศษ
คกก.นโยบาย ตํารวจแห่งชาติ
Royal Thai Arm Force & ศูนย์รักษา ความปลอดภัย คอมพิวเตอร์
Law Enforcement
Office of Electronic Transactions Commission
Best Practices & Guidelines
NBTC
NIA Critical Infrastructure Group
Policy & Defense
13
policy and National Cybersecurity Model Scheme
develop guideline for measure, plan and cybersecurity programs
and evaluate measures and plans according to the guideline
progress, situation and risk analysis
threats report to the Council of Ministers
subcommitte es or working groups to support the
with local and international cybersecurity
assignment
14
15
Collaborate with involved Agencies Develop plan and Workflow for interoperability when incidents occur Develop Security Framework Build Public Awareness Incidents Drill Practice Setup CERT as internal unit for other organization Capacity Building National Assessment FIRST event preparation