Practical Magic: Behavior- based Security Design for IoT
Kelly Shortridge (@swagitda_) Troopers 2018
Practical Magic: Behavior- based Security Design for IoT Kelly - - PowerPoint PPT Presentation
Practical Magic: Behavior- based Security Design for IoT Kelly Shortridge (@swagitda_) Troopers 2018 Hi, Im Kelly I usually solve problems by letting them devour me. Franz K afka 3 100 90 80 70 60 50 40 30 20 10 0
Kelly Shortridge (@swagitda_) Troopers 2018
3
4
10 20 30 40 50 60 70 80 90 100 January 1, 2007 January 1, 2009 January 1, 2011 January 1, 2013 January 1, 2015 January 1, 2017
IoT IoT Security
Source: Google Trends
5
6
Dyn DDoS / Mirai Botnet Reaper Botnet RSAC 2017
10 20 30 40 50 60 70 80 90 100 January 1, 2007 January 1, 2009 January 1, 2011 January 1, 2013 January 1, 2015 January 1, 2017
Source: Google Trends
7
8
9
10
11
12
14
15
16
17
18
19
20
21
22
23
24
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
Design Build Test
the change of default creds
data w/ SSL or TLS
call bash scripts or use custom API protocols
If internet-connected, spoof headers to appear “normal” Cross-checking by teams of critical measures to be taken
concerning security steps with the team
understands the security requirements
added since design that require review? (ie interfacing w/ the internet, collecting user data)
non-routine security controls required?
implementation of controls take?
impacts of the controls?
controls (default credential alerts, lockouts, 2FA)
device, and labelling of user data
vulnerabilities to be addressed
concerns around management going forward and any future security concerns?
immediate post-testing security management are drawn up together
100
102
103
104
105
106
107
108
109
111
▪ “Approaches based on behavioral economics could help nudge patients and providers toward lower health spending growth,” A. Darzi, F. Greaves, D. King, I. Vlaev ▪ “Behavior-based Safety Guide,” Ireland Health & Safety Authority ▪ “Farmer Behaviour, Agricultural Management and Climate Change,” OECD ▪ “Guidance for the Content of Premarket Submissions for Software Contained in Medical Devices,” FDA ▪ “Influencing behaviour: The mindspace way,” P. Dolan, et al. ▪ “Postmarket Management of Cybersecurity in Medical Devices,” FDA ▪ “A Surgical Safety Checklist to Reduce Morbidity and Mortality in a Global Population,” Alex B. Haynes, et al. ▪ “The Theory of Value-Based Payment Incentives and Their Application to Health Care,” Conrad DA
111
112