Storytelli Storytelling ng in in Infosec Infosec (Draft aft of) - - PowerPoint PPT Presentation

storytelli storytelling ng in in infosec infosec
SMART_READER_LITE
LIVE PREVIEW

Storytelli Storytelling ng in in Infosec Infosec (Draft aft of) - - PowerPoint PPT Presentation

Dr. med. Christina Czeschik www.serapion.de Storytelli Storytelling ng in in Infosec Infosec (Draft aft of) a Pr Practical ctical Guide ide BalCCon 2k17 Sept 16, 2017, Novi Sad How to Make Users Behave Safely? Explain things to them?


slide-1
SLIDE 1

Storytelli Storytelling ng in in Infosec Infosec

  • Dr. med. Christina Czeschik

www.serapion.de BalCCon 2k17 Sept 16, 2017, Novi Sad (Draft aft of) a Pr Practical ctical Guide ide

slide-2
SLIDE 2

How to Make Users Behave Safely?

slide-3
SLIDE 3

Explain things to them?

Source: http://www.simonmgarrett.com/career/lecturing-and-training/

slide-4
SLIDE 4

Take away their permissions?

Source: https://www.ibm.com/developerworks/community/blogs/idsteam/entry/oat_311_login?lang=en

slide-5
SLIDE 5

Threaten them with heavy objects?

slide-6
SLIDE 6

A better way:

Tell a story.

slide-7
SLIDE 7

Why Storytelling Works

slide-8
SLIDE 8

Evolutionary Advantage?

slide-9
SLIDE 9
slide-10
SLIDE 10

Evolutionary Advantage!

Sources: http://untappedcities.com/2013/06/20/discover-cave-paintings-in-baja-california-mexico-near-loreto/, https://owlcation.com/stem/The-Saber-Tooth-Tiger

slide-11
SLIDE 11

Why we remember stories…

… better than stand-alone facts:

  • 1. They raise attention!

Source: http://www.i-am-bored.com/2015/08/call-him-a-crazy-cat-person-one-more-time-pic.html

slide-12
SLIDE 12

Why we remember stories…

… better than stand-alone facts:

  • 2. They organize knowledge.

Source: https://www.commonsensemedia.org/tv-reviews/scrubs

slide-13
SLIDE 13

Why we remember stories…

… better than stand-alone facts:

  • 3. They offer self-reference.

Source: http://www.dailymail.co.uk/news/article-2044620/School-bans-children-putting-hands-class--tells-pupils-Fonz- thumbs-instead.html

slide-14
SLIDE 14

Why we remember stories…

… better than stand-alone facts:

  • 3. They offer self-reference.

… commonly known as the answer to the question: "WTF will I ever need that for?"

Source: http://www.dailymail.co.uk/news/article-2044620/School-bans-children-putting-hands-class--tells-pupils-Fonz- thumbs-instead.html

slide-15
SLIDE 15

Why we remember stories…

… better than stand-alone facts:

  • 4. They invoke emotions.
slide-16
SLIDE 16

What Is a Story?

slide-17
SLIDE 17

What is a story?

Sources: http://edtech2.boisestate.edu/weltys/502/conceptmap.html

slide-18
SLIDE 18

What is a story?

Source: http://250bpm.com/blog:45

Protagonist

slide-19
SLIDE 19

What is a story?

Sources: http://www.yourheroicjourney.com/, https://britannica.com/biography/Joseph-Campbell-American-author

Joseph Campbell, The Power of Myth (1988)

slide-20
SLIDE 20

Working definition:

Humans

slide-21
SLIDE 21

Working definition:

Humans doing

slide-22
SLIDE 22

Working definition:

Humans doing stuff.

slide-23
SLIDE 23

Types of Stories

slide-24
SLIDE 24

Types of Stories

Narrative Case Study Scenario Problem-based Learning

slide-25
SLIDE 25

Types of Stories

Narrative Case Study Scenario Problem-based Learning Emotion Analysis

slide-26
SLIDE 26

Source: https://snowdenfilm.com

Narrative

Example:

slide-27
SLIDE 27

Case Study

Source: https://www.heise.de/newsticker/meldung/Trojaner-im-OP-wie-ein-Krankenhaus-mit-den-Folgen- lebt-3617880.html

Example:

slide-28
SLIDE 28

Scenario

Source: http://news.softpedia.com/news/petya-ransomware-uses-dos-level-lock-screen-prevents-os-boot- up-502166.shtml#sgal_2

Example:

slide-29
SLIDE 29

Problem-based Learning

Source: http://www.csoonline.com/article/3175503/leadership-management/congrats-you-re-the-new-ciso- now-what.html

Example:

slide-30
SLIDE 30

Metaphors and Analogies

slide-31
SLIDE 31

Narratives, Case Studies and Scenarios

… can be real, but don't have to be. They can also be analogies from other fields than infosec.

slide-32
SLIDE 32

Narratives, Case Studies and Scenarios

… can be real, but don't have to be. They can also be analogies from other fields than infosec. In fact, that may be better.

slide-33
SLIDE 33

Source: http://memory-alpha.wikia.com/wiki/Q_Continuum?file=Q_Continuum_ranch_house.jpg

slide-34
SLIDE 34

(By the way…)

Happy 30th Birthday, Q!

… on September 28, 2017

slide-35
SLIDE 35

So… Where Do We Get Our Stories From?

slide-36
SLIDE 36

Myths and Legends

(Of course.)

slide-37
SLIDE 37

Myths and Legends

Peace be within your walls and security within your towers!

Psalm 122:7

Source: http://www.ebrahma.com/2015/04/firewall-basic-concepts/

slide-38
SLIDE 38

Myths and Legends

For you say, I am rich, I have prospered, and I need nothing, not realizing that you are wretched, pitiable, poor, blind, and naked.

Revelation 3:17

Source: http://www.macworld.co.uk/review/mac-laptops/apple-macbook-air-mid-2017-review-3659879/

slide-39
SLIDE 39

The Analogies Project

www.theanalogiesproject.org

slide-40
SLIDE 40

The Analogies Project

slide-41
SLIDE 41

The Analogies Project

Rapunzel – lessons learned: Biometric access control can be fooled. Even if Especially when the system is human.

Source: https://theanalogiesproject.org/the-analogies/rapunzel/

slide-42
SLIDE 42

The Analogies Project

Rumpelstiltskin – lessons learned: Do not sing your passwords when dancing around a campfire.

(Not even on BalCCon. Seriously.)

Source: https://theanalogiesproject.org/the-analogies/rumpelstiltskin-a-lesson-in-password-security/

slide-43
SLIDE 43

The Analogies Project

Source: https://theanalogiesproject.org/the-analogies/infosec-like-sun-protection/

Infosec is like sun protection: Lotion won't prevent heatstroke Hat won't prevent sunburn  You need more than one protection. (Or you can just stay offline – lock yourself in your apartment all summer…)

slide-44
SLIDE 44

TV Tropes

www.tvtropes.org

slide-45
SLIDE 45

TV Tropes

A trope is a

  • storytelling device or convention,
  • a shortcut for describing situations

the storyteller can reasonably assume the audience will recognize.

slide-46
SLIDE 46

TV Tropes

Source: http://tvtropes.org/pmwiki/pmwiki.php/Main/MagicalComputer

!!!

slide-47
SLIDE 47

TV Tropes

Source: http://tvtropes.org/pmwiki/pmwiki.php/Main/HollywoodHacking

!!!

slide-48
SLIDE 48

TV Tropes

Source: http://tvtropes.org/pmwiki/pmwiki.php/Main/HollywoodHacking

!!!

slide-49
SLIDE 49

TV Tropes

Source: http://tvtropes.org/pmwiki/pmwiki.php/Main/ApologisesALot

!!!

slide-50
SLIDE 50

TV Tropes

Source: http://tvtropes.org/pmwiki/pmwiki.php/Main/YouDidntAsk

!!!

slide-51
SLIDE 51

TV Tropes

Source: http://tvtropes.org/pmwiki/pmwiki.php/Main/RaceAgainstTheClock

slide-52
SLIDE 52

Thank you for your attention!

Christina Czeschik www.serapion.de czeschik@serapion.de Twitter: @serapionblog