the evolving threat
play

The Evolving Threat Todays cyber security challenges and solutions - PowerPoint PPT Presentation

The Evolving Threat Todays cyber security challenges and solutions Are Water Lines At Risk? n Security lacking in networks controlling critical infrastructure n Hackers, terrorists could find way into controls of nuclear power


  1. The Evolving Threat Today’s cyber security challenges and solutions

  2. Are Water Lines At Risk? n Security lacking in networks controlling critical infrastructure n Hackers, terrorists could find way into controls of nuclear power stations, electrical grids, water lines. n By Bob Keefe WEST COAST BUREAU Monday, October 02, 2006

  3. The Past

  4. The Present Source: http://cm.bell-labs.com/who/ches/map/gallery/index.html

  5. The earlier threat landscape Exposures Human Agents n Hackers Information theft, loss & n n Disgruntled employees corruption n White collar criminals n Monetary theft & embezzlement n Organized crime n Critical infrastructure failure n Terrorists n Hacker adventures, e-graffiti/ n defacement Business disruption n Representative Incidents Methods of Attack n Code Red, Nimda, Sircam Brute force n n Denial of Service CD Universe extortion, e-Toys n n Viruses & worms “Hactivist” campaign, n Back door taps & misappropriation, n Love Bug, Melissa Viruses n Information Warfare (IW) n SOBIG, SLAMMER techniques n

  6. The earlier threat: growth in vulnerabilities (CERT/cc) 4,500 4,129 4,000 3,500 3,000 2,437 2,500 2,000 1,090 1,500 1,000 417 345 500 311 262 171 0 1995 2002

  7. The earlier threat: cyber incidents 120000 110,000 100000 80000 55,100 60000 40000 21,756 20000 9,859 2,340 2,412 2,573 132 2,134 3,734 252 6 1,334 406 773 0 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002

  8. Anyone have a cell phone? n “Companies have built into their business models the efficiencies of digital technologies such as real time tracking of supply lines, inventory management and on-line commerce. The continued expansion of the digital lifestyle is already built into almost every company’s assumptions for growth.” ---The Manufacturing Institute July 2006

  9. The changing threat n The fast-moving virus or worm pandemic is not the threat. 2002-2004 almost 100 medium-to-high risk attacks. 2005, there were only 6 This year, 0.

  10. The changing threat n Today, attackers are motivated to perpetrate fraud, gather intelligence, or gain access to vulnerable systems. n Vulnerabilities are now on client-side devices and applications (word processing, spreadsheet programs, wireless devices) that require interaction, instead of on servers

  11. The changing threat n Cybercrime growth n 6,110 Denial of Service attacks per day n 4000 in January ’06 to 7,500 in June ‘06 n Bot nets are the engine driving growth n Increase in modular malicious code (initially limited functionality but updates itself with new, more damaging capabilities) n Insider threats

  12. Economic Effects of Attacks n 25% of our wealth---$3 trillion---is transmitted over the Internet daily n FBI: Cyber crime cost business $26 billion (probably a LOW estimate) n Financial Institutions are generally considered the safest---their losses were up 450% in the last year n There are more electronic financial transactions than paper checks now, 1% of cyber crooks are caught.

  13. I’m too Small to Attack, Not. n One of every three small businesses in America were affected by MyDoom virus---- 2x the proportion of large companies effected by that virus. n Small Businesses get attacked more often, have less defenses, have smaller margins to protect against loss n Small businesses have needs and require a special program

  14. 2006 Data Breach Laws Introduced in at least 35 states Enacted in: IN, ME, Enacted in: WI AZ, CO, KS, UT, NE, ID Sources: National Conference of State Legislatures U.S. Public Interest Research Group

  15. Pending Federal Legislation n House Judiciary Committee: Ø Passed legislation on Thursday June 1 st 2006 n House Energy and Commerce Committee Ø Passed legislation on Wednesday May 31 st 2006 n Senate Judiciary Committee Ø S.1789 Personal Data and Privacy Act - Pending n Sponsor: Sen. Arlen Specter (PA) n Cosponsors: Sen. Patrick Leahy (VT), Sen. Russell D. Fiengold (WI), Sen. Dianne Fienstein (CA)

  16. What’s the result of all the legislative activity? 1. Confusion for business 2. Inaction in the Congress 3. Growing problems and costs “August 2006 was the worst month for data security breeches on record” SANS Institute Sept 2006

  17. Can it be stopped ? YES ! n PricewaterhouseCoopers conducted 2 International surveys (2004 & 2006) covering 15,000 corporations of all types n Apx 25% of the companies surveyed were found to have followed recognized “best practices” for cyber security.

  18. Benefits of Best Practices n Reduces the number of successful attacks n Reduces the amount of down-time suffered from attacks n Reduces the amount of money lost from attacks n Reduces the motivation to comply with extortion threats

  19. n Cited in US National Draft Strategy to Protect Cyber Space (September 2002) n Endorsed by TechNet for CEO Security Initiative (April 2003) n Endorsed US India Business Council (April 2003)

  20. ISALLIANCE BEST PRACTICES n Practice #1: General Management n Practice #2: Policy n Practice #3: Risk Management n Practice #4: Security Architecture & Design n Practice #5: User Issues n Practice #6: System & Network Management n Practice #7: Authentication & Authorization n Practice #8: Monitor & Audit n Practice #9: Physical Security n Practice #10: Continuity Planning & Disaster Recovery

  21. Why Doesn’t Everyone Comply with the Best Practices? n “Many organizations have found it difficult to provide a business case to justify security investments and are reluctant to invest beyond the minimum. One of the main reasons for this reluctance is that companies have been largely focused on direct expenses related to security and not the collateral benefits that can be realized—Manufacturer’s Institute ‘06

  22. But, management is wrong. n Stanford Global Supply Chain Management Forum/IBM Study: “Clearly demonstrated that investments in supply chain security can provide business value such as: * Improved Product Safety (38%) • Improved Inventory management (14%) • Increase in timeliness of shipping info (30%)

  23. There’s More !!! n Increase in supply chain information access (50%) n Improved product handling (43%) n Reduction in cargo delays (48% reduction in inspections) n Reduction in transit time (29%) n Reduction in problem identification time (30%) n Higher customer satisfaction (26%)

  24. Security, like Digital Technology must be Integrated in Bus Plan n “Security is still viewed as a cost, not as something that could add strategic value and translate into revenue and savings. But if one digs into the results there is evidence that aligning security with enterprise business strategy reduces the number of successful attacks and financial loses as well as creates value as part of the business plan.” PricewaterhoseCoopers Sept 2006

  25. So, how do we do that? n We have a changing technology environment n We have a changing business model n We have a constantly changing legal and regulatory environment n Business must take the lead

  26. Cyber Security is not an IT problem n Issues must be addressed simultaneously from the n Legal Perspective n The Business Perspective n The Technology perspective n The Policy Perspective

  27. ISAlliance Integrated Business Security Program n Outsourcing n Risk Management n Security Breech Notification n Privacy n Insider Threats n Auditing n Contractual Relationships (suppliers, partners, sub-contractors, customers)

  28. ISAlliance Small Business Program n Special Set of Best Practices Endorsed by: n DHS n Chamber of Commerce n NAM n NFIB n ABA n “Wholesale Memberships” through trade associations

  29. Sponsors

  30. Larry Clinton Operations Officer Internet Security Alliance lclinton@eia.org 703-907-7028 202-236-0001

Recommend


More recommend