the not so ominous future of computer system defense who
play

The not so Ominous Future of Computer System Defense Who am I PhD - PowerPoint PPT Presentation

The not so Ominous Future of Computer System Defense Who am I PhD Candidate at UNC Charlotte Defense Competition Enthusiast 49sd Director of Education Where are current advancements leading us? Traditional System Defense SEIM


  1. The not so Ominous Future of Computer System Defense

  2. Who am I ● PhD Candidate at UNC Charlotte ● Defense Competition Enthusiast ● 49sd Director of Education

  3. Where are current advancements leading us?

  4. Traditional System Defense ● SEIM ● [NG] Firewall ● Antivirus ● Alerting ● Threat Hunting

  5. The Optimal Goal ● Respond at moment of detection ● Respond Optimally ● Increase cost of attacking network ● Secure all the things

  6. Current Advancements ● Robust MTD (also via SDN) ● Active Cyber Defense ● Automated Network Management

  7. How can we do better? ● Machine/Deep Learning ● The “Cloud” ● Blockchain ● Containers and Automation

  8. So what if we put it all together? *Excluding blockchain of course

  9. Disclaimer This may not fit your business model

  10. The Bleeding Edge ● Software Defined Networks ● SecOps/Automation ● Immutable Infrastructure… or not

  11. Autonomic Systems ● Nervous System ● Self-(x) ● IBM and DARPA 2001 ● IETF ANIMA

  12. Components of an Autonomic System

  13. Reactive Frameworks ● OODA (Observer, Orient, Decide, Act) ● MAPE (Monitor, Analyze, Plan, Execute) ● FOCALE (Foundation, Observe, Compare, Act, Learn, rEason)

  14. Current Challenges ● Securing SDN ● Creating intelligent feedback loops ● Cool projects don’t last forever (runbook.io) ● Self-awareness systems

  15. What does this mean?

  16. In Summary ● Effective autonomic design is efficient and secure ● Autonomic features are here ● Reducing complexity at the cost of complexity

  17. Thanks for your Attention Twitter: @trevonistrevon Website: trevon.dev

  18. References ● D.I.E - Linkedin SlideShare ● DARPA SARA - Paper ● Network Fault Management - Paper ● RFC 7575 - Work group

Recommend


More recommend