Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 •...

26
Improving Cyber Ecosystems Health by Metrics, Measurement and Mitigation Support Borderless Cyber Asia 2016, at Keio University,Tokyo Yurie Ito Executive Director, CyberGreen

Transcript of Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 •...

Page 1: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

ImprovingCyberEcosystemsHealthbyMetrics,MeasurementandMitigationSupport

BorderlessCyberAsia2016,atKeioUniversity,TokyoYurieIto

ExecutiveDirector,CyberGreen

Page 2: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

2Copyright©CyberGreen2016AllRightsReserved.

Page 3: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

3Copyright©CyberGreen2016AllRightsReserved.

CyberGreen:Whatwedo

CyberHealthMeasurementWemeasureRisk-to-others.

ProvideaclearingHouseforRiskMiFgaFonBCPs.

SourcingRiskcondiFonsData

Advocacy

CapacityBuildingNeedsanalysisandImpactmeasurement

Page 4: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

4Copyright©CyberGreen2016AllRightsReserved.

CyberGreen:Whoweare–collaborationforGlobalCommonGood

CyberGreenMetricsExperts

Group

SpecialAdvisers

CyberGreenBoard

Directors

TechnicalPartners

MiFgaFonsCSIRTs

GlobalDatasources

Sponsors

Dr.PaulTwomeyFormerICANNCEO)

Dr.RichardSoleyIndustrialInternetConsorFum

Dr.DanGeerSpecialAdviseronMetrics

Dr.JunMuraiDean,KeioUniversity

Dr.PaulVixieFarsightTechnology(SpecialAdviser)

Page 5: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

5Copyright©CyberGreen2016AllRightsReserved.

TheCybersecurityLandscape

ThreatResponse

NaFonalsecurity

Publicsafety

Intelligence

LawEnforcement

Military

EcosystemHealthImprovement

Networkoperators

CSIRTs

ProductVendors

Media

Users CorporaFons

Policymakers

Page 6: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

6Copyright©CyberGreen2016AllRightsReserved.

LackofmaintenanceisriskstoOTHERS

MisconfiguraFon

VulnerabiliFes

InfecFon

Riskfactorsofthehealthyinternet

Page 7: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

7Copyright©2016,CyberGreen Sept2016

Abuse-ablesystemicconditionsposingriskstoothers*includingtoyourself*

OpenrecursiveDNSservers

OpenNTPservers

OpenSSDPservers

OpenSNMPservers

Page 8: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

Copyright©CyberGreen2016AllRightsReserved.

CyberGreenv2.0Metrics:Premise

•  CGwilltaketheperspecFveofrisk-to-

others.

•  On-the-groundrealityisthatDDoSisthedamagingformofa_ackcurrentlymostextensivelyseeninquanFty.

8

Page 9: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

9Copyright©CyberGreen2016AllRightsReserved.

v.2Metricsmethod

Page 10: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

CyberGreenMetrics

10Copyright©CyberGreen2016AllRightsReserved.

Page 11: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

•  Risktoothers•  Don'tmeasurework/effort,measurerisk

reducFon.•  Transparency•  Reproducibility/Repeatability•  Accuracy

Principles

Page 12: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

12Copyright©CyberGreen2016AllRightsReserved.

ETLprocess

Page 13: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

13Copyright©CyberGreen2016AllRightsReserved.

Page 14: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

14Copyright©CyberGreen2016AllRightsReserved.

CyberGreenPlatformTechnical

Objectives

Page 15: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

15Copyright©CyberGreen2016AllRightsReserved.

Page 16: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

16Copyright©CyberGreen2016AllRightsReserved.

Page 17: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

17Copyright©CyberGreen2016AllRightsReserved.

Page 18: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

18Copyright©CyberGreen2016AllRightsReserved.

Page 19: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

19Copyright©CyberGreen2016AllRightsReserved.

Page 20: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

20Copyright©CyberGreen2016AllRightsReserved.

Page 21: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

21Copyright©CyberGreen2016AllRightsReserved.

MoreEfficientandGreaterImpactofMitigationforGlobalCommonGood

Ecosystemownersandstakeholdersmusttakecareofecosystemhealthandclean-upinfecFonssuchaseffortstoeliminateproxya_ackinfrastructure.EliminaFngtherisksposingtotherestoftheworldwouldbuild;o NaFonallevelàConfidenceo Businessàsocialresponsibility,brandingpowero UsersàIndicaFonofmaturityofcybersociety,educaFonalandawarenesslevel

Page 22: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

22Copyright©CyberGreen2016AllRightsReserved.

Futurework:Metricsv.3

•  ImproveAssetOwnerMetrics,CreateNewVendorMetrics

•  AnalyzewhohasgreaterabilityformiFgaFonimpact•  V.2isassetownerfocused•  V.3:howcanweadd“vendorrisktoothers”

CyberGreenislookingfortheSponsorforthisresearchanddevelopmentofMetricsv.3PleasecontactushowtoSupport.

[email protected]/[email protected]

Page 23: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

G7ICTMinisterscommitment

h_p://www.soumu.go.jp/main_content/000416960.pdf

Page 24: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

RegionalhubHighlight:ASEAN

MinisterYaacob’sopeningstatement-13CyberGreenisoneglobaliniFaFvethatwillaidusinsecuringourcommoncyberspace.TheCyberGreenprojectaimstogivecountriesawarenessofthestateofcyberhealthandpotenFalvulnerabiliFeswithinourborders.WiththissituaFonalawareness,countriescanthentakeprevenFveacFontodealwithpotenFalcyberrisksandvulnerabiliFes.Thebe_eracountry’scyberhealth,the“greener”itwillbe.OverFme,CyberGreenwilldeveloprobustcyberhealthmetrics.ThesewillallowpracFFonersandpolicy-makerslikeourselvestoassesshowourcountries,andASEANasawhole,areprogressingonthecybersecurityfront.Cyberincidentresponderscanalsobe_eridenFfyandremediatedifferentclassesofthreats,basedonacFonablethreatinformaFonprovidedbyCyberGreen.14SingaporeisexcitedtobeasponsorofthisglobaliniFaFve.WehavesignedontoCyberGreen,aswerecognisethatASEANMemberStatesincludingourselvescanbenefitfromCyberGreen.Asastart,becauseofoursponsorship,allASEANMemberStateswillbeabletoaccessCyberGreenthroughSingaporeforfree,andgetafirstcutreportonthestateoftheirowncountry’scyberhealthstatus.IwouldliketoinvitefellowASEANMemberStatestocomeonboard,andjoinSingaporeinCyberGreen.Throughthisplaporm,ourcountriescanworktogethertoimproveourcybersituaFonalawareness,sharpenincidentresponse,andthereforesecureASEAN’scommoncyberspace.

Page 25: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

25Copyright©CyberGreen2016AllRightsReserved.

PresidentBarackObamaonwhatAIMeansforNationalSecurity–WIRED

OBAMA:TradiFonally,whenwethinkaboutsecurityandprotecFngourselves,wethinkintermsofarmororwalls.Increasingly,Ifindmyselflookingtomedicineandthinkingaboutviruses,anFbodies.PartofthereasonwhycybersecurityconEnuestobesohardisbecausethethreatisnotabunchoftanksrollingatyoubutawholebunchofsystemsthatmaybevulnerabletoawormgeFnginthere.Itmeansthatwe’vegottothinkdifferentlyaboutoursecurity,makedifferentinvestmentsthatmaynotbeassexybutmayactuallyendupbeingasimportantasanything.

h_ps://www.wired.com/2016/10/president-obama-mit-joi-ito-interview/

WhatIspendalotofFmeworryingaboutarethingslikepandemics.Youcan’tbuildwallsinordertopreventthenextairbornelethalflufromlandingonourshores.Instead,whatweneedtobeabletodoissetupsystemstocreatepublichealthsystemsinallpartsoftheworld,Clicktriggersthattelluswhenweseesomethingemerging,andmakesurewe’vegotquickProtocolsandsystemsthatallowustomakevaccinesalotsmarter.SoifyoutakeapublichealthModel,andyouthinkabouthowwecandealwith,youknow,theproblemsofcybersecurity,alotmayendupbeingreallyhelpfulinthinkingabouttheAIthreats.

Page 26: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

HelpusfostertheCyberGreenapproach.

Contact:[email protected]