The Newest Element of Risk Metrics: Social Media

32
SESSION ID: The Newest Element of Risk Metrics: Social Media GRC-T10R Ian Amit Vice President ZeroFOX inc. @iiamit

Transcript of The Newest Element of Risk Metrics: Social Media

Page 1: The Newest Element of Risk Metrics: Social Media

SESSION ID:

TheNewestElementofRiskMetrics:SocialMedia

GRC-T10R

IanAmitVicePresident ZeroFOXinc. @iiamit

Page 2: The Newest Element of Risk Metrics: Social Media

BasicMo<va<on-ho?est/easiestvector!

“…inpreviousyears,wesawphishingmessagescomeandgoandreportedthattheoveralleffecAvenessofphishingcampaignswasbetween10and20%.Thisyear,wenotedthatsomeofthesestatswenthigher,with23%ofrecipientsnowopeningphishingmessagesand11%clickingona?achments.Somestatswerelower,though,withaslightdeclineinusersactuallygoingtophishingsitesandgivinguppasswords.”

“Fortwoyears,morethantwo-thirdsofincidentsthatcomprisetheCyber-EspionagepaNernhavefeaturedphishing.”

2015DBIR

2

Page 3: The Newest Element of Risk Metrics: Social Media

WhydoIwantthis?

Everyoneisonsocialmedia.Whetheryoutellyouremployeesthattheycanorcan’t.

OrganizaAonsfindthattheyconductbusinesscommunicaAonsoversocialmedia.

Thegapbetweenonlineandphysicalisverynarrowwhenfactoringinsocialmedia.

ANackerstargetorganizaAonsthroughthepathofleastresistance.Socialmediaistheeasiestas:

Thereareless(ifany)controlsoverit.Itprovidesamorepersonalized“experience”fortheuser(unlikeemail).ItismoreinteracAveandaNackerscanquicklyadapttheirapproach.

ItiseasytoimpersonatesomeoneonsocialmediaandimpacttheorganizaAon.

3

Page 4: The Newest Element of Risk Metrics: Social Media

Whoispoten<allyaffected?

Areyouengagedina“controversial”pracAce?

4

FinancialServices DIB Healthcare

Pharma Agribusiness LEA

Energy

Page 5: The Newest Element of Risk Metrics: Social Media

CanIreallypredictriskbasedonSMac<vity?

SenAmentanalysisandtheGermanelecAons

PredicAngElecAonswithTwiNer:What140CharactersRevealaboutPoliAcalSenAment

“TwiNercanbeseenasavalidreal-AmeindicatorofpoliAcalsenAment.”

hNp://www.aaai.org/ocs/index.php/ICWSM/ICWSM10/paper/viewFile/1441/1852

5

Page 6: The Newest Element of Risk Metrics: Social Media

6

Page 7: The Newest Element of Risk Metrics: Social Media

#RSAC

Comingupwithasolu<on

Frameworkformeasuringtheriskofaperson/organizaAon’ssocialmediaacAvity

Page 8: The Newest Element of Risk Metrics: Social Media

Whatisitthatweneedtoaddress?

Aframeworkforyoutolookathowinflammatoryor“risky”individualsinyourorganizaAonare.Individuals:

likeexecuAves,technicalcontractors&employeeswho,youknow,mighthaveadminaccess,and/oremployeessuscepAbletootherriskcategorieslikeFraud,ReputaAon,andStrategicrisk.

8

Page 9: The Newest Element of Risk Metrics: Social Media

WhatwillIgetoutofthis?

Theabilitytobuildascorecardallowingyoutorankemployeerisk.

TheabilitytodrilldownintotheSMbehaviorsthatcontributetorisk

AndsubsequentlylowerariskprofilethroughapplyingcontrolstoselectelementsidenAfiedthroughtheprocess.

TheabilitytoenhanceOSINTfuncAonswithSM-focusedfuncAons

9

Page 10: The Newest Element of Risk Metrics: Social Media

Basicconceptsbehindthemodel

WeuAlizedtheGQMapproach:

Conceptuallevel(goal)Goalsdefinedforanobjectforavarietyofreasons,withrespecttovariousmodels,fromvariouspointsofview.

OperaAonallevel(ques<on)QuesAonsareusedtodefinemodelsoftheobjectofstudyandthenfocusesonthatobjecttocharacterizetheassessmentorachievementofaspecificgoal.

QuanAtaAvelevel(metric)Metrics,basedonthemodels,isassociatedwitheveryquesAoninordertoansweritinameasurableway.

10

Page 11: The Newest Element of Risk Metrics: Social Media

GQM

11

VictorBasili

Goalsestablishwhatwewanttoaccomplish.

Questionshelpusunderstandhowtomeetthegoal.Theyaddresscontext.

Metricsidentifythemeasurementsthatareneededtoanswerthequestions.

Goal 1 Goal 2

Q1 Q2 Q3 Q4 Q5

M1 M2 M3 M4 M5 M6 M7

11

Page 12: The Newest Element of Risk Metrics: Social Media

OurGQMdata

Goal:Provideasocialmediariskscorecardforaperson/organizaAon.

QuesAons:Howwouldone’sOAaffectthelikelihoodofathreat?Howwouldone’sOAaffectstheimpactofathreat,andtheareasofimpact?HowdoesunsancAonedpresenceofsomeoneaffectsaidthreats?

Metrics:ProvideaqualitaAve*approachtomeasuringtheoverallrisk,aswellasspecificaspectsofthesocialmediapresence.

12

*And when we say qualitative we lie a little bit…

Page 13: The Newest Element of Risk Metrics: Social Media

MoreGoals

1.ProvideameasurablewaytoquanAfyriskassociatedwithonlineacAvityoftheorganizaAonandit'semployees.

2.ProvideanothermeasureforquanAfyingriskofworkingwith3rdparAesandcontractors.

3.CreateascoreforexecuAvestomeasuretheirsocialmediaexposure(fromanexecprotecAonperspecAve,insidertrading,etc...)

4.CreateascoreformeasuringandcomparingintraandextraindustrysocialmediariskraAngs

5.BeabletoquanAfytheeffectofchangingcontrols,processesandpoliciesontheriskassociatedwithsocialmedia.

13

Page 14: The Newest Element of Risk Metrics: Social Media

Mindmap(seeexternalreferences)

14

Page 15: The Newest Element of Risk Metrics: Social Media

Developingthescoreboard

Startedwiththebasics,comparaAvemeasurements…

QualitaAveapproachdictatestryingtoleavequanAtaAveelementsout(whichwekind’atryto).Sothecompromisewastoprovideafairlydetailedbreakdownofelements,andinsteadofmeasuringthemonascale,onlyindicatepresence(1or0).

AggregaAondidn'twork(per-se),Averagingwouldnottakeintoaccountthefullmagnitudeofthelargestelements,MAX()wouldnotfactorincontribuAonfromsmallerones.Wehavetoprovidemoreaccurateweights…

15

Page 16: The Newest Element of Risk Metrics: Social Media

ScoringApproach

EndedupwithprovidingaweighAngsystemforthemajorelementsandtheirimportancetotheorganizaAon(context?!).

GivenXpointstodistributebetweenYelements.Weight=Y’/XwhereY’isthenumberofpointsgiventoeachelement.

Sum(Y’…Y’’)=1

ApplyweighAngtothescorecardtogetweightedriskscore.(whereweightsareappropriatefortheorganizaAon’soperaAonalcontext).

16

Page 17: The Newest Element of Risk Metrics: Social Media

Weigh<ng

17 Sample

Page 18: The Newest Element of Risk Metrics: Social Media

Scorecardroadmap

Current:BreakdownofLikelihood,Manifesta<on,Impact,andanesAmatedfactorofthenumberofonlinethreats(bycompoundingmonitoredinstancesofthreatactorswiththemediumused).

Future:Addbreakdowntopersonalvscorporaterisk,andfurthersemanAcssuchasexposuretomaliciouscontent,negaAvesenAment,informaAonleaks,etc…

18

Page 19: The Newest Element of Risk Metrics: Social Media

Whatkindofdataisneeded?

OrganizaAonsize,andthesizeofthemanagement.

HowmanyintheorganizaAonaremonitored(andinmanagement)

LocalityinformaAon(HQ,offices,sizeperlocaAon)

ChaNer-menAoning,conversingwith,andtalkingaboutmonitoredassets.Also-assetsposAng/conversing/menAoningothers.

ImpersonaAons-whoisbeingimpersonated?What’stheintent(nefariousvs.parody)

SenAmentanalysis-inchaNer,brokendowntomanagementvscompanyvsindividuals(perlocaAon),andbydistancefromasset(1st,2nd,3rddegree)

19

Page 20: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP1:DeterminehowyourorganizaAonwillsupportprofiling.NoneatallNonebutpubliclyavailableinformaAonVoliAonalEnforced

20

Page 21: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP2:DeterminewhoyoumightwanttoprotectprivilegedITusersexecuAves/boardmembersmarkeAng/PRpeoplesales

21

Page 22: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP3:DeterminewhereyouwillprofilethemSocialMediasitesWebsitesBlogcomments

22

Page 23: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP4:Collect<ALL>thedata.Extract/Tranform/Load

Scrape/Transform/LoadAnalysispostscrapeAnalysisinreal-ishAme(stormuw) (twiNerapi->spout->boltforprocessing)

23

Page 24: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP5:Storethedata.Whateveryouwant.

24

Page 25: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP6A:AnalysisAmishhandcraued

Scorecommentsregardingthefactorsthatcontributetothelikelihood/manifestaAon/impactelementsofthemodelUsefreebietoolsordoityourselftoolslike…hNps://tone-analyzer-demo.mybluemix.net/hNps://watson-pi-demo.mybluemix.net/Scoreinourhandy-dandyexceltool(orsomevariaAonthereof)

25

Page 26: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?(automatedanalysis)

26

Page 27: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP6B:DIYBIGDATAMAGICSSenAmentanalysis(listfromhNp://breakthroughanalysis.com/2012/01/08/what-are-the-most-powerful-open-source-senAment-analysis-tools/)PythonNLTK(NaturalLanguageToolkit),hNp://www.nltk.org/,butseealsohNp://text-processing.com/demo/senAment/–R,TM(textmining)module,hNp://cran.r-project.org/web/packages/tm/index.html,includingtm.plugin.senAment.–RapidMiner,hNp://rapid-i.com/content/view/184/196/.–GATE,teGeneralArchitectureforTextEngineering,hNp://gate.ac.uk/senAment/.ApacheUIMAistheUnstructuredInformaAonManagementArchitecture,hNp://uima.apache.org/—alsosenAmentclassifiersfortheWEKAdata-miningworkbench,hNp://www.cs.waikato.ac.nz/ml/weka/.SeehNp://www.unal.edu.co/diracad/einternacional/Weka.pdfforoneexample.StanfordNLPtools,hNp://www-nlp.stanford.edu/souware/LingPipe,(pseudo-opensource).SeehNp://alias-i.com/lingpipe/demos/tutorial/senAment/read-me.html.

27

Page 28: The Newest Element of Risk Metrics: Social Media

HowcanYOUdoit?

STEP7:SCORECARD!OutputviamodelRemember,it’sthefactorsofstressnotnecessarilya“riskscore”thatmaNers.UlAmategoalisprotect,bethatviatechnologyorbehavioralcontrols.Alsoapplicable-legal,financialhedging,insurance,etc…

28

Page 29: The Newest Element of Risk Metrics: Social Media

Wherecanyougetit?

TheSocietyofInformaAonRiskAnalysts

hNp://www.societyinforisk.org

AswellasontheSMRMsite:

hNp://risk-metrics.com/

29

Page 30: The Newest Element of Risk Metrics: Social Media

Take-away

1. Checkwhatisyourcurrentsocialmediasecuritypolicy(ifyouhaveone).

2. Doyouhaveacurrentriskmodelthatincorporatessocialmediaaspartofit(aNacksurface/informaAonleak/intelligence)

3. MeasureyourcurrentsocialmediariskpostureforkeyindividualsinyourorganizaAon.

Andthenin2-3months-measureagaintoseewhetheranychangesyouhaveimplementedinlightoftheiniAalmeasurementhadtherightimpact.

30

Page 31: The Newest Element of Risk Metrics: Social Media

#RSAC

Thankyou!

Ques<ons?

IanAmit:@iiamit|[email protected]|hNp://www.iamit.org

Page 32: The Newest Element of Risk Metrics: Social Media

Resources

SenAmentanalysisandgermanelecAons:hNp://www.aaai.org/ocs/index.php/ICWSM/ICWSM10/paper/viewFile/1441/1852

Analyzetoneoftext:hNps://tone-analyzer-demo.mybluemix.net/

Analyzepersonalitybasedontext:hNps://watson-pi-demo.mybluemix.net/

SenAmentanalysis(listfromhNp://breakthroughanalysis.com/2012/01/08/what-are-the-most-powerful-open-source-senAment-analysis-tools/)

PythonNLTK(NaturalLanguageToolkit),hNp://www.nltk.org/,butseealsohNp://text-processing.com/demo/senAment/R,TM(textmining)module,hNp://cran.r-project.org/web/packages/tm/index.html,includingtm.plugin.senAment.RapidMiner,hNp://rapid-i.com/content/view/184/196/.GATE,teGeneralArchitectureforTextEngineering,hNp://gate.ac.uk/senAment/.

ApacheUIMAistheUnstructuredInformaAonManagementArchitecture,hNp://uima.apache.org/—alsosenAmentclassifiersfortheWEKAdata-miningworkbench,hNp://www.cs.waikato.ac.nz/ml/weka/.SeehNp://www.unal.edu.co/diracad/einternacional/Weka.pdfforoneexample.

StanfordNLPtools,hNp://www-nlp.stanford.edu/souware/

LingPipe,(pseudo-opensource).SeehNp://alias-i.com/lingpipe/demos/tutorial/senAment/read-me.html.

32