There is no security (and it feels just fine)

49
There is no security (and it feels just fine) Jonathan Care @arashiyama http://uk.linkedin.com/in/computercrime/

description

Slides supporting a talk given at the British Computer Society October 2014

Transcript of There is no security (and it feels just fine)

Page 1: There is no security (and it feels just fine)

There is no security

(and it feels just fine)

Jonathan Care@arashiyama

http://uk.linkedin.com/in/computercrime/

Page 2: There is no security (and it feels just fine)

@arashiyama

No Security: wtf?

Page 3: There is no security (and it feels just fine)

@arashiyama

kill off misconceptions

Page 4: There is no security (and it feels just fine)

@arashiyama

get past the sales talk

Page 5: There is no security (and it feels just fine)

@arashiyama

expose the cyber

Page 6: There is no security (and it feels just fine)

@arashiyama

We really do care about security and privacy…

Page 7: There is no security (and it feels just fine)

@arashiyama

Page 8: There is no security (and it feels just fine)

@arashiyama

Meanwhile …

Page 9: There is no security (and it feels just fine)

@arashiyama

Page 10: There is no security (and it feels just fine)

@arashiyama

What do IT guys actually care about?

Page 11: There is no security (and it feels just fine)

@arashiyama Credit: 451 Research

Page 12: There is no security (and it feels just fine)

@arashiyama

three faces of information security

Page 13: There is no security (and it feels just fine)

@arashiyama

compliance

Page 14: There is no security (and it feels just fine)

@arashiyama

business enablement

Page 15: There is no security (and it feels just fine)

@arashiyama

real infosec

Page 16: There is no security (and it feels just fine)

@arashiyama

Security fail #1 : PCI DSS

Page 17: There is no security (and it feels just fine)

@arashiyama

Most breaches web-commerce based

Page 18: There is no security (and it feels just fine)

@arashiyama

Although compromised PEDs are fun too

Page 19: There is no security (and it feels just fine)

@arashiyama

Security fail #2 : ICS/SCADA

Page 20: There is no security (and it feels just fine)

@arashiyama

Note: I will not visit you in prison if you get into trouble trying out this stuff. Also, SCADA systems control things that are IMPORTANT and should not be fscked with lightly

Page 21: There is no security (and it feels just fine)

@arashiyama

http://bit.ly/lyMi35Siemens, SIMATIC HMI, XP277, 6AV6 643-0CD01-1AX0, HW: 0, SW: V 1 1 2

Page 22: There is no security (and it feels just fine)

@arashiyama

http://bit.ly/jTlKsL(What temperature would you like your HVAC today?)

Page 23: There is no security (and it feels just fine)

@arashiyama

Wide open webcams?

Page 24: There is no security (and it feels just fine)

@arashiyama

Oh yeah.

Page 25: There is no security (and it feels just fine)

@arashiyama

Security fail #3 : Consumers

Page 26: There is no security (and it feels just fine)

@arashiyama

ecommerce

Page 27: There is no security (and it feels just fine)

@arashiyama

SaaS

Page 28: There is no security (and it feels just fine)

@arashiyama

(we are all consumers)

Page 29: There is no security (and it feels just fine)

@arashiyama

Security fail #4 – Software (!)

Page 30: There is no security (and it feels just fine)

@arashiyama

Heartbleed

Page 31: There is no security (and it feels just fine)

@arashiyama

ShellShock

Page 32: There is no security (and it feels just fine)

@arashiyama

Page 33: There is no security (and it feels just fine)

@arashiyama

Page 34: There is no security (and it feels just fine)

@arashiyama

So, how’s YOUR software dev doing?

Page 35: There is no security (and it feels just fine)

@arashiyama

Page 36: There is no security (and it feels just fine)

@arashiyama

Conclusions:

Page 37: There is no security (and it feels just fine)

@arashiyama

1.All software has bugs.

Page 38: There is no security (and it feels just fine)

@arashiyama

2. Bugs will be discovered

Page 39: There is no security (and it feels just fine)

@arashiyama

3. Some bugs will have a security impact

Page 40: There is no security (and it feels just fine)

@arashiyama

4. Product owners continue to value functionality over security

Page 41: There is no security (and it feels just fine)

@arashiyama

5. Investors place little value on security and privacy

Page 42: There is no security (and it feels just fine)

@arashiyama

6. End users trust vendors

Page 43: There is no security (and it feels just fine)

@arashiyama

What can we do?

Page 44: There is no security (and it feels just fine)

@arashiyama

PROTECT

DETECTRESPOND

Page 45: There is no security (and it feels just fine)

@arashiyama

SANS Top 20 Critical Controls

Page 46: There is no security (and it feels just fine)

@arashiyama

Policy, processes & guidelines

InfoSec checkpoints in project lifecycle

Threat Model

Risk Appetite / Risk Tolerance

Secure Software Environment

Operational Security Controls

Continuous Vulnerability Scan –Fix

Penetration Testing / Red teaming

Malware

IDS / IPS

Firewalls

Centralised Logging (SIEM)

Threat Intelligence

PROTECT

DETECTRESPOND

Incident Response (Threat Model)

Incident Response (“Bluebird”)

Exec-level(press, clients)

“Forensic Readiness”

Update PROTECT model

Page 47: There is no security (and it feels just fine)

@arashiyama

Secure Software Environment - BSIMM

Page 48: There is no security (and it feels just fine)

@arashiyama

Secure Software

Environment

Governance

Intelligence

SSDL Touchpoints

Deployment

Strategy and Metrics

Compliance and Policy

Training

Attack Models

Security Features and Design

Standards and Requirements

Architecture Analysis

Code Review

Security Testing

Penetration Testing

Software Environment

Configuration Mgmt / Vulnerability Mgmt

Page 49: There is no security (and it feels just fine)

@arashiyama