17
Hitting Above The Security Mendoza Line Ed Bellis, CEO Risk I/O

Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

  • Upload
    others

  • View
    9

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Hitting Above The Security Mendoza LineEd Bellis, CEO Risk I/O

Page 2: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Nice To Meet YouCoFounder Risk I/O

About Me

About Risk I/O

Former CISO Orbitz

Contributing Author Beautiful Security

CSO Magazine/Online Writer

Data-Driven Vulnerability Management as a Service

DataWeek 2012 Top Security Innovator

3 Startups to Watch - Information Week

InfoSec Island Blogger

16 Hot Startups - eWeek

Page 3: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

About Mario

Played for Pirates, Rangers & Mariners

Played MLB for 9 Seasons

Lifetime Batting Avg: .214, 4HR, 101 RBI

Failed to bat .200 5 times

Page 4: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

The Security Mendoza Line

Alex Hutton came up with original concept of the Security Mendoza Line

http://riskmanagementinsight.com/riskanalysis/?p=294

Wouldn’t it be nice if we had something that helped us divide who we considered “Amateur” and who we considered “Professional”?

Enter The Security Mendoza Line

Page 5: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Josh Corman expands

HD Moore’s Law

the Security Mendoza Line

“Compute power grows at the rate of doubling about every 2 years”

“Casual attacker power grows at the rate of Metasploit”

Page 6: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

A Difficult Task

ExploitDB > 18K Exploits0

500

1000

1500

2000

2010 2012

Exploit Development

MSF Modules

Nearly 2K MSF Exploits

Page 7: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Release Early Release Often

Page 8: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Point Click Pwn

Page 9: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

A Data Driven Approach

Page 10: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Out Scripting the Kiddies

Fighting Automation with Automation

Avg: .200

Netflix/SimianArmy Github

Page 11: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Context Matters

Attack Path data analysis

Avg: .220

Page 12: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Context Matters

Mitigating Controls

Firewalls / ACLs

IPS

WAF

MFA

Other

Avg: .240

Page 13: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Context Matters

Honeypot, WAF & IDS data

Avg: .260

logs! logs! logs!

Measuring Likelihood

Page 14: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

My(vuln posture X other threat activity) / (other

vuln posture X other threat activity)

Broader Context

Targets of Opportunity?

Avg: .280

Page 15: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Beyond Info SharingModel Sharing

Avg: .300ALL Star!

Page 16: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

CVE Trending Analysis

A Quick Side Note

Gunnar’s Debt Clock

Page 17: Hitting Above The Security Mendoza Line Ed Bellis ... - SecTor Bellis - Hitting Above... · The Security Mendoza Line Alex Hutton came up with original concept of the Security Mendoza

Q & A

follow us

http://blog.risk.io/

http://www.honeyapps.com/signuphttp://www.honeyapps.com/signup

@riskio

@ebellis

the blog

twitter

And one more thing....

We’re Hiring! https://www.risk.io/jobs