75
Information Security & Cybercrime status and way forward (writing on the wall) Sherif El-Kassas CTO SecureMisr December 20, 2011 1 2011/12/20

Information Security & Cybercrime status and way forward (writing on the wall)

  • Upload
    gage

  • View
    46

  • Download
    0

Embed Size (px)

DESCRIPTION

Information Security & Cybercrime status and way forward (writing on the wall). Sherif El- Kassas CTO SecureMisr December 20, 2011. Outline. Information Security O verview Technology and Trust (local perspective) Way forward: Societal directions R&D directions. Cybercrime. - PowerPoint PPT Presentation

Citation preview

Page 1: Information Security & Cybercrime status and way forward (writing on the wall)

1

Information Security & Cybercrimestatus and way forward(writing on the wall)

Sherif El-KassasCTO SecureMisrDecember 20, 2011

2011/12/20

Page 2: Information Security & Cybercrime status and way forward (writing on the wall)

2

Outline

• Information Security Overview

• Technology and Trust(local perspective)

• Way forward:– Societal directions– R&D directions

2011/12/20

Page 3: Information Security & Cybercrime status and way forward (writing on the wall)

3

Cybercrime

2011/12/20

Page 4: Information Security & Cybercrime status and way forward (writing on the wall)

4

http://news.bbc.co.uk/2/hi/business/davos/7862549.stm

2011/12/20

Page 5: Information Security & Cybercrime status and way forward (writing on the wall)

5

http://blogs.zdnet.com/security/?p=2868&tag=nl.e539

2011/12/20

Page 6: Information Security & Cybercrime status and way forward (writing on the wall)

6

http://www.privacydigest.com/2009/03/13/cybercrime+service+takes

2011/12/20

Page 7: Information Security & Cybercrime status and way forward (writing on the wall)

7

Information Security NewsOur Region

2011/12/20

Page 8: Information Security & Cybercrime status and way forward (writing on the wall)

8

http://www.itp.net/579360-egypt-and-saudi-snared-in-dangerous-botnet2011/12/20

Page 9: Information Security & Cybercrime status and way forward (writing on the wall)

9

http://www.zdnet.com/

2011/12/20

Page 10: Information Security & Cybercrime status and way forward (writing on the wall)

102011/12/20

http://www.akhbarelyom.org.eg/elakhbar/issues/18076/detailze3fad.html

Egyptian DA orders the arrest of “Internet Pirates”

Page 11: Information Security & Cybercrime status and way forward (writing on the wall)

112011/12/20

http://www.arabianbusiness.com/512710-thousands-hit-by-card-fraud

Page 12: Information Security & Cybercrime status and way forward (writing on the wall)

12

Nir Kshetri, “The Simple Economics of Cybercrimes,” IEEE Security & Privacy, January/February 2006

Countries Generating Most Online fraud

Security Trends & Newsin the region

2011/12/20

Page 13: Information Security & Cybercrime status and way forward (writing on the wall)

132011/12/20

Elsewhere

Page 14: Information Security & Cybercrime status and way forward (writing on the wall)

142011/12/20

Page 15: Information Security & Cybercrime status and way forward (writing on the wall)

152011/12/20

http://www.almasryalyoum.com/node/481121

Page 16: Information Security & Cybercrime status and way forward (writing on the wall)

162011/12/20

Page 17: Information Security & Cybercrime status and way forward (writing on the wall)

172011/12/20http://www.wired.com/threatlevel/2010/07/atms-jackpotted/

Page 18: Information Security & Cybercrime status and way forward (writing on the wall)

182011/12/20

Page 19: Information Security & Cybercrime status and way forward (writing on the wall)

19

http://www.reuters.com/article/technologyNews/idUSTRE5584CA20090609

2011/12/20

Page 20: Information Security & Cybercrime status and way forward (writing on the wall)

20

http://news.bbc.co.uk/2/hi/technology/7990997.stm

2011/12/20

Page 21: Information Security & Cybercrime status and way forward (writing on the wall)

212011/12/20

http://www.bbc.co.uk/news/technology-15817335

Page 22: Information Security & Cybercrime status and way forward (writing on the wall)

222011/12/20

http://www.bbc.co.uk/news/technology-15529930

Page 23: Information Security & Cybercrime status and way forward (writing on the wall)

232011/12/20

Hackers Broke Into Brazil Grid Last Thursdayhttp://news.slashdot.org/story/09/11/17/2245241/Hackers-Broke-Into-Brazil-Grid-Last-Thursday

Page 24: Information Security & Cybercrime status and way forward (writing on the wall)

242011/12/20http://www.itp.net/584600-new-malware-targeting-iranian-government

Page 25: Information Security & Cybercrime status and way forward (writing on the wall)

252011/12/20

http://www.fco.gov.uk/en/global-issues/london-conference-cyberspace/cyber-crime/case-studies/cyber-attacks-cabo

Page 26: Information Security & Cybercrime status and way forward (writing on the wall)

26

“on trusting trust”a local perspective

2011/12/20

Page 27: Information Security & Cybercrime status and way forward (writing on the wall)

27

Conspiracy Theories!

2011/12/20

Page 28: Information Security & Cybercrime status and way forward (writing on the wall)

282011/12/20

http://www.f-secure.com/weblog/archives/00002226.html

Nation-State

Lockheed-martinRSA secureID

Page 29: Information Security & Cybercrime status and way forward (writing on the wall)

292011/12/20

http://news.cnet.com/8301-27080_3-20068836-245/china-linked-to-new-breaches-tied-to-rsa/

Page 30: Information Security & Cybercrime status and way forward (writing on the wall)

302011/12/20

http://www.bbc.co.uk/news/technology-12473809

Page 31: Information Security & Cybercrime status and way forward (writing on the wall)

312011/12/20

http://www.bbc.co.uk/news/technology-13078297

Page 32: Information Security & Cybercrime status and way forward (writing on the wall)

32

http://newsworldwide.wordpress.com/2008/05/02/microsoft-discloses-government-backdoor-on-windows-operating-systems/

2011/12/20

Page 33: Information Security & Cybercrime status and way forward (writing on the wall)

33

http://vincentarnold.com/blog/chinese-backdoors-hidden-in-router-firmware/

2011/12/20

Page 34: Information Security & Cybercrime status and way forward (writing on the wall)

34

www.spectrum.ieee.org/may08/6171

2011/12/20

Page 35: Information Security & Cybercrime status and way forward (writing on the wall)

35http://www.iwm.org.uk/online/enigma/eni-intro.htm

2011/12/20

Page 36: Information Security & Cybercrime status and way forward (writing on the wall)

36

People!

2011/12/20

Page 37: Information Security & Cybercrime status and way forward (writing on the wall)

37

employee1 employee2

Hacker

Sorry!

Can’t Fax out

Please fax me

“Confidential

Information.”2011/12/20

Page 38: Information Security & Cybercrime status and way forward (writing on the wall)

38

employee1employee2

Hacker

fax to emp2

“Confidential

Information.”

“ConfidentialInformation”

Please forward

the fax you’ve

just received.“Confidential

Information”

2011/12/20

Page 39: Information Security & Cybercrime status and way forward (writing on the wall)

39

Seeking answers

2011/12/20

Page 40: Information Security & Cybercrime status and way forward (writing on the wall)

40

Some Perspective

2011/12/20

Page 41: Information Security & Cybercrime status and way forward (writing on the wall)

41

cert.org

2011/12/20

Page 42: Information Security & Cybercrime status and way forward (writing on the wall)

42

Security is Socio-technical & Physical!

Security ≠ Technological Security

2011/12/20

Page 43: Information Security & Cybercrime status and way forward (writing on the wall)

43

Technological

Business Risks

Security Risks

Networks

Systems

Applications

Data & Information

People

2011/12/20

Page 44: Information Security & Cybercrime status and way forward (writing on the wall)

442011/12/20

research agenda

Page 45: Information Security & Cybercrime status and way forward (writing on the wall)

45http://www.cra.org/2011/12/20

Page 46: Information Security & Cybercrime status and way forward (writing on the wall)

46http://www.cra.org/

2011/12/20

Page 47: Information Security & Cybercrime status and way forward (writing on the wall)

472011/12/20

development agenda

Page 48: Information Security & Cybercrime status and way forward (writing on the wall)

48

• The need for trustworthy technology– One possible approach• Build your own• Start from OSS to save time• Strong certification program to ensure quality

• Invest in people– The true asset

• Standards to ensure no short cuts are taken

2011/12/20

Page 49: Information Security & Cybercrime status and way forward (writing on the wall)

49

Conclusions

• Information Security is a huge challenge• Appears to be a loosing battle at the moment• We need to education ourselves and

understand the significance of infosec• Trustworthy technology and people at the

right place

• Invest in R&D

2011/12/20

Page 50: Information Security & Cybercrime status and way forward (writing on the wall)

50

Thank you

Question?

2011/12/20

Page 51: Information Security & Cybercrime status and way forward (writing on the wall)

512011/12/20

The bot-net trade

Page 52: Information Security & Cybercrime status and way forward (writing on the wall)

522011/12/20

http://en.wikipedia.org/wiki/File:Botnet.svg

Page 53: Information Security & Cybercrime status and way forward (writing on the wall)

53

Types of attacks

2011/12/20

Page 54: Information Security & Cybercrime status and way forward (writing on the wall)

Types of Threats & Attacks

• Technical– Using technological means to break into an

organization's network and systems• Physical– Physically access and attack the enterprise

• Social– Social engineering attacks

Page 55: Information Security & Cybercrime status and way forward (writing on the wall)

55

simple technical attacksfield experienceHow easy is it?

2011/12/20

Page 56: Information Security & Cybercrime status and way forward (writing on the wall)

562011/12/20

Page 57: Information Security & Cybercrime status and way forward (writing on the wall)

572011/12/20

Page 58: Information Security & Cybercrime status and way forward (writing on the wall)

582011/12/20

Page 59: Information Security & Cybercrime status and way forward (writing on the wall)

592011/12/20

Page 60: Information Security & Cybercrime status and way forward (writing on the wall)

602011/12/20

Page 61: Information Security & Cybercrime status and way forward (writing on the wall)

612011/12/20

Page 62: Information Security & Cybercrime status and way forward (writing on the wall)

622011/12/20

Page 63: Information Security & Cybercrime status and way forward (writing on the wall)

632011/12/20

Page 64: Information Security & Cybercrime status and way forward (writing on the wall)

642011/12/20

Page 65: Information Security & Cybercrime status and way forward (writing on the wall)

65

name=skpass=Linux4ever

2011/12/20

Page 66: Information Security & Cybercrime status and way forward (writing on the wall)

66

More field experienceGoogle is a friend!

2011/12/20

Page 67: Information Security & Cybercrime status and way forward (writing on the wall)

67

Google for:

site:XYZ.eg inurl:code= filetype:asp

2011/12/20

Page 68: Information Security & Cybercrime status and way forward (writing on the wall)

68

Programming 101: Check inputs!

2011/12/20

Page 69: Information Security & Cybercrime status and way forward (writing on the wall)

69

Direct from the Database!

2011/12/20

Page 70: Information Security & Cybercrime status and way forward (writing on the wall)

70

More field experience:Phishing

2011/12/20

Page 71: Information Security & Cybercrime status and way forward (writing on the wall)

71

Email & Phishing

2011/12/20

Page 72: Information Security & Cybercrime status and way forward (writing on the wall)

72

Email & Phishing

2011/12/20

Page 73: Information Security & Cybercrime status and way forward (writing on the wall)

732011/12/20

physical attacks

Page 74: Information Security & Cybercrime status and way forward (writing on the wall)

742011/12/20

http://www.answers.com/topic/keystroke-logger?cat=technology

Page 75: Information Security & Cybercrime status and way forward (writing on the wall)

75

http://www.linuxdevices.com/articles/AT2016997232.html2011/12/20