SlideShare ist ein Scribd-Unternehmen logo
1 von 19
A Military Perspective on Cyber Security  “Not a Paradigm Shift, Tactical Approach”  Joey Hernandez CISSP, MBCI jhernandez@iSCSP.org
Topic Background The Change Center of Gravity Rings Principles of War Contested Commons Your Turn
About Me Former Intelligence and Cyber Operations Analyst with a broad background in all domains of Network Operations.  College Professor in the areas of Criminal Justice & Information Security Background in assessments covering NIST, FIPS, & ISO standards Background in International CERT operations & current Director of Operations for the iSCSP
Background Elevated age in cyber warfare Malware has become focused  SCADA Systems (Stuxnet) Malware performs Operational Preparation of the Environment (OPE) Conficker (Millions still infected) Ransomeware Data is being held hostage The advanced capability of the threat has increased the risk.  Understanding the risk allows employment of defensive measures to mitigate the risk – “Risk will always be present”
The Change Combined capabilities have helped attackers create weapon systems Soldier +Rifle + Bullets =(This is a weapon systems) Cyber State Sponsored, Script Kiddies, Paid Staff Laptop, Desktop, Mobile devices Metasploit, Backtrak, PoisonIvy, Mpack, other RAT Hacker + Laptop + Metasploit = Weapon System Attackers, Adversaries, Cyber terrorist are now employing TTP
Wardens Rings The focus is to attack Centers of Gravity  The Estonian attacks Utilized TTP Rings   Leadership (Defaced Ministry of Defense, Finance, etc) Organic/System Essentials Infrastructure (DDoS against ISP and Wardialing to lock up POTS network) Population (News Media) Fielded Military Forces Inside Out Attack Methodology For Kinetic Warfare
Cyber  Population attacks cascade the rings System essential attacks on services eg. Supply Chain, Food, FedEx ; feeds the rings in both direction Infrastructure attacks feed the rings both directions Leadership focus elevates the nature of the actions Inside Out Attack Methodology For Cyber Warfare “Defense measures must ensure protection of systems first and population foremost”
Countering Principles of War Raising perceptions of attacks guarantee an elevated perspective. Proactive approaches to providing defense-in- depth reduces risk to all Centers of Gravity NOT immediately achievable, requires buy-in
Principle 1 Objective:Direct every operation towards a clearly defined, decisive, and attainable objective. Security Create policy & Directives that are concise, fed from leadership and enhances current capabilities. Defense Institutionalize SOP creating a path to obtainable objectives
Principle 2 Offensive:Seize, retain, and exploit the initiative Cyber Security personnel must have all tools required to respond to incidents or events when presented enabling decisive results Immediate knowledge of events through proactive Proactive research International teams of trust Reverse engineering of “current” malicious code Pentesting with seized exploits ensure preparedness Exercise routinely against new threats Exploitation allows establishing opstempo for defensive and counter operations.
Principle 3 Economy of Force:Allocate minimum essential combat power to secondary efforts. Cyber Security staff should only be allocated tasks relating to protection of grid and its associated systems Minimize external tasks not associated to Cyber Security “Employ” others to do: password resets, maintenance, and support Discriminate whenever possible! Indentify and prioritize cyber assets and assign coverage accordingly
Principle 4 Mass:	Concentrate combat power at the decisive place and time. Sustain with technology, resolve with Mass – Use Crisis action teams, leverage distributed knowledge “Get there first with the most”. The dynamic nature of Cyber Space allows you to employ mass globally with centralized control Convene and delegate Ensure communication is continuous If possible (Make possible) Disarm the attacker Block/Mitigate adversaries ability to maneuver, virtual arm bar Remain focused on protection
Principle 5 Surprise:Strike the enemy at a time, place, or manner for which they are unprepared. Always expect it! Trust but verify – If the network is quiet lower thresholds, to find hidden traffic Utilize time to influence out of the box operating procedures and TTP to develop  Always expect it!
Principle 6 Maneuver:Place the enemy in a position of disadvantage through flexible application of combat power Gain an advantage in positioning by training, certifying defense crews Exercising as a team places the adversary in a position of disadvantage Train as a group to flexibly protect, respond, and mitigate attacks Leverage internal and external trusted SME capabilities
Principle 7 Unity of Command:	For every objective, ensure unity of effort under one responsible commander. A single leader should provide direction and coordination for crews ensuring clear and concise objectives. Alignment facilitates communication for mission/common objective Each task presented should have ownership and custodial characteristics for members of the crew Ideas & Solutions  Preferred collective Collective not required
Principle 8 Security:Never permit the enemy to acquire an unexpected advantage. Protect and preserve defense measures, procedures and capabilities from the eyes of the adversary. Protect Information, through PEOPLE vetting “Minimize the chance of future Wiki Leaks” Security exertion minimizes attack vectors Understand the capabilities and limiting factors of your people – “provides for a clearer situational awareness”
Principle 9 Simplicity:Prepare clear, uncomplicated plans concise orders to ensure thorough understanding. Concise Plans and Orders minimize the chance for mistakes.  Degree of operational simplicity results from from experience, training, empowerment and institutionalization of processes. Simplicity in Cyber Operations  - is an Art of Balance Open lines of communication Local & Global support simplicity and information sharing
Contested Commons It is Global medium:	Maritime, Air, Space, Cyber Relied upon for business globalization More nations, organizations, economies at risk Rapid capability development, sluggish legal and global agreement on how to “Address Cyber Attacks” Russia & China created No CY Zones  Some believe there is “No Cyber War” Ask Estonia, Brazil, Canada, South Africa, Malaysia
Your Turn Train & Exercise your crews as a team Open lines of communication Think strategically, act locally Be proactive, make quick fixes, and best practice into TTP Be paranoid, suspicious and know your adversaries Build your trusted crisis network Plan for events Clear the fog

Weitere ähnliche Inhalte

Was ist angesagt?

Cyber Threat Intelligence
Cyber Threat IntelligenceCyber Threat Intelligence
Cyber Threat IntelligencePrachi Mishra
 
Cyber security presentation
Cyber security presentation Cyber security presentation
Cyber security presentation sweetpeace1
 
Cyber Terrorism Presentation
Cyber Terrorism PresentationCyber Terrorism Presentation
Cyber Terrorism Presentationmerlyna
 
Cybersecurity Employee Training
Cybersecurity Employee TrainingCybersecurity Employee Training
Cybersecurity Employee TrainingPaige Rasid
 
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Stephen Cobb
 
Cyber Security Awareness Session for Executives and Non-IT professionals
Cyber Security Awareness Session for Executives and Non-IT professionalsCyber Security Awareness Session for Executives and Non-IT professionals
Cyber Security Awareness Session for Executives and Non-IT professionalsKrishna Srikanth Manda
 
Cybersecurity Awareness Training
Cybersecurity Awareness TrainingCybersecurity Awareness Training
Cybersecurity Awareness TrainingDave Monahan
 
IT Security Awareness-v1.7.ppt
IT Security Awareness-v1.7.pptIT Security Awareness-v1.7.ppt
IT Security Awareness-v1.7.pptOoXair
 
Cyber security
Cyber securityCyber security
Cyber securitymanoj duli
 
Cybersecurity Attack Vectors: How to Protect Your Organization
Cybersecurity Attack Vectors: How to Protect Your OrganizationCybersecurity Attack Vectors: How to Protect Your Organization
Cybersecurity Attack Vectors: How to Protect Your OrganizationTriCorps Technologies
 
Cyber Threat Intelligence
Cyber Threat IntelligenceCyber Threat Intelligence
Cyber Threat IntelligenceZaiffiEhsan
 
Cyber security awareness
Cyber security awarenessCyber security awareness
Cyber security awarenessJason Murray
 

Was ist angesagt? (20)

cyber security
cyber securitycyber security
cyber security
 
Risk Assessments
Risk AssessmentsRisk Assessments
Risk Assessments
 
Cyber Threat Intelligence
Cyber Threat IntelligenceCyber Threat Intelligence
Cyber Threat Intelligence
 
Cyber security presentation
Cyber security presentation Cyber security presentation
Cyber security presentation
 
Cyber Terrorism Presentation
Cyber Terrorism PresentationCyber Terrorism Presentation
Cyber Terrorism Presentation
 
Cybersecurity Employee Training
Cybersecurity Employee TrainingCybersecurity Employee Training
Cybersecurity Employee Training
 
Cybersecurity
CybersecurityCybersecurity
Cybersecurity
 
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
 
Cyber Security Awareness Session for Executives and Non-IT professionals
Cyber Security Awareness Session for Executives and Non-IT professionalsCyber Security Awareness Session for Executives and Non-IT professionals
Cyber Security Awareness Session for Executives and Non-IT professionals
 
Cybersecurity Awareness Training
Cybersecurity Awareness TrainingCybersecurity Awareness Training
Cybersecurity Awareness Training
 
IT Security Awareness-v1.7.ppt
IT Security Awareness-v1.7.pptIT Security Awareness-v1.7.ppt
IT Security Awareness-v1.7.ppt
 
Cyber security
Cyber securityCyber security
Cyber security
 
cyber security
cyber securitycyber security
cyber security
 
Cybersecurity Attack Vectors: How to Protect Your Organization
Cybersecurity Attack Vectors: How to Protect Your OrganizationCybersecurity Attack Vectors: How to Protect Your Organization
Cybersecurity Attack Vectors: How to Protect Your Organization
 
Cyber Terrorism
Cyber TerrorismCyber Terrorism
Cyber Terrorism
 
Security awareness
Security awarenessSecurity awareness
Security awareness
 
Cybersecurity Roadmap Development for Executives
Cybersecurity Roadmap Development for ExecutivesCybersecurity Roadmap Development for Executives
Cybersecurity Roadmap Development for Executives
 
Cyber Threat Intelligence
Cyber Threat IntelligenceCyber Threat Intelligence
Cyber Threat Intelligence
 
Introduction to security
Introduction to securityIntroduction to security
Introduction to security
 
Cyber security awareness
Cyber security awarenessCyber security awareness
Cyber security awareness
 

Andere mochten auch

Securing the Internet of Things
Securing the Internet of ThingsSecuring the Internet of Things
Securing the Internet of ThingsPaul Fremantle
 
Military Robots
Military RobotsMilitary Robots
Military Robotsnsapre
 
Civil – military relations in india a perspective
Civil – military relations in india   a perspectiveCivil – military relations in india   a perspective
Civil – military relations in india a perspectiveUmong Sethi
 
Cyber security
Cyber securityCyber security
Cyber securitySiblu28
 
Network Security Threats and Solutions
Network Security Threats and SolutionsNetwork Security Threats and Solutions
Network Security Threats and SolutionsColin058
 
IoT - IT 423 ppt
IoT - IT 423 pptIoT - IT 423 ppt
IoT - IT 423 pptMhae Lyn
 

Andere mochten auch (9)

Securing the Internet of Things
Securing the Internet of ThingsSecuring the Internet of Things
Securing the Internet of Things
 
Military Robots
Military RobotsMilitary Robots
Military Robots
 
Indian Army
Indian ArmyIndian Army
Indian Army
 
Indian army
Indian armyIndian army
Indian army
 
Network security
Network securityNetwork security
Network security
 
Civil – military relations in india a perspective
Civil – military relations in india   a perspectiveCivil – military relations in india   a perspective
Civil – military relations in india a perspective
 
Cyber security
Cyber securityCyber security
Cyber security
 
Network Security Threats and Solutions
Network Security Threats and SolutionsNetwork Security Threats and Solutions
Network Security Threats and Solutions
 
IoT - IT 423 ppt
IoT - IT 423 pptIoT - IT 423 ppt
IoT - IT 423 ppt
 

Ähnlich wie A military perspective on cyber security

Strategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity RisksStrategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity RisksMatthew Rosenquist
 
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...Morakinyo Animasaun
 
Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016CSO_Presentations
 
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie AheadRethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie AheadOpenDNS
 
The Economics of Cyber Security
The Economics of Cyber SecurityThe Economics of Cyber Security
The Economics of Cyber SecurityJohn Gilligan
 
Cyber Security Audit.pdf
Cyber Security Audit.pdfCyber Security Audit.pdf
Cyber Security Audit.pdfVograce
 
Phases of Incident Response
Phases of Incident ResponsePhases of Incident Response
Phases of Incident ResponseEC-Council
 
Improve Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USMImprove Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USMAlienVault
 
Symantec cyber-resilience
Symantec cyber-resilienceSymantec cyber-resilience
Symantec cyber-resilienceSymantec
 
Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?nathan816428
 
Multimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguisMultimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguissamis
 
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual SecurityA Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual SecurityHossam Al-Ansary
 
Preparing for future attacks. Solution Brief: Implementing the right securit...
Preparing for future attacks.  Solution Brief: Implementing the right securit...Preparing for future attacks.  Solution Brief: Implementing the right securit...
Preparing for future attacks. Solution Brief: Implementing the right securit...Symantec
 
Proposal defense presentation
Proposal defense presentationProposal defense presentation
Proposal defense presentationRuchika Mehresh
 
[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defence[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defenceOWASP EEE
 
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINALDefending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINALMichael Bunn
 
Wasn't expecting that! Now what?
Wasn't expecting that! Now what?Wasn't expecting that! Now what?
Wasn't expecting that! Now what?Jisc
 

Ähnlich wie A military perspective on cyber security (20)

Strategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity RisksStrategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity Risks
 
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
 
Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016
 
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie AheadRethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
 
The Economics of Cyber Security
The Economics of Cyber SecurityThe Economics of Cyber Security
The Economics of Cyber Security
 
Cyber Security Audit.pdf
Cyber Security Audit.pdfCyber Security Audit.pdf
Cyber Security Audit.pdf
 
Phases of Incident Response
Phases of Incident ResponsePhases of Incident Response
Phases of Incident Response
 
Improve Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USMImprove Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USM
 
Symantec cyber-resilience
Symantec cyber-resilienceSymantec cyber-resilience
Symantec cyber-resilience
 
Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?
 
Cyber Resilience
Cyber ResilienceCyber Resilience
Cyber Resilience
 
Multimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguisMultimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguis
 
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual SecurityA Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
 
Preparing for future attacks. Solution Brief: Implementing the right securit...
Preparing for future attacks.  Solution Brief: Implementing the right securit...Preparing for future attacks.  Solution Brief: Implementing the right securit...
Preparing for future attacks. Solution Brief: Implementing the right securit...
 
Proposal defense presentation
Proposal defense presentationProposal defense presentation
Proposal defense presentation
 
[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defence[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defence
 
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINALDefending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
 
Iscsp apt
Iscsp aptIscsp apt
Iscsp apt
 
SecurityOperations
SecurityOperationsSecurityOperations
SecurityOperations
 
Wasn't expecting that! Now what?
Wasn't expecting that! Now what?Wasn't expecting that! Now what?
Wasn't expecting that! Now what?
 

Kürzlich hochgeladen

Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
React Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App FrameworkReact Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App FrameworkPixlogix Infotech
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfIngrid Airi González
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observabilityitnewsafrica
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationKnoldus Inc.
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsRavi Sanghani
 
Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024TopCSSGallery
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructureitnewsafrica
 
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesMuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesManik S Magar
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Farhan Tariq
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterMydbops
 

Kürzlich hochgeladen (20)

Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
React Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App FrameworkReact Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App Framework
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdf
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog Presentation
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and Insights
 
Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024Top 10 Hubspot Development Companies in 2024
Top 10 Hubspot Development Companies in 2024
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
 
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesMuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
 
Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...Genislab builds better products and faster go-to-market with Lean project man...
Genislab builds better products and faster go-to-market with Lean project man...
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL Router
 

A military perspective on cyber security

  • 1. A Military Perspective on Cyber Security “Not a Paradigm Shift, Tactical Approach” Joey Hernandez CISSP, MBCI jhernandez@iSCSP.org
  • 2. Topic Background The Change Center of Gravity Rings Principles of War Contested Commons Your Turn
  • 3. About Me Former Intelligence and Cyber Operations Analyst with a broad background in all domains of Network Operations. College Professor in the areas of Criminal Justice & Information Security Background in assessments covering NIST, FIPS, & ISO standards Background in International CERT operations & current Director of Operations for the iSCSP
  • 4. Background Elevated age in cyber warfare Malware has become focused SCADA Systems (Stuxnet) Malware performs Operational Preparation of the Environment (OPE) Conficker (Millions still infected) Ransomeware Data is being held hostage The advanced capability of the threat has increased the risk. Understanding the risk allows employment of defensive measures to mitigate the risk – “Risk will always be present”
  • 5. The Change Combined capabilities have helped attackers create weapon systems Soldier +Rifle + Bullets =(This is a weapon systems) Cyber State Sponsored, Script Kiddies, Paid Staff Laptop, Desktop, Mobile devices Metasploit, Backtrak, PoisonIvy, Mpack, other RAT Hacker + Laptop + Metasploit = Weapon System Attackers, Adversaries, Cyber terrorist are now employing TTP
  • 6. Wardens Rings The focus is to attack Centers of Gravity The Estonian attacks Utilized TTP Rings Leadership (Defaced Ministry of Defense, Finance, etc) Organic/System Essentials Infrastructure (DDoS against ISP and Wardialing to lock up POTS network) Population (News Media) Fielded Military Forces Inside Out Attack Methodology For Kinetic Warfare
  • 7. Cyber Population attacks cascade the rings System essential attacks on services eg. Supply Chain, Food, FedEx ; feeds the rings in both direction Infrastructure attacks feed the rings both directions Leadership focus elevates the nature of the actions Inside Out Attack Methodology For Cyber Warfare “Defense measures must ensure protection of systems first and population foremost”
  • 8. Countering Principles of War Raising perceptions of attacks guarantee an elevated perspective. Proactive approaches to providing defense-in- depth reduces risk to all Centers of Gravity NOT immediately achievable, requires buy-in
  • 9. Principle 1 Objective:Direct every operation towards a clearly defined, decisive, and attainable objective. Security Create policy & Directives that are concise, fed from leadership and enhances current capabilities. Defense Institutionalize SOP creating a path to obtainable objectives
  • 10. Principle 2 Offensive:Seize, retain, and exploit the initiative Cyber Security personnel must have all tools required to respond to incidents or events when presented enabling decisive results Immediate knowledge of events through proactive Proactive research International teams of trust Reverse engineering of “current” malicious code Pentesting with seized exploits ensure preparedness Exercise routinely against new threats Exploitation allows establishing opstempo for defensive and counter operations.
  • 11. Principle 3 Economy of Force:Allocate minimum essential combat power to secondary efforts. Cyber Security staff should only be allocated tasks relating to protection of grid and its associated systems Minimize external tasks not associated to Cyber Security “Employ” others to do: password resets, maintenance, and support Discriminate whenever possible! Indentify and prioritize cyber assets and assign coverage accordingly
  • 12. Principle 4 Mass: Concentrate combat power at the decisive place and time. Sustain with technology, resolve with Mass – Use Crisis action teams, leverage distributed knowledge “Get there first with the most”. The dynamic nature of Cyber Space allows you to employ mass globally with centralized control Convene and delegate Ensure communication is continuous If possible (Make possible) Disarm the attacker Block/Mitigate adversaries ability to maneuver, virtual arm bar Remain focused on protection
  • 13. Principle 5 Surprise:Strike the enemy at a time, place, or manner for which they are unprepared. Always expect it! Trust but verify – If the network is quiet lower thresholds, to find hidden traffic Utilize time to influence out of the box operating procedures and TTP to develop Always expect it!
  • 14. Principle 6 Maneuver:Place the enemy in a position of disadvantage through flexible application of combat power Gain an advantage in positioning by training, certifying defense crews Exercising as a team places the adversary in a position of disadvantage Train as a group to flexibly protect, respond, and mitigate attacks Leverage internal and external trusted SME capabilities
  • 15. Principle 7 Unity of Command: For every objective, ensure unity of effort under one responsible commander. A single leader should provide direction and coordination for crews ensuring clear and concise objectives. Alignment facilitates communication for mission/common objective Each task presented should have ownership and custodial characteristics for members of the crew Ideas & Solutions Preferred collective Collective not required
  • 16. Principle 8 Security:Never permit the enemy to acquire an unexpected advantage. Protect and preserve defense measures, procedures and capabilities from the eyes of the adversary. Protect Information, through PEOPLE vetting “Minimize the chance of future Wiki Leaks” Security exertion minimizes attack vectors Understand the capabilities and limiting factors of your people – “provides for a clearer situational awareness”
  • 17. Principle 9 Simplicity:Prepare clear, uncomplicated plans concise orders to ensure thorough understanding. Concise Plans and Orders minimize the chance for mistakes. Degree of operational simplicity results from from experience, training, empowerment and institutionalization of processes. Simplicity in Cyber Operations - is an Art of Balance Open lines of communication Local & Global support simplicity and information sharing
  • 18. Contested Commons It is Global medium: Maritime, Air, Space, Cyber Relied upon for business globalization More nations, organizations, economies at risk Rapid capability development, sluggish legal and global agreement on how to “Address Cyber Attacks” Russia & China created No CY Zones Some believe there is “No Cyber War” Ask Estonia, Brazil, Canada, South Africa, Malaysia
  • 19. Your Turn Train & Exercise your crews as a team Open lines of communication Think strategically, act locally Be proactive, make quick fixes, and best practice into TTP Be paranoid, suspicious and know your adversaries Build your trusted crisis network Plan for events Clear the fog