anonymous 20*20. director of security intelligence for akamai technologies former research...

52
Anonymous 20*20

Upload: india-risher

Post on 15-Dec-2015

215 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Anonymous 20*20

Page 2: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Director of Security Intelligence for Akamai Technologies

Former Research Director, Enterprise Security [The 451 Group]

Former Principal Security Strategist [IBM ISS]

Industry Experience Faculty: The Institute for Applied

Network Security (IANS) 2012 Vanity Fair Hero Co-Founder of “Rugged Software”

www.ruggedsoftware.org

Things I’ve been researching Compliance vs Security Disruptive Security for Disruptive

Innovations Chaotic Actors Espionage Security Metrics

2

Chief Curmudgeon for attrition.org President/COO of Open Security Foundation (OSF) Director of Non-profit Activity at Risk Based Security

Industry ExperienceFaculty: Honorary Professor @

University of Dayton School of Law 2000-2001, CyberCrime Curriculum

2000 Vanity Fair VillainPresident / COO of Open Security

Foundation (OSF)

Things I’ve been researchingThe Myth of Compliance & Certification Disruptive Rants and Twitter RepliesInfoSec Industry ErrataSquirrelsVulnerability Databases & Metrics

JerichoJoshua Corman

Page 3: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Consequences: Replaceability

3

http://blog.cognitivedissidents.com/2011/10/24/a-replaceability-continuum/

Page 4: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Anon

“Good Guys”

Analysts

Civilians LEO

Page 5: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

=

Page 6: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 7: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 8: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 9: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 10: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Endgame Ethics

Page 11: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Chaotic Actor

Page 12: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

12

Page 13: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Lots & Lots of Anonymous Sects

13

Page 14: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

“Anonymous is God’s gift to the Chinese” – Government Agency CISO

False Flag: Criminal & State Actors

Page 15: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Cyber-Neo-McCarthyism

Page 16: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 17: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Mastercard / Visa – Denying payments to Wikileaks

PayPal – Suspended Wikileaks account

Sony – Lawsuit against PlayStation 3 hacker George Hotz

HBGary – Threat of outing Anonymous leaders

Retaliation

Page 18: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Operation Payback

Page 19: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Beyond Operation Payback

Page 20: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Data on Anonymous

Page 21: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Name: Anonymous

Hacktivism

Denial of Service

Defacements

Use of Iconography

Decentralized Group

What is really new?

Page 22: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

A Mirror to Our Neglect…

Page 23: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 24: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Modern Pantheon of Adversary Classes

TargetsCredit Card

#s

Web Presence

Connectivity

Intellectual Property

PII / Identity

Cyber Infrastruct

ure

Core Business Processes

Impacts

Reputational Personal Confidentiality Integrity Availability

Motivations

Financial Industrial Military Ideological Political Prestige

Actors

StatesCompetit

orsOrganized Crime

Script Kiddies Terrorists Hacktivis

ts Insiders Auditors

Page 25: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 26: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 27: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Anonymous & the Law

Page 28: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Anonymous Activity

Page 29: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Law Enforcement Activity

Page 30: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

The Face of Anonymous*

Page 31: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

The Unknowns of Anonymous

~270

Page 32: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 33: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Crossroads

Page 34: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 35: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 36: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Chaotic Good

Legislation

Watchdog

Chaotic Good

Free Speech

Chaotic Good

Moral Outrage

Anonymous Identity/Meme“General Population”

MalSec?

ChaoticGood? or

Evil?

Leave

LulzSec

ChaoticEvil

Page 37: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

“If you believe something…”

Page 38: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 39: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Finger on the Pulse

Page 40: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Vigilantism?

Page 41: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Predictions about Anonymous are [interesting|amusing|ridiculous]

“Will this mean the end of Anonymous? No. It will mean the end of LulzSec, but Anonymous existed before LulzSec and will continue existing. However we probably won't see any more hacks as the ones LulzSec had been perpetrating, and Anonymous will only use their known childish tactic of DDoS using their LOIC tool.” -- Luis Corrons, Panda Security.

Page 42: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Anonymous as an Industry

Page 43: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 44: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Control and Chaos”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

Page 45: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Does not one cause the other?”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

“It’s a Trap” on shirt.woot.com

Page 46: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

1914

Page 47: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

With Great Power?

"When you don't have centralized leadership, it doesn't matter what most will do, it matters what one

of them will do," Corman said.

Page 48: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Back to Anonymous 2020

Page 49: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

The Future of Anonymous

Page 50: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal
Page 51: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal

Thank You & Contact Mar @ sudux.com @krypt3ia “anonymous” contributors “unspecified” contributors

@attritionorg @JoshCorman

http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/

Page 52: Anonymous 20*20. Director of Security Intelligence for Akamai Technologies  Former Research Director, Enterprise Security [The 451 Group]  Former Principal