keeping the lights on - of theory and...

16
Keeping the lights on Of theory and practice Presented by Ralph Holz School of Information Technologies

Upload: others

Post on 09-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

Keeping the lights onOf theory and practice

Presented byRalph HolzSchool of Information Technologies

Page 2: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

About the speaker

– Lecturer in Networks and Security, USYD

– Leading Node for Cybersecurity in Human-Centred TechnologiesCluster

– Research streams:– Empirical Security Analysis and Engineering– Blockchain Security

– Teaching:– Security Engineering

Keeping the lights on | Ralph Holz 1

Page 3: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

Theory and practice

Figure: xkcd.com

Keeping the lights on | Ralph Holz 2

Page 4: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

Hard to get numbers

Figure: dilbert.com

Keeping the lights on | Ralph Holz 3

Page 5: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

What are our problems, really?

– Critical infrastructure is vulnerable?

– Internet of Broken Things?

– Advanced Persistent Threat?

– Are we doomed?

– Is any of this new?

Keeping the lights on | Ralph Holz 4

Page 6: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

What are our problems, really?

– Critical infrastructure is vulnerable?

– Internet of Broken Things?

– Advanced Persistent Threat?

– Are we doomed?

– Is any of this new?

Keeping the lights on | Ralph Holz 4

Page 7: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

What are our problems, really?

– Critical infrastructure is vulnerable?

– Internet of Broken Things?

– Advanced Persistent Threat?

– Are we doomed?

– Is any of this new?

Keeping the lights on | Ralph Holz 4

Page 8: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

What are our problems, really?

– Critical infrastructure is vulnerable?

– Internet of Broken Things?

– Advanced Persistent Threat?

– Are we doomed?

– Is any of this new?

Keeping the lights on | Ralph Holz 4

Page 9: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

What are our problems, really?

– Critical infrastructure is vulnerable?

– Internet of Broken Things?

– Advanced Persistent Threat?

– Are we doomed?

– Is any of this new?

Keeping the lights on | Ralph Holz 4

Page 10: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

The new threats?

– None of the security vulnerabilities are new in nature.

– The scale is new, but:

– It really is a case of a changed threat model.– The attackers are organised and better funded.– They have a very different motivation.

– But does this mean we need the latest and greatest?– Not wrong to invest, but make it defence-in-depth

Keeping the lights on | Ralph Holz 5

Page 11: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

The new threats?

– None of the security vulnerabilities are new in nature.

– The scale is new, but:

– It really is a case of a changed threat model.– The attackers are organised and better funded.– They have a very different motivation.

– But does this mean we need the latest and greatest?– Not wrong to invest, but make it defence-in-depth

Keeping the lights on | Ralph Holz 5

Page 12: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

What we really see

Figure: Covering the wrong bases (P. Gutmann, 2014)

Keeping the lights on | Ralph Holz 6

Page 13: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

Where are the vulnerabilities?I would argue that we are getting most of the basics wrong.

– Server-land (from our own studies):– Even if good technology exists, it is not deployed

(complexity)– Complexity is the enemy of security– Delicate trade-offs between availability and security

(revenue!)

– Office-land:– Users are blamed (instead of usability)– Phishing and social engineering penetrate even the fanciest

defences

– Wrong advice is perpetuated in compliance-driven security

– Reaction to successful attack is neglected

Keeping the lights on | Ralph Holz 7

Page 14: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

Measuring security

Any security technology whose effectiveness can’tbe empirically determined is indistinguishable fromblind luck. - Dan Geer

Keeping the lights on | Ralph Holz 8

Page 15: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

Policy

– Vendors should not be allowed to sell Internet-facing productswithout a certification

– What we really need to think about is how to design security testsfor products

– This is the opposite of compliance-based security

– This is a job for policy-makers, not technologists

– Would love to see more evidence-based policy-making– Yes, that is a call for more security measurements

Keeping the lights on | Ralph Holz 9

Page 16: Keeping the lights on - Of theory and practicethewarrencentre.org.au/wp-content/uploads/2017/08/...Keeping the lights on - Of theory and practice Author Ralph Holz Created Date 8/16/2017

Remedies: education in security

– Security needs to be an obligatory part of very curriculum– USYD: part of ‘Integrated IT’ core units

– Some engineering topics:– Assessing security in design and practice– Threat modelling– Privacy– Usability

Keeping the lights on | Ralph Holz 10