using gamification for cyber exercises and security competence building · 2018-10-05 · itu...

30
ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber Exercises and Security Competence Building Almerindo Graziano CEO, Silensec [email protected]

Upload: others

Post on 25-May-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Using Gamification for Cyber Exercises and Security Competence Building

Almerindo GrazianoCEO, [email protected]

Page 2: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

• Information Security Management Consultancy Company (ISO27001 Certified) – Security compliance, Security Audits– Security System Integration (SIEM,

DAMs, WAFs, etc.)– Managed Security Services

• Independent Security training provider

About Silensec

Page 3: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

• CEO of Silensec

• PhD in mobile computer security from the University of Naples, Italy.

• Founder and course Leader for the MSc in Information Systems Security at Sheffield Hallam University

• Author of numerous security training courses

• Cyber security expert for International Telecommunication Union (ITU)

• Airmiles collector

Almerindo Graziano

About Me

Page 4: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Free Security Awareness Resources

Silensec on Social Media

Page 5: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

At least 3.5 million cyber security jobs will be left vacant by 2021

1 in 5 organization receives fewer than 5 candidates for each advertised security position and 37% of the organisations lament that fewer than 1 in 4 of the candidates they do receive are actually qualified for the job!

The Size of The Problem

The Security Skills Gap

Page 6: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

The security job market has big gaps with regards to security certifications

The cost of training and certificaition is one of the underlying causes of the cybersecurity skills gap

Lack of Certified Professionals

The Security Skills Gap

Page 7: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

High-value skills in critically short supply - Intrusion detection - Secure software development - Attack mitigation

Page 8: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Other desired skills include malware analysis skills, familiarity with commercial tools and feeds, knowledge of adversaries campaigns and the ability to write correlation rules to link security events.

The Gap Between Offer And Demand

The Security Skills Gap

Page 9: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

• Companies prefer to invest in systems rather than competences

• ROI on security spending alone is difficult to justify• Companies fear staff may leave once trained• Training costs money, period!

after salary, opportunities for training are the second highest motivating factor in recruitment and staff retention followed by the reputation of the employer’s IT department and potential for advancement.

Companies Do Not Invest Enough In Staff Training

The Challenges

Page 10: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

The Commoditization of Security Training

The Market Solution

Page 11: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Welcome to Cybrary, Where Every Training is Free!

The Market Solution

Page 12: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

After All..Welcome To Google University – Free Admission Daily

Page 13: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

The True Cost of Commoditization

What is Really Happening?

Paper Certifications and Certificates of Completion!

Try FailEmphasis is put on the achievement and not in the acquisition of competences

Finding the right security professional gets harder

Which certification? Which training? Where can I practice?...

Page 14: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Gamification Principles

Security Gamification

• Gameplay

• Re-playability

• Co-operation/competition between players

• Allegion

• Graphics power

• Artistic and sound aspects

• Plot

Page 15: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Sample Activities

ITU Cyberdrills Experience

• Development of Cyberdrill workshops and training for Computer Emergency Response Teams

• Events run by the International Communication Union (ITU) worldwide

Past Cyberdrills• Zambia• Egypt• Montenegro• Mauritius• Tunisia• Ecuador• Oman• Qatar• Suriname• Tanzania• Moldova• Argentina

Page 16: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Example

Cyber Exercise

• Log Analysis and Incident Response• Computer/Mobile forensics• Cyber Threat Intelligence• Ethical Hacking• Table-top exercises

Page 17: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Definition

Cyber Ranges

An interactive, simulated representations of an organization’s local network, system, tools, and applications that are connected to a simulated Internet level environment. National Initiative for Cyber security education (NIST)

Page 18: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Page 19: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Specifications

Silensec Cyber Range

• Portable cyber range– 192GB Ram– 24 CPU cores– 6TB storage)

• Online cyber range– Scalabale to thousands of

simultaneous users

www.cyberranges.com

Page 20: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Silensec Cyber Range

Page 21: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Online Persona

Page 22: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Join a Team

Page 23: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Cooperation

Page 24: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Game Mode

Page 25: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Creating the Game/Scenario

Page 26: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Starting The Game

Page 27: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Scoring

Page 28: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

National Cybersecurity Competitions – www.cyberstars.pro

Cyber Range Use Today

Page 29: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

ITU Cyberdrill, 4-5 Oct 2018Grand-Bassam, Côte d’Ivoire

Arab Regional CyberstarsThreat Hunter Edition

Page 30: Using Gamification for Cyber Exercises and Security Competence Building · 2018-10-05 · ITU Cyberdrill, 4-5 Oct 2018 Grand-Bassam, Côte d’Ivoire Using Gamification for Cyber

Thank you