back to the roots – incident case study

21
Back to the roots – incident case study Mikko Karikytö Head of Ericsson PSIRT

Upload: nerys

Post on 22-Feb-2016

55 views

Category:

Documents


0 download

DESCRIPTION

Back to the roots – incident case study. Mikko Karikytö Head of Ericsson PSIRT. outline. Ericsson PSIRT – intro Setting the scene The Case The contact Investigation Aftermath Conclusions. Ericsson. 40%. 180. 2.5b. “Constituency”. Ericsson PSIRT. Established 2004 TI 2005 - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Back to the roots – incident case study

Back to the roots – incident case studyMikko KarikytöHead of Ericsson PSIRT

Page 2: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 2

› Ericsson PSIRT – intro› Setting the scene› The Case

– The contact– Investigation– Aftermath

› Conclusions

outline

Page 3: Back to the roots – incident case study

“Constituency”

40%2.5b180

Ericsson

Page 4: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 4

› Established 2004› TI 2005› FIRST 2006› Vulnerability Management› Incident Response› Corporate group› Finland› Co-op

Ericsson PSIRT

Page 5: Back to the roots – incident case study

Setting the scene

Page 6: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 6

The scene

E///

Managed Service Provider

Mobile Operator

“the customer”

PSIRT

Page 7: Back to the roots – incident case study

The case

Page 8: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 8

“Hi Mikko,

Would you have a BSS specialist with deeper knowledge on the nodes? We could use one in a case with our customer…”

Page 9: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 9

Finding the common frequency

Page 10: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 10

Building a team and flying in

Page 11: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 11

› Good overview› Too many issues included

in one report

›XXX› SIMbox

Initial investigation report

Page 12: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 12

simbox

Page 13: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 13

Simbox scenario

Internet

Operator A Operator BSubscriber A Subscriber B

Page 14: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 14

› Obvious from beginning› Operator blaming the MS

Provider› MS Provider blaming the

operator

› Internal blame game in the Managed Service Provider

Blame game

Page 15: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 15

› High pressure put on certain people

› Afraid for their jobs› Defensive mode› How to get truthful

answers?

people

Page 16: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 16

Page 17: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 17

Big pile of cra… findings

No policy

No processes

No

responsibleNo assets

Shared accounts

No log

monitoring

No physical security

Unclear SLA

No screening of employees

Page 18: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 18

› No technical vulnerability in the system itself

› Aircraft carrier size holes in operational security

– Impossible to name culprits– Shared root accounts etc…

› Nice process! When is it created?

Summary of findings

Page 19: Back to the roots – incident case study

Back to the roots - Incident case study | Commercial in confidence | © Ericsson AB 2014 | 2014-06-19 | Page 19

› It’s humans who run this show

› Communication flows or doesn’t

› Blame game takes time and energy

It’s a long way

Page 20: Back to the roots – incident case study

Mikko KarikytöHead of Ericsson PSIRT

mikko.tel

Thank you

Page 21: Back to the roots – incident case study