martin lee - first - improving security together€¦ · © 2014 cisco and/or its affiliates. all...

41
Cisco 1 © 2014 Cisco and/or its affiliates. All rights reserved. Martin Lee Technical Lead, Cisco 02/4/2014

Upload: others

Post on 01-Oct-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 1 © 2014 Cisco and/or its affiliates. All rights reserved.

Martin Lee Technical Lead, Cisco

02/4/2014

Page 2: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 2 © 2014 Cisco and/or its affiliates. All rights reserved.

Page 3: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 3 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://en.wikipedia.org/wiki/Moore%27s_law

Page 4: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 4 © 2014 Cisco and/or its affiliates. All rights reserved.

Osborne Executive

1982 – $2495

iPhone

2007 - $499

Source: http://web.mit.edu/newsoffice/2013/how-to-predict-the-progress-of-technology-0306.html

Page 5: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 5 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://www.singularity.com/charts/page62.html

P III - $496 1999

P III - $12 2014

Page 6: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 6 © 2014 Cisco and/or its affiliates. All rights reserved.

Source:Byte magazine, July 1980, Amazon 2014

Page 7: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 7 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: M.Komorowski http://www.mkomo.com/cost-per-gigabyte

Page 8: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 8 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: Ovum

Cost: US$/Gb/sec/Km

1994 ~$2000

2014 < $1

Page 9: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 9 © 2014 Cisco and/or its affiliates. All rights reserved.

SENSOR

ACTUATOR

CONTROL SYSTEM

DATA

Control unit

Wireless communication

Operations Centre

Readings

Instructions

Page 10: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 10 © 2014 Cisco and/or its affiliates. All rights reserved.

Page 11: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 11 © 2014 Cisco and/or its affiliates. All rights reserved.

CONTROL SYSTEM

DATA

Operations Centre

Accident

Dispatch Help

Accelerometer

Page 12: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 12 © 2014 Cisco and/or its affiliates. All rights reserved.

CONTROL SYSTEM

DATA

Air temperature

Air humidity

Leaf wetness

Soil moisture

Soil temperature

Solar radiation

Operations Centre

Spray

Harvest

Irrigate

http://newsroom.cisco.com/video-content?type=webcontent&articleId=1275685

Vines

Sensors

(30 000)

Page 13: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 13 © 2014 Cisco and/or its affiliates. All rights reserved.

CONTROL SYSTEM

DATA

Pulse

Breathing rate

Oxygen saturation

Movement

Operations Centre

http://www.oxehealth.com Philips VitalSigns camera

Patient Phone Camera Intervene

Page 14: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 14 © 2014 Cisco and/or its affiliates. All rights reserved.

CONTROL SYSTEM

DATA

Usage

Operations Centre

Source: http://www.energymanagertoday.com/atms-vending-machines-waste-loads-of-energy-097280

ATMs (58 000)

Usage: 8.4 min/hr

50% can power down

$19 M/yr saving

Page 15: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 15 © 2014 Cisco and/or its affiliates. All rights reserved.

Page 16: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 16 © 2014 Cisco and/or its affiliates. All rights reserved.

Tom Noonan, Cisco

Source: http://gigaom.com/2013/12/01/the-big-energy-problem-that-happens-while-youre-sleeping/

Page 17: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 17 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://www.bbc.co.uk/news/business-15352599

Page 18: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 18 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: https://www.gov.uk/government/policies/reducing-the-uk-s-greenhouse-gas-emissions-by-80-by-2050/supporting-pages/carbon-budgets

Page 19: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 19 © 2014 Cisco and/or its affiliates. All rights reserved.

CONTROL SYSTEM

DATA

Time / Date

Ingress / Egress

External temperature

Room temperature

Weather forecast

Water usage

Power usage / device

Lift utilisation

Signs of wear in lift

Operations Centre

Smart Building

Page 20: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 20 © 2014 Cisco and/or its affiliates. All rights reserved.

CONTROL SYSTEM

DATA

Heat where needed

Light where needed

Power down devices

Power down coffee machine

Switch off water pump

One operational lift

Call for service

Operations Centre

Smart Building

Page 21: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 21 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: Hugh Boyes, IET

Integration with wider environment.

Smart grid

Public transport

Page 22: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 22 © 2014 Cisco and/or its affiliates. All rights reserved.

Page 23: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 23 © 2014 Cisco and/or its affiliates. All rights reserved.

SENSOR

ACTUATOR

CONTROL SYSTEM

DATA

Operations Centre

Activate cooling

High temperature

Page 24: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 24 © 2014 Cisco and/or its affiliates. All rights reserved.

SENSOR

ACTUATOR

CONTROL SYSTEM

DATA

Operations Centre

X

X Block Readings

Page 25: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 25 © 2014 Cisco and/or its affiliates. All rights reserved.

SENSOR

ACTUATOR

CONTROL SYSTEM

DATA

Operations Centre

X

X Intercept Readings

Fake Reading

Fake Instruction

Page 26: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 26 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://www.jpost.com/Enviro-Tech/Technion-students-find-way-to-hack-Waze-create-fake-traffic-jams-346377

Page 27: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 27 © 2014 Cisco and/or its affiliates. All rights reserved.

SENSOR

ACTUATOR

Fake Reading FAKE SENSOR

FAKE ACTUATOR

Fake Operations Centre

Fake Instruction

Page 28: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 28 © 2014 Cisco and/or its affiliates. All rights reserved.

SENSOR

ACTUATOR

CONTROL SYSTEM

DATA

Operations Centre

Hack

Hack

Hack

Page 29: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 29 © 2014 Cisco and/or its affiliates. All rights reserved.

Source:http://www.cctvblog.com/2014/04/03/hikvision-bad-end-bitcoin-hijacking-using-security-dvrs/

Page 30: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 30 © 2014 Cisco and/or its affiliates. All rights reserved.

SENSOR

ACTUATOR

CONTROL SYSTEM

DATA

Authenticate Access Harden & Monitor

Operations Centre

Authenticate Devices

Authenticate Origin

Encrypt Data

Multiple Routes

Patch

Page 31: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 31 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://news.cnet.com/8301-1009_3-57599646-83/cybercrooks-use-ddos-attacks-to-mask-theft-of-banks-millions/

Page 32: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 32 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://www.bbc.co.uk/news/technology-21784005

http://en.community.dell.com/cfs-file.ashx/__key/telligent-evolution-components-attachments/13-4491-00-00-20-10-90-89/Facility-Cooling-Failure-Ride-Through-whitepaper.pdf

Page 33: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 33 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: https://blogs.cisco.com/security/the-internet-of-everything-including-malware/

Page 34: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 34 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://www.wired.com/threatlevel/2013/05/googles-control-system-hacked/

Page 35: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 35 © 2014 Cisco and/or its affiliates. All rights reserved.

Source: http://www.wired.com/threatlevel/2013/08/computer-prison-door-mishap/

Page 36: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 36 © 2014 Cisco and/or its affiliates. All rights reserved.

UK Cyber Standards Report

Source: https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/261681/bis-13-1294-uk-cyber-security-standards-research-report.pdf#!

InfoSec Standards Safety Standards

ISO 2700x IEC 62443

IEC 61508

PAS 555

Page 37: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 37 © 2014 Cisco and/or its affiliates. All rights reserved.

Page 38: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 38 © 2014 Cisco and/or its affiliates. All rights reserved.

Low cost sensors + ubiquitous bandwidth + cheap data processing means -

The Internet of Things is Happening.

Lowering energy costs & reducing wastage means -

Smart Buildings Are Profitable Buildings.

If we have learnt anything over the past 15 years –

Poorly Secured Systems Will Be Compromised.

Page 39: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 39 © 2014 Cisco and/or its affiliates. All rights reserved.

Do you have devices / people in smart buildings?

Model Your Risk.

Does your building management know the risk?

Ask Questions, Specify Requirements.

If we have learnt anything over the past 15 years –

Test, Test & Test Again!

Page 40: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Cisco 40 © 2014 Cisco and/or its affiliates. All rights reserved.

Learn more:

http://www.theiet.org/sectors/information-communications/intelligent-buildings.cfm

http://internetofeverything.cisco.com/

Page 41: Martin Lee - FIRST - Improving Security Together€¦ · © 2014 Cisco and/or its affiliates. All rights reserved. Cisco 1 Martin Lee Technical Lead, Cisco 02/4/2014

Thank you.

Martin Lee

[email protected]