michael dinning - national defense transportation …...2017/09/28  · bug bounty 43 adapt…...

55
Cybersecurity attacks, a transporter’s worst nightmare: how to minimize your risks Michael Dinning Advancing transportation innovation for the public good

Upload: others

Post on 19-Aug-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

Cybersecurity attacks, a transporter’s worst

nightmare: how to minimize your risks

Michael Dinning

Advancing transportation innovation for the public good

Page 2: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

Cybersecurity attacks, a transporter’s worst

nightmare: how to minimize your risks

Michael Dinning

Advancing transportation innovation for the public good

Page 3: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

3

Source: MN DOT

Page 4: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

4

Source: houstontranstar.com

Source: houstontranstar.org.png

Page 5: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

5

Source: wagmtv.com

Page 6: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

6

Source: healthcareitnews.com

Page 7: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

7

Page 8: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

8

Source: Wikipedia.org, 9/28/17

Page 9: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

9

Major disruption to:

ComputersAccess to dataInternetEmailMobile phonesCommunications with customersCommunications with contractorsCommunications with customs, etc.Operations

Page 10: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

10

GPS spoofing in Black Sea

Source: Maritime Executive, 7/12/17, Dana Goward

Page 11: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

11

Political attacks - GPS jamming

Source: GNSSnews.com

Page 12: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

12

Trucking & Shipping

Surveying & Mapping

Cargo Tracking

Power Grids

NextGen

Personal Navigation

Maritime Navigation

Military Land Ops

National Transportation System and the expanding ITS

UAVs

Satellite Operations

Aviation

Dependencies on GPS throughout

transportation and other sectors

Page 13: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

13

Financially motivated criminal attacks

Source: bbc.com

Page 14: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

14

Hacktivists

“No Justice No BART” – Physical Attacks “Anonymous” – Cyber Attacks

Sources: nojusticenobart.com, softpedia.com

Page 15: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

15

91,000 square mile “ATC Zero”

CyberPhysicalPersonnel

September 26, 2014

Insider attacks

Sources: time.com, rwf2000.com

Page 16: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

16

Gray Hat (or Opportunistic) Hackers

Source: permaculturenews.com

Page 17: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

17

White Hat (Ethical) Hackers

Page 18: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

18

Every mode is automated and connected

Page 19: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

19

Source: velvetoverdrive.bandcamp.com

Page 20: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

20

Tripadvisor.com

Page 21: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

21

Source: Freakonomics.com

Page 22: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

22

Sources: SFPE.com, electronicsweekly.com

Page 23: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

23

Source: flickr.com

Page 24: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

24

Source: retroplanet.com

Page 25: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

25

Source: Daycaller.com

Source: centralyavapaifire.org

Page 26: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

26

Source: mystateline.com

Page 27: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

27

How do we do this for cyber risks?

Page 28: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

28

Adapted from tieuluu.com

Page 29: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

29

“We need to crawl/walk/run”

Page 30: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

30

Industry-wide problem – lack of basics

“44% of ocean carriers show signs of low levels of cybersecurity related to very basic elements”

A top 20 carrier allows shippers to use “x” as password

10% of carriers and 20% of port terminals haven’t patched to prevent threats from 2½ years ago

Source: Lars Jensen, CEO CyberKeel and SeaIntelligence

Page 31: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

31

Good cyber

hygiene reduces

risk over 80%

“Password123” is not secure!

Page 32: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

32

Source: twoanimators.blogspot.com

Page 33: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

33

Reinforcing good cyber hygiene

Dear Client,We have sent you this e-mail, because we have strong reason to belive, your account has been used by someone else. In order to prevent any fraudulent activity from occurring we are required to open an investigation into this matter. We’ve locked your Amazon account, and you have 36 hours to verify it, or we have the right to terminate it.

To confirm your identity with us click the link below:https://www.amazon.com/exec/obiodos/sigh-in.html

Sincerely, The Amazon Associates Team

Source: Softpedia News, Feb. 17, 2015

Page 34: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

34

Reinforcing good cyber hygiene

Source: Softpedia News, Feb. 17, 2015

Page 35: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

35

Which systems are most mission-critical?

Adapted from Joy Alexander, 2015 TRB Annual Meeting

Page 36: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

36

Cyber Security Evaluation Tool (CSET)

Aviation Pipeline

Maritime HighwaySource: DHS.gov

Page 37: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

37

37

Adapted from Joy Alexander, 2015 TRB Annual Meeting

Page 38: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

3838

Segmentation by risk

Aircraft control Airline Information

Services

Passenger Information and Entertainment

Services

Passenger-Owned Devices

Flight and Embedded

Control Systems

Cabin Core

Admin

Passenger Support

Control the

Airplane

Operate the

Airline

Entertain the

Passengers

Entertain the

Passengers

Closed Private Public

Plus: encryption, authentication, intrusion detection

Page 39: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

39

Design-it-in with specs & contracts

Electronic Stability ControlElectric Power Steering

Lane Departure PreventionAutomatic ParkingAutomatic Steering

Forward Crash Mitigation – Automatic BrakingAdaptive Cruise Control

Electronic Throttle Control

Battery Safety Management

Engine Control

Active Suspension

Antilock BrakingRegenerative Braking

Automatic Start/Stop

Hill-Hold Control

Dedicated Short-Range and Voice/Data

Communications

Recommended practices for cyber security & resilience

Page 40: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

40

Collaborate to address high risks:

Protecting fleets of connected vehicles

Source: Freightliner.com

“Telematics Cybersecurity Primer for Agencies”

Bi-monthly report: https://hvcslistservice.nmfta.org

Page 41: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

41

Page 42: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

42

White Hat (Ethical) Hackers

“Good hacking is a gift”Elon Musk

BUG BOUNTY

Page 43: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

43

Adapt…

securely

Page 44: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

44

Adapting with secure over-the-air updates

Page 45: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

45

Collaborative, pre-planned responses

Page 46: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

46

“We didn’t just open our kimonos,

we wrapped each other up in them”

Page 47: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

47

Defense Transportation ISAC

Mission assuranceSensitive information

Global scope

Page 48: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

48

Cyber exercises & games

http://targetedattacks.trendmicro.com/cyoa/en/#

https://www.pwc.co.uk/issues/cyber-security-data-privacy/game-of-threats.html

Best practice: Create game scenarios tailored to your operations

Page 49: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

49

Can you survive a

“Day Without Cyber”?

Page 50: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

50

Cyber resilience = mission assurance

Government & commercial supply chain partners

Page 51: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

51

How do we know if we’re all secure &

resilient?

Understand mission-critical risks

Agree on “standards” & apply throughout enterprise

Verify with independent audits & testing

Conduct cyber resilience exercises & refine

Develop & maintain sharing and collaboration

Page 52: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

52

thesun.co.uk

Page 53: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

53

Smokey the CyBear

Users

Developers

Public & privatepartners

Contractors

Suppliers

Source: retroplanet.com

Page 54: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

54

Smokey the CyBear

Users

Developers

Public & privatepartners

Contractors

SuppliersSource: sheknows.com

Source: retroplanet.com

Page 55: Michael Dinning - National Defense Transportation …...2017/09/28  · BUG BOUNTY 43 Adapt… securely 44 Adapting with secure over-the-air updates 45 Collaborative, pre-planned responses

55

Michael Dinning

U.S. Department of Transportation

John A. Volpe National Transportation Systems Center

55 Broadway, Cambridge, MA 02142

[email protected]

617-494-2422 (o)

617-694-7518 (m)

The ideas in this briefing are the personal thoughts of the author, not the United States Department of Transportation.The United States Government does not endorse products or manufacturers. Trade or manufacturers’

names appear solely to illustrate the concepts presented in the briefing.

Information about Volpe Center collaboration with DoD: https://www.volpe.dot.gov/sites/volpe.dot.gov/files/docs/news/61416/dot-volpe-and-dod-successful-partnership.pdf