[lithuania] i am the cavalry

36
I AM THE CAVALRY http://iamthecavalry.org @iamthecavalry SHOULDN’T YOU BE ALSO?

Upload: owasp-eee

Post on 16-Jan-2017

282 views

Category:

Internet


0 download

TRANSCRIPT

Page 1: [Lithuania] I am the cavalry

I AM THE CAVALRYhttp://iamthecavalry.org

@iamthecavalry

SHOULDN’T YOU BE ALSO?

Page 2: [Lithuania] I am the cavalry

CLAUS CRAMON HOUMANN

Infosec Community Manager @ Peerlyst

(A start-up Infosec community/Social platform that wants to turn the

tables on cyber security)

Infosec Consultant

The Analogies contributor

Twitter: @claushoumann

Page 3: [Lithuania] I am the cavalry

IDEA

“Our dependence on technology

is growing faster than our ability

to secure it”

Page 4: [Lithuania] I am the cavalry

IDEA

“Our society has evolved

faster than our laws”

Page 5: [Lithuania] I am the cavalry

IDEA

But why wait.......

Page 6: [Lithuania] I am the cavalry

ALL SYSTEMS FAIL*

* Yes; all

Page 7: [Lithuania] I am the cavalry

WHERE DO WE SEE CONNECTIVITY NOW?

In Our Bodies In Our Homes

In Our InfrastructureIn Our Cars

Page 8: [Lithuania] I am the cavalry

HEARTBLEED + (UNPATCHABLE ) INTERNET OF

THINGS == ___ ?In Our Bodies In Our Homes

In Our InfrastructureIn Our Cars

Page 9: [Lithuania] I am the cavalry

SAY BABY MONITORS AGAIN?

In Our Homes

Source: Rapid7 research/Mark Stanislav: Baby monitors

https://www.rapid7.com/docs/Hacking-IoT-A-Case-Study-on-Baby-Monitor-

Exposures-and-Vulnerabilities.pdf

Page 10: [Lithuania] I am the cavalry

THEN

Page 11: [Lithuania] I am the cavalry

BUT ALSO

Page 12: [Lithuania] I am the cavalry

IT’S SAFETY

NOT JUST SECURITY

Ouch!

Page 13: [Lithuania] I am the cavalry

Cars have computers

Computers have security issues

Security issues in cars are safety issues

Safety issues can cost or imperil lives

Page 14: [Lithuania] I am the cavalry

www.iamthecavalry.org@iamthecavalry

Past versus Future

Bolt-On Vs Built-In

Page 15: [Lithuania] I am the cavalry

SOMEONE WILL FIX IT

FOR US

Chapter 2

Page 16: [Lithuania] I am the cavalry
Page 17: [Lithuania] I am the cavalry

OR NOT……..

Chapter 3

Page 18: [Lithuania] I am the cavalry

Let’s create ripples

Page 19: [Lithuania] I am the cavalry

A DO-OCRACY OF

DO’ERS.W H E R E D O I N G S TA RT S W I T H

EMPATHY

And by ripples I mean

Page 20: [Lithuania] I am the cavalry
Page 21: [Lithuania] I am the cavalry
Page 22: [Lithuania] I am the cavalry
Page 23: [Lithuania] I am the cavalry

The Point?

Page 24: [Lithuania] I am the cavalry

NEVER DOUBT THAT A SMALL GROUP

OF THOUGHTFUL, COMMITTED

CITIZENS CAN CHANGE THE WORLD;

IT ’S THE ONLY THING

THAT EVER HAS.

- M A R G A R E T M E A D( A N A M E R I C A N C U LT U R A L A N T H R O P O L O G I S T )

Page 25: [Lithuania] I am the cavalry

•The

The Cavalry isn’t coming… It falls to usProblem Statement

Our society is adopting connected technology faster than we are able to secure it.

Mission StatementTo ensure connected technologies with the potential to impact public safety and human life are worthy of our trust.

Collecting existing research, researchers, and resourcesConnecting researchers with each other, industry, media, policy, and legal

Collaborating across a broad range of backgrounds, interests, and skillsetsCatalyzing positive action sooner than it would have happened on its own

Why Trust, public safety, human lifeHow Education, outreach, researchWho Infosec research community Who Global, grass roots initiative

WhatLong-term vision for cyber safety Medical Automotive

ConnectedHome

PublicInfrastructure

I Am The Cavalry

Page 26: [Lithuania] I am the cavalry

Connections and Ongoing Collaborations

5-Star Framework

5-Star Capabilities Safety by Design – Anticipate failure and plan mitigation

Third-Party Collaboration – Engage willing allies

Evidence Capture – Observe and learn from failure

Security Updates – Respond quickly to issues discovered

Segmentation & Isolation – Prevent cascading failure

Addressing Automotive Cyber Systems

Automotive

Engineers

Security

Researchers

Policy

Makers

Insurance

Analysts

Accident

Investigators

Standards

Organizations

https://www.iamthecavalry.org/auto/5star/

Page 27: [Lithuania] I am the cavalry

www.iamthecavalry.org@iamthecavalry

5-Star Cyber SafetyFormal Capacities

1. Safety By Design2. Third Party Collaboration3. Evidence Capture4. Security Updates5. Segmentation and Isolation

Plain Speak1. Avoid Failure2. Engage Allies To Avoid

Failure3. Learn From Failure4. Respond to Failure5. Isolate Failure

Page 28: [Lithuania] I am the cavalry

5 STARS

5 star ICS

5 star IoT

5 star medical devices

Page 29: [Lithuania] I am the cavalry

www.iamthecavalry.org@iamthecavalry

And!• Dräger on board with I am the Cavalry as first

medical device producer working directly in sync with us

• Their Product Security Manager is even directly involved now

Page 30: [Lithuania] I am the cavalry

AND MORE IN OTHER AREAS

COMING

We try to connect researchers to

1. Lawmakers to inform of meaningful changes to laws to enforce

secure by default

2. Vendors/producers to inform of secure ways to build securely by

design and of identified vulnerabilities

3. Purchasers of devices (example: Pacemakers, car distributors) to

explain to them why they need to contractually demand security – if

there is demand vendors will supply

Page 31: [Lithuania] I am the cavalry

AND YES I DID SAY LAWMAKERS

It is WEIRD for you to have to listen to. I

agree, but

Page 32: [Lithuania] I am the cavalry

WHAT YOU CAN DO

Chapter 5

Page 33: [Lithuania] I am the cavalry

CONNECTIONS/CONNECTORS

WANTED

Breakers and Builders

Legal and Policy

Citizens, Connectors

Parents/Guardians

Community Leaders/Bloggers/Podcasters/etc.

Page 34: [Lithuania] I am the cavalry

MOUNT UP AND BE THE

CAVALRY

YOU DON’T ACTUALY

NEED A HORSE

Page 35: [Lithuania] I am the cavalry

SAFER.

SOONER.

TOGETHER

http://iamthecavalry.org

@iamthecavalry

Page 36: [Lithuania] I am the cavalry

-> OWASK SKF

-> OWASP SECURITY SHEPHERD

-> OWASP ZAP

Recommendations:

Use SDLC