sustainable · security service (mcss) penetration testing soc incident response apt solution our...

17
SUSTAINABLE CYBER SECURITY COUNTERACTS Ko Sasaki General Manager Global Business Development LAC Co., Ltd.

Upload: others

Post on 02-Aug-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

SUSTAINABLE CYBER SECURITY COUNTERACTS

Ko Sasaki General Manager Global Business Development LAC Co., Ltd.

Page 2: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

Interpol Governments

1995

360 20

1986

Page 3: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved. 3

Consulting

Training /Drill

Cyber R&D

Managed Cyber Security Service

(MCSS)

Penetration Testing

SOC

Incident Response

APT Solution

Our Cyber Security Business

Total Cyber Security Managed Service Provider By Top Cyber Security Experts

2015 Frost & Sullivan Japan's Managed

Security Service Provider of the Year

Award

Page 4: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

Japan Security Operation Center

JSOC

100 cyber engineers

15 yrs

800 million logs

15 mins Alert

Page 5: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

Trend in Cyber Attacks in Japan

5

Page 6: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

External Attacks

Internal Attacks

40%

60%

Page 7: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

Incident Trend in Japan detected at our SOC

Page 8: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved. Copyright ©LAC Co., Ltd. All Rights Reserved.

June 2015

Japan Pension Service

The Tokyo Chamber of

Commerce and industry

Petroleum Association

of Japan

WASEDA University

About 1.25 million personal information

stolen

12,000 personal information stolen

Petroleum Policy documents stolen

3300 staff information stolen

Page 9: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

External Attacks

Internal Attacks Internal but EXTERNAL Attacks

Page 10: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

External Attacks

Internal Attacks Internal but EXTERNAL Attacks

Email

Browsing

Software Updates

Page 11: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

the Mission-critical systems

Information on

infected host

the Mission-critical systems

the Information systems Shared server

② collect information

spread by E-mail ①

How APT (Advanced Persistent Threat) works

Page 12: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved. 12

Malware Protection

System

Sandbox

How to prevent in theory

Pattern/Signature Matching

Legacy attacks

APT

Port Scan/DoS

Known Attacks/ Known Malware

Their Variants

Unknown Attacks/ Malware

APT ( Email / Browsing)

Firewall IPS Anti-Virus

NGFW/UTM

Reputation Detective Devices

Multi-layered Prevention

Page 13: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved. 13

The fact

Page 14: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

No perfect solution

Takes great efforts and time to detect new attacks

NEED EYES

Page 15: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

Cyber Security Capacity Building

15

Detection

Analysis

Response Counteract

Basic Knowledge/Understanding about cyber security management

ISO/IEC 27001 Risk Vulnerability Techniques

Management Layer

Technical Experts

Page 16: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Copyright ©LAC Co., Ltd. 2015 All Rights Reserved.

LAC-Co (ラッコ/Sea Otter / 海獺)

THANK YOU terima kasih

Ko Sasaki [email protected]

Page 17: SUSTAINABLE · Security Service (MCSS) Penetration Testing SOC Incident Response APT Solution Our Cyber Security Business Total Cyber Security Managed Service Provider By Top Cyber

Ko Sasaki [email protected]