synthetic teammates and the future of cybersecurity · 1 synthetic teammates and the future of...

40
1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology, Inc. [email protected] 8 August 2017

Upload: others

Post on 01-Aug-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

1

Synthetic Teammates andthe Future of Cybersecurity

Dr. Fernando Maymí Lead Scientist, Cyberspace Operations

Soar Technology, [email protected]

8 August 2017

Page 2: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

2

- THE FUTURE THREAT LANDSCAPE- SYNTHETIC TEAMMATES- WORKFORCE DEVELOPMENT

Page 3: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

3

- THE FUTURE THREAT LANDSCAPE- SYNTHETIC TEAMMATES- WORKFORCE DEVELOPMENT

Page 4: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

4

The Tactical Battlefield of 2050

• Augmented humans

• Automated decision making and autonomous processes

• Misinformation as a weapon

• Micro-targeting

• Large-scale self-organization and collective decision making

• Cognitive modeling of the opponent

• Ability to understand and cope in a contested, imperfect, information environment

Page 5: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

5

Threatcasting

http://threatcasting.com

Page 6: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

6

Page 7: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

7

Page 8: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

8

Page 9: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

9

Page 10: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

10

Page 11: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

11

Page 12: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

12

Concerns

• War on reality: the weaponization of data

• Blended attacks

• Micro-targeting

• Efficiency is easy to hack

• Complex autonomous systems

Understanding the context is essential

Page 13: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

13

- THE FUTURE THREAT LANDSCAPE- SYNTHETIC TEAMMATES- WORKFORCE DEVELOPMENT

Page 14: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

14

Partial Artificial Intelligence Taxonomy

Machine Learning Cognitive Modeling

Page 15: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

15

(Oversimplifying) Artificial Intelligence

Source, Fair use, https://en.wikipedia.org/w/index.php?curid=36632393,

https://readingraphics.com/book-summary-thinking-fast-and-slow/

Analogous to

Machine Learning

Analogous to

Cognitive Modeling

Page 16: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

16

Autonomous Agents

Sense

Act

Think

Learn

Page 17: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

17

MACHINE LEARNING

System 1

17

Page 18: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

18

Machine Learning

Extract

Features

Filter

Noise

Sense

Data

Classify

Sample

External agent validates

results during training phase

Production (trained) system

outputs results to other systems

Page 19: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

19

Adversarial Machine Learning

Original image

classified as a panda

with 60% confidence

Imperceptibly modified

image classified as a

gibbon with 99%

confidence

Tiny adversarial

perturbation

This is a gibbon

Source, Fair use, http://www.kdnuggets.com/2015/07/deep-learning-adversarial-examples-misconceptions.html,

https://www.ippl.org/gibbon/wp-content/uploads/2010/09/peppyaction-269x300.jpg

Page 20: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

20

Adversarial Machine Learning

Original image

classified as malware

with 60% confidence

Imperceptibly modified

file classified as

whitelisted software

with 99% confidence

Tiny adversarial

perturbation

Source, Fair use, http://www.kdnuggets.com/2015/07/deep-learning-adversarial-examples-misconceptions.html,

https://stixproject.github.io/documentation/idioms/maec-malware/

Page 21: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

21

Towards a Solution

Page 22: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

22

COGNITIVE MODELING

System 2

22

Page 23: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

23

Towards a Common Model of TTPs

Procedures: the algorithmic, atomic unit of cyberspace operations

Techniques: unique ways to perform procedures

Tactics: directed subgraphs of procedures with one or more goals

as their terminal nodes

Page 24: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

24

Towards a Common Model of TTPs

Procedures: the algorithmic, atomic unit of cyberspace operations

Techniques: unique ways to perform procedures

Tactics: directed subgraphs of procedures with one or more goals

as their terminal nodes

Page 25: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

25

Towards Common Models of Threat Actors

Partial model of APT28 (Fancy Bear) during Operation Pawn Storm

Page 26: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

26

Simulated Cognitive Cyber Red-team Attack Model

Command & Control

Situation Reports

Human

Controller

Cyber Actions

Network Under Test

SC2RAM

Page 27: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

27

SC2RAM Graphical User Interface

Page 28: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

28

Network Attack Visualization

Developed by IHMC for SC2RAM

Page 29: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

29

Using Synthetic Attackers for Cybersecurity

Page 30: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

30

Autonomous Hunt Teammate

Hypothesis

Generator

Learning Module

Hypothesis

Evaluation

Threat Intel Feeds Other Feeds Internal Models

DHS

ISAC

Commercial

Dark

Web

Social

MediaAssets TTPs

Attacks

Logs

IDS

Firewalls

Internal Sensors

Page 31: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

31

- THE FUTURE THREAT LANDSCAPE- SYNTHETIC TEAMMATES- WORKFORCE DEVELOPMENT

Page 32: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

32

Workforce Pipeline

Access Employ Develop Retain

Page 33: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

33

What Are We Looking For?

Source, fair use: http://host.madison.com/ct

Access Employ Develop Retain

Page 34: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

34

Why?

Source, fair use: http://dailymail.co.uk

Access Employ Develop Retain

Page 35: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

35

Key Hiring Trends in Cybersecurity

• Companies are seeking certified candidates- 35% of positions required a certification

• Companies are seeking educated candidates

- 80% of positions require a Bachelor’s degree

• Hands-on skills are more valuable than managerial ones- Lead Software Developer average salary: $ 233,333

- Chief Security Officer average salary: $ 225,000

• Openings are harder to fill- Cybersecurity openings remain open 8% longer than IT ones

- Security clearances or financial sector experience is even harder to fill

• Next-generation gap- Younger generation is not as interested in cybersecurity, particularly women

Access Employ Develop Retain

Page 36: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

36

Developing the Cybersecurity Workforce

Access Employ Develop Retain

Source, fair use: http://www.naturethruphotos.com

Page 37: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

37

Developing the Cybersecurity Workforce

Access Employ Develop Retain

Source, fair use: https://certification.comptia.org

Page 38: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

38

Retention

Access Employ Develop Retain

Page 39: Synthetic Teammates and the Future of Cybersecurity · 1 Synthetic Teammates and the Future of Cybersecurity Dr. Fernando Maymí Lead Scientist, Cyberspace Operations Soar Technology,

39

Most Importantly…

Source: https://www.123rf.com/profile_garagestock

Access Employ Develop Retain