SlideShare a Scribd company logo
A Military Perspective on Cyber Security  “Not a Paradigm Shift, Tactical Approach”  Joey Hernandez CISSP, MBCI jhernandez@iSCSP.org
Topic Background The Change Center of Gravity Rings Principles of War Contested Commons Your Turn
About Me Former Intelligence and Cyber Operations Analyst with a broad background in all domains of Network Operations.  College Professor in the areas of Criminal Justice & Information Security Background in assessments covering NIST, FIPS, & ISO standards Background in International CERT operations & current Director of Operations for the iSCSP
Background Elevated age in cyber warfare Malware has become focused  SCADA Systems (Stuxnet) Malware performs Operational Preparation of the Environment (OPE) Conficker (Millions still infected) Ransomeware Data is being held hostage The advanced capability of the threat has increased the risk.  Understanding the risk allows employment of defensive measures to mitigate the risk – “Risk will always be present”
The Change Combined capabilities have helped attackers create weapon systems Soldier +Rifle + Bullets =(This is a weapon systems) Cyber State Sponsored, Script Kiddies, Paid Staff Laptop, Desktop, Mobile devices Metasploit, Backtrak, PoisonIvy, Mpack, other RAT Hacker + Laptop + Metasploit = Weapon System Attackers, Adversaries, Cyber terrorist are now employing TTP
Wardens Rings The focus is to attack Centers of Gravity  The Estonian attacks Utilized TTP Rings   Leadership (Defaced Ministry of Defense, Finance, etc) Organic/System Essentials Infrastructure (DDoS against ISP and Wardialing to lock up POTS network) Population (News Media) Fielded Military Forces Inside Out Attack Methodology For Kinetic Warfare
Cyber  Population attacks cascade the rings System essential attacks on services eg. Supply Chain, Food, FedEx ; feeds the rings in both direction Infrastructure attacks feed the rings both directions Leadership focus elevates the nature of the actions Inside Out Attack Methodology For Cyber Warfare “Defense measures must ensure protection of systems first and population foremost”
Countering Principles of War Raising perceptions of attacks guarantee an elevated perspective. Proactive approaches to providing defense-in- depth reduces risk to all Centers of Gravity NOT immediately achievable, requires buy-in
Principle 1 Objective:Direct every operation towards a clearly defined, decisive, and attainable objective. Security Create policy & Directives that are concise, fed from leadership and enhances current capabilities. Defense Institutionalize SOP creating a path to obtainable objectives
Principle 2 Offensive:Seize, retain, and exploit the initiative Cyber Security personnel must have all tools required to respond to incidents or events when presented enabling decisive results Immediate knowledge of events through proactive Proactive research International teams of trust Reverse engineering of “current” malicious code Pentesting with seized exploits ensure preparedness Exercise routinely against new threats Exploitation allows establishing opstempo for defensive and counter operations.
Principle 3 Economy of Force:Allocate minimum essential combat power to secondary efforts. Cyber Security staff should only be allocated tasks relating to protection of grid and its associated systems Minimize external tasks not associated to Cyber Security “Employ” others to do: password resets, maintenance, and support Discriminate whenever possible! Indentify and prioritize cyber assets and assign coverage accordingly
Principle 4 Mass:	Concentrate combat power at the decisive place and time. Sustain with technology, resolve with Mass – Use Crisis action teams, leverage distributed knowledge “Get there first with the most”. The dynamic nature of Cyber Space allows you to employ mass globally with centralized control Convene and delegate Ensure communication is continuous If possible (Make possible) Disarm the attacker Block/Mitigate adversaries ability to maneuver, virtual arm bar Remain focused on protection
Principle 5 Surprise:Strike the enemy at a time, place, or manner for which they are unprepared. Always expect it! Trust but verify – If the network is quiet lower thresholds, to find hidden traffic Utilize time to influence out of the box operating procedures and TTP to develop  Always expect it!
Principle 6 Maneuver:Place the enemy in a position of disadvantage through flexible application of combat power Gain an advantage in positioning by training, certifying defense crews Exercising as a team places the adversary in a position of disadvantage Train as a group to flexibly protect, respond, and mitigate attacks Leverage internal and external trusted SME capabilities
Principle 7 Unity of Command:	For every objective, ensure unity of effort under one responsible commander. A single leader should provide direction and coordination for crews ensuring clear and concise objectives. Alignment facilitates communication for mission/common objective Each task presented should have ownership and custodial characteristics for members of the crew Ideas & Solutions  Preferred collective Collective not required
Principle 8 Security:Never permit the enemy to acquire an unexpected advantage. Protect and preserve defense measures, procedures and capabilities from the eyes of the adversary. Protect Information, through PEOPLE vetting “Minimize the chance of future Wiki Leaks” Security exertion minimizes attack vectors Understand the capabilities and limiting factors of your people – “provides for a clearer situational awareness”
Principle 9 Simplicity:Prepare clear, uncomplicated plans concise orders to ensure thorough understanding. Concise Plans and Orders minimize the chance for mistakes.  Degree of operational simplicity results from from experience, training, empowerment and institutionalization of processes. Simplicity in Cyber Operations  - is an Art of Balance Open lines of communication Local & Global support simplicity and information sharing
Contested Commons It is Global medium:	Maritime, Air, Space, Cyber Relied upon for business globalization More nations, organizations, economies at risk Rapid capability development, sluggish legal and global agreement on how to “Address Cyber Attacks” Russia & China created No CY Zones  Some believe there is “No Cyber War” Ask Estonia, Brazil, Canada, South Africa, Malaysia
Your Turn Train & Exercise your crews as a team Open lines of communication Think strategically, act locally Be proactive, make quick fixes, and best practice into TTP Be paranoid, suspicious and know your adversaries Build your trusted crisis network Plan for events Clear the fog

More Related Content

What's hot

Cyber Security
Cyber SecurityCyber Security
Cyber Security
Ramiro Cid
 
Cyber security
Cyber security Cyber security
Cyber security
Sachith Lekamge
 
PHISHING PROTECTION
PHISHING PROTECTIONPHISHING PROTECTION
PHISHING PROTECTION
Sylvain Martinez
 
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
Edureka!
 
Ppt
PptPpt
Cyber terrorism
Cyber terrorismCyber terrorism
Cyber terrorism
Savigya Singh
 
Cyber warfare Threat to Cyber Security by Prashant Mali
Cyber warfare Threat to Cyber Security by Prashant MaliCyber warfare Threat to Cyber Security by Prashant Mali
Cyber warfare Threat to Cyber Security by Prashant Mali
Adv Prashant Mali
 
Career in cyber security
Career in  cyber securityCareer in  cyber security
Career in cyber security
Manjushree Mashal
 
Cyber security
Cyber securityCyber security
Cyber security
Bhavin Shah
 
Advanced Persistent Threat
Advanced Persistent ThreatAdvanced Persistent Threat
Advanced Persistent Threat
Ammar WK
 
Cyber Terrorism Presentation
Cyber Terrorism PresentationCyber Terrorism Presentation
Cyber Terrorism Presentation
merlyna
 
Cyber Security Awareness
Cyber Security AwarenessCyber Security Awareness
Cyber Security Awareness
Ramiro Cid
 
Cybersecurity
CybersecurityCybersecurity
Cybersecurity
A. Shamel
 
Cyber security
Cyber securityCyber security
Cyber security
Manjushree Mashal
 
Cybersecurity Awareness
Cybersecurity AwarenessCybersecurity Awareness
Cybersecurity Awareness
JoshuaWisniewski3
 
Cyber Warfare - Jamie Reece Moore
Cyber Warfare - Jamie Reece MooreCyber Warfare - Jamie Reece Moore
Cyber Warfare - Jamie Reece Moore
Jamie Moore
 
Cyber security
Cyber securityCyber security
Cyber security
TaimoorArshad5
 
Cybercrime and its effects on personal life who uses internet
Cybercrime and its effects on personal life who uses internet Cybercrime and its effects on personal life who uses internet
Cybercrime and its effects on personal life who uses internet
vimal kumar arora
 
Introduction to cyber security
Introduction to cyber security Introduction to cyber security
Introduction to cyber security
RaviPrashant5
 

What's hot (20)

Cyber Security
Cyber SecurityCyber Security
Cyber Security
 
Cyber security
Cyber security Cyber security
Cyber security
 
PHISHING PROTECTION
PHISHING PROTECTIONPHISHING PROTECTION
PHISHING PROTECTION
 
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
Cybersecurity Tools | Popular Tools for Cybersecurity Threats | Cybersecurity...
 
Ppt
PptPpt
Ppt
 
Cyber terrorism
Cyber terrorismCyber terrorism
Cyber terrorism
 
Cyber warfare Threat to Cyber Security by Prashant Mali
Cyber warfare Threat to Cyber Security by Prashant MaliCyber warfare Threat to Cyber Security by Prashant Mali
Cyber warfare Threat to Cyber Security by Prashant Mali
 
Career in cyber security
Career in  cyber securityCareer in  cyber security
Career in cyber security
 
Cyber security
Cyber securityCyber security
Cyber security
 
Cyber Security
Cyber SecurityCyber Security
Cyber Security
 
Advanced Persistent Threat
Advanced Persistent ThreatAdvanced Persistent Threat
Advanced Persistent Threat
 
Cyber Terrorism Presentation
Cyber Terrorism PresentationCyber Terrorism Presentation
Cyber Terrorism Presentation
 
Cyber Security Awareness
Cyber Security AwarenessCyber Security Awareness
Cyber Security Awareness
 
Cybersecurity
CybersecurityCybersecurity
Cybersecurity
 
Cyber security
Cyber securityCyber security
Cyber security
 
Cybersecurity Awareness
Cybersecurity AwarenessCybersecurity Awareness
Cybersecurity Awareness
 
Cyber Warfare - Jamie Reece Moore
Cyber Warfare - Jamie Reece MooreCyber Warfare - Jamie Reece Moore
Cyber Warfare - Jamie Reece Moore
 
Cyber security
Cyber securityCyber security
Cyber security
 
Cybercrime and its effects on personal life who uses internet
Cybercrime and its effects on personal life who uses internet Cybercrime and its effects on personal life who uses internet
Cybercrime and its effects on personal life who uses internet
 
Introduction to cyber security
Introduction to cyber security Introduction to cyber security
Introduction to cyber security
 

Viewers also liked

Securing the Internet of Things
Securing the Internet of ThingsSecuring the Internet of Things
Securing the Internet of Things
Paul Fremantle
 
Military Robots
Military RobotsMilitary Robots
Military Robots
nsapre
 
Indian Army
Indian ArmyIndian Army
Indian Army
Sridhar Srinivas
 
Civil – military relations in india a perspective
Civil – military relations in india   a perspectiveCivil – military relations in india   a perspective
Civil – military relations in india a perspectiveUmong Sethi
 
Cyber security
Cyber securityCyber security
Cyber security
Siblu28
 
Network Security Threats and Solutions
Network Security Threats and SolutionsNetwork Security Threats and Solutions
Network Security Threats and SolutionsColin058
 
IoT - IT 423 ppt
IoT - IT 423 pptIoT - IT 423 ppt
IoT - IT 423 pptMhae Lyn
 

Viewers also liked (9)

Securing the Internet of Things
Securing the Internet of ThingsSecuring the Internet of Things
Securing the Internet of Things
 
Military Robots
Military RobotsMilitary Robots
Military Robots
 
Indian Army
Indian ArmyIndian Army
Indian Army
 
Indian army
Indian armyIndian army
Indian army
 
Network security
Network securityNetwork security
Network security
 
Civil – military relations in india a perspective
Civil – military relations in india   a perspectiveCivil – military relations in india   a perspective
Civil – military relations in india a perspective
 
Cyber security
Cyber securityCyber security
Cyber security
 
Network Security Threats and Solutions
Network Security Threats and SolutionsNetwork Security Threats and Solutions
Network Security Threats and Solutions
 
IoT - IT 423 ppt
IoT - IT 423 pptIoT - IT 423 ppt
IoT - IT 423 ppt
 

Similar to A military perspective on cyber security

Strategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity RisksStrategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity Risks
Matthew Rosenquist
 
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Morakinyo Animasaun
 
Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016
CSO_Presentations
 
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie AheadRethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
OpenDNS
 
The Economics of Cyber Security
The Economics of Cyber SecurityThe Economics of Cyber Security
The Economics of Cyber Security
John Gilligan
 
Cyber Security Audit.pdf
Cyber Security Audit.pdfCyber Security Audit.pdf
Cyber Security Audit.pdf
Vograce
 
Phases of Incident Response
Phases of Incident ResponsePhases of Incident Response
Phases of Incident Response
EC-Council
 
Improve Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USMImprove Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USM
AlienVault
 
Symantec cyber-resilience
Symantec cyber-resilienceSymantec cyber-resilience
Symantec cyber-resilience
Symantec
 
Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?
nathan816428
 
Cyber Resilience
Cyber ResilienceCyber Resilience
Cyber Resilience
Phil Huggins FBCS CITP
 
Multimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguisMultimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguis
samis
 
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual SecurityA Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
Hossam Al-Ansary
 
Preparing for future attacks. Solution Brief: Implementing the right securit...
Preparing for future attacks.  Solution Brief: Implementing the right securit...Preparing for future attacks.  Solution Brief: Implementing the right securit...
Preparing for future attacks. Solution Brief: Implementing the right securit...
Symantec
 
Proposal defense presentation
Proposal defense presentationProposal defense presentation
Proposal defense presentation
Ruchika Mehresh
 
[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defence[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defence
OWASP EEE
 
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINALDefending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINALMichael Bunn
 
Wasn't expecting that! Now what?
Wasn't expecting that! Now what?Wasn't expecting that! Now what?
Wasn't expecting that! Now what?
Jisc
 

Similar to A military perspective on cyber security (20)

Strategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity RisksStrategic Leadership for Managing Evolving Cybersecurity Risks
Strategic Leadership for Managing Evolving Cybersecurity Risks
 
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
Be Prepared: Emerging Cyber Security Threats, Vulnerabilities and Risks on Ca...
 
Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016Robert Lentz - CSO Perspectives Roadshow 2016
Robert Lentz - CSO Perspectives Roadshow 2016
 
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie AheadRethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
Rethinking Cyber-Security: 7 Key Strategies for the Challenges that Lie Ahead
 
The Economics of Cyber Security
The Economics of Cyber SecurityThe Economics of Cyber Security
The Economics of Cyber Security
 
Cyber Security Audit.pdf
Cyber Security Audit.pdfCyber Security Audit.pdf
Cyber Security Audit.pdf
 
Phases of Incident Response
Phases of Incident ResponsePhases of Incident Response
Phases of Incident Response
 
Improve Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USMImprove Situational Awareness for Federal Government with AlienVault USM
Improve Situational Awareness for Federal Government with AlienVault USM
 
Symantec cyber-resilience
Symantec cyber-resilienceSymantec cyber-resilience
Symantec cyber-resilience
 
Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?Proactive Security - Principled Aspiration or Marketing Buzzword?
Proactive Security - Principled Aspiration or Marketing Buzzword?
 
Cyber Resilience
Cyber ResilienceCyber Resilience
Cyber Resilience
 
Multimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguisMultimedia content security in file based environments - sami guirguis
Multimedia content security in file based environments - sami guirguis
 
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual SecurityA Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
A Proposed Model for Datacenter in -Depth Defense to Enhance Continual Security
 
Preparing for future attacks. Solution Brief: Implementing the right securit...
Preparing for future attacks.  Solution Brief: Implementing the right securit...Preparing for future attacks.  Solution Brief: Implementing the right securit...
Preparing for future attacks. Solution Brief: Implementing the right securit...
 
Proposal defense presentation
Proposal defense presentationProposal defense presentation
Proposal defense presentation
 
[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defence[Bucharest] Attack is easy, let's talk defence
[Bucharest] Attack is easy, let's talk defence
 
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINALDefending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
Defending Against Advanced Threats-Addressing the Cyber Kill Chain_FINAL
 
Iscsp apt
Iscsp aptIscsp apt
Iscsp apt
 
SecurityOperations
SecurityOperationsSecurityOperations
SecurityOperations
 
Wasn't expecting that! Now what?
Wasn't expecting that! Now what?Wasn't expecting that! Now what?
Wasn't expecting that! Now what?
 

Recently uploaded

FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
DianaGray10
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Product School
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
UiPathCommunity
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Ramesh Iyer
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
Frank van Harmelen
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
91mobiles
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
g2nightmarescribd
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
DianaGray10
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
Product School
 

Recently uploaded (20)

FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
Builder.ai Founder Sachin Dev Duggal's Strategic Approach to Create an Innova...
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3UiPath Test Automation using UiPath Test Suite series, part 3
UiPath Test Automation using UiPath Test Suite series, part 3
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 

A military perspective on cyber security

  • 1. A Military Perspective on Cyber Security “Not a Paradigm Shift, Tactical Approach” Joey Hernandez CISSP, MBCI jhernandez@iSCSP.org
  • 2. Topic Background The Change Center of Gravity Rings Principles of War Contested Commons Your Turn
  • 3. About Me Former Intelligence and Cyber Operations Analyst with a broad background in all domains of Network Operations. College Professor in the areas of Criminal Justice & Information Security Background in assessments covering NIST, FIPS, & ISO standards Background in International CERT operations & current Director of Operations for the iSCSP
  • 4. Background Elevated age in cyber warfare Malware has become focused SCADA Systems (Stuxnet) Malware performs Operational Preparation of the Environment (OPE) Conficker (Millions still infected) Ransomeware Data is being held hostage The advanced capability of the threat has increased the risk. Understanding the risk allows employment of defensive measures to mitigate the risk – “Risk will always be present”
  • 5. The Change Combined capabilities have helped attackers create weapon systems Soldier +Rifle + Bullets =(This is a weapon systems) Cyber State Sponsored, Script Kiddies, Paid Staff Laptop, Desktop, Mobile devices Metasploit, Backtrak, PoisonIvy, Mpack, other RAT Hacker + Laptop + Metasploit = Weapon System Attackers, Adversaries, Cyber terrorist are now employing TTP
  • 6. Wardens Rings The focus is to attack Centers of Gravity The Estonian attacks Utilized TTP Rings Leadership (Defaced Ministry of Defense, Finance, etc) Organic/System Essentials Infrastructure (DDoS against ISP and Wardialing to lock up POTS network) Population (News Media) Fielded Military Forces Inside Out Attack Methodology For Kinetic Warfare
  • 7. Cyber Population attacks cascade the rings System essential attacks on services eg. Supply Chain, Food, FedEx ; feeds the rings in both direction Infrastructure attacks feed the rings both directions Leadership focus elevates the nature of the actions Inside Out Attack Methodology For Cyber Warfare “Defense measures must ensure protection of systems first and population foremost”
  • 8. Countering Principles of War Raising perceptions of attacks guarantee an elevated perspective. Proactive approaches to providing defense-in- depth reduces risk to all Centers of Gravity NOT immediately achievable, requires buy-in
  • 9. Principle 1 Objective:Direct every operation towards a clearly defined, decisive, and attainable objective. Security Create policy & Directives that are concise, fed from leadership and enhances current capabilities. Defense Institutionalize SOP creating a path to obtainable objectives
  • 10. Principle 2 Offensive:Seize, retain, and exploit the initiative Cyber Security personnel must have all tools required to respond to incidents or events when presented enabling decisive results Immediate knowledge of events through proactive Proactive research International teams of trust Reverse engineering of “current” malicious code Pentesting with seized exploits ensure preparedness Exercise routinely against new threats Exploitation allows establishing opstempo for defensive and counter operations.
  • 11. Principle 3 Economy of Force:Allocate minimum essential combat power to secondary efforts. Cyber Security staff should only be allocated tasks relating to protection of grid and its associated systems Minimize external tasks not associated to Cyber Security “Employ” others to do: password resets, maintenance, and support Discriminate whenever possible! Indentify and prioritize cyber assets and assign coverage accordingly
  • 12. Principle 4 Mass: Concentrate combat power at the decisive place and time. Sustain with technology, resolve with Mass – Use Crisis action teams, leverage distributed knowledge “Get there first with the most”. The dynamic nature of Cyber Space allows you to employ mass globally with centralized control Convene and delegate Ensure communication is continuous If possible (Make possible) Disarm the attacker Block/Mitigate adversaries ability to maneuver, virtual arm bar Remain focused on protection
  • 13. Principle 5 Surprise:Strike the enemy at a time, place, or manner for which they are unprepared. Always expect it! Trust but verify – If the network is quiet lower thresholds, to find hidden traffic Utilize time to influence out of the box operating procedures and TTP to develop Always expect it!
  • 14. Principle 6 Maneuver:Place the enemy in a position of disadvantage through flexible application of combat power Gain an advantage in positioning by training, certifying defense crews Exercising as a team places the adversary in a position of disadvantage Train as a group to flexibly protect, respond, and mitigate attacks Leverage internal and external trusted SME capabilities
  • 15. Principle 7 Unity of Command: For every objective, ensure unity of effort under one responsible commander. A single leader should provide direction and coordination for crews ensuring clear and concise objectives. Alignment facilitates communication for mission/common objective Each task presented should have ownership and custodial characteristics for members of the crew Ideas & Solutions Preferred collective Collective not required
  • 16. Principle 8 Security:Never permit the enemy to acquire an unexpected advantage. Protect and preserve defense measures, procedures and capabilities from the eyes of the adversary. Protect Information, through PEOPLE vetting “Minimize the chance of future Wiki Leaks” Security exertion minimizes attack vectors Understand the capabilities and limiting factors of your people – “provides for a clearer situational awareness”
  • 17. Principle 9 Simplicity:Prepare clear, uncomplicated plans concise orders to ensure thorough understanding. Concise Plans and Orders minimize the chance for mistakes. Degree of operational simplicity results from from experience, training, empowerment and institutionalization of processes. Simplicity in Cyber Operations - is an Art of Balance Open lines of communication Local & Global support simplicity and information sharing
  • 18. Contested Commons It is Global medium: Maritime, Air, Space, Cyber Relied upon for business globalization More nations, organizations, economies at risk Rapid capability development, sluggish legal and global agreement on how to “Address Cyber Attacks” Russia & China created No CY Zones Some believe there is “No Cyber War” Ask Estonia, Brazil, Canada, South Africa, Malaysia
  • 19. Your Turn Train & Exercise your crews as a team Open lines of communication Think strategically, act locally Be proactive, make quick fixes, and best practice into TTP Be paranoid, suspicious and know your adversaries Build your trusted crisis network Plan for events Clear the fog