Helping You Piece IT Together
http://www.bhconsulting.ie info@bhconsulting.ie
Learning From History
Who is Brian Honan?
Who is Brian Honan?
What is IRISS-CERT?
 Ireland’s First CSIRT
(Computer Security Incident Response Team)
 Provide Services On Information Security
 Services Provided Free of Charge
 Not For Profit Organisation
Services Offered
 Irish Focused Alerts and Warnings
Vulnerability Awareness
Incident Awareness
Sanitised Attack Notifications
Coordination Service
 Irish Focused Research
Trends and Metrics
General Awareness
 Knowledge Sharing
Informal discussion
Information Sharing & Dissemination
2004 – The Journey Began
What’s Missing?
Not a Fair Fight !
Stakeholders
2008 IRISS Is Born
IRISSCERT Team
Affiliations
Affiliations
IRISSCERT Achievements
Finalist in Best Information
Security Team Category
IRISSCERT SmileIreland
IRISSCERT SmileIreland
Other Key Achievements
 Verizon Databreach Investigations Report
(DBIR) 2012 & 2013
 Assisted NHTCU In Bredolab Cleanup
 Hosted Transits Training for 35 CERT Personnel
From Around Europe
 DNS Changer Cleanup
 Participated in A CERT Exercises
 Coordinated Vulnerability Disclosures (CNI,
vendors, & websites)
Infosec Certainties
Recognised Threat
Recognised Threat
“the cyber threat to our nation
is one of the most serious
economic and national
security challenges we face.”
"industrial-scale processes
involving many thousands of
people lying behind both state
sponsored cyber espionage and
organised cyber crime".
Traditional IT Security
Ancient Security
Ancient Security
Fortified Perimeter
Ingress/Egress Points
Layered Security
Perimeter Defences
Good Against
And
But Not Against
Or
Or
So In Reality Is Like
Crack the Outer Shell
Verizon DBIR
Breach Detection
69%
22%
9%
Detected by 3rd Party
Detected by Org
Detected by Customer
Source: Verizon DBIR 2013
Time To Discover Breach
34%
4%
62%
Less than A month
Years or More
Months or More
Source: Verizon DBIR 2013
Difficulty
78%
22%
Not Difficult
Moderate to Difficult
Source: Verizon DBIR 2013
2012 - Incidents
2012 - Incidents
Phishing,
74%
Malware,
19%
Other,
7%
2012 - Incidents
Org Crime,
95%
Other, 5%
2012 - Incidents
 Increase in Targeted Attacks
 Increase in DDOS Attacks
 Increase in Activism
 Ransomware Attacks
2012 - Incidents
 Root Cause
 Poor Passwords
 Missing Patches
 Vulnerabilities
 Web Platforms
 Out of Data Anti-Virus Software
 Lack of Monitoring
Learning from The Past
Understand Your Business
Don’t Forget The Basics
Patching
Strong Passwords (2FA?)
Anti-Virus
Monitor Logs
Harden Systems
Use Security Tools
Segment Your Information
Analyse Network Patterns
Train Staff & Partners
Use Open Source Data
Set Traps
Share with Peers
http://www.veriscommunity.net/doku.php
Questions ?

Learning from History

Editor's Notes

  • #7 2004 I identified that Ireland had no CERT. I felt that this was a major weakness in our security infrastructure at both an economic and national security point of view. In 2004 I took the decision to pursue the reasons why we had no CERT and based on the responses determine if we needed one. If it was determined we should have one then outline a way forward for Ireland to have a CERT
  • #10 I met with the various stakeholders; Department of Communications responsible for Internet security Subsequent meetings with An Garda Siochana (Irish Police) Chambers Ireland Irish Business and Employers Confederation Enterprise Ireland Irish Small & Medium Enterprises Association Internet Service Provider Association of Ireland Science Foundation Ireland HEAnet CERT Center for Cybercrime Investigation - University College Dublin ISSA Ireland Irish Information Systems Security Forum The SANS Institute Europe ENISA (the European Network and Information Security Agency ) Numerous Organisations of Varying Sizes
  • #11 So I set up IRISS. IRISS is a registered not for profit company. Business Day coverage Contactable by email & web. Part Time Volunteer Staff Irish Focused Security Information
  • #19 The three certainties with regards to information security Death and Taxes You will have an incident. How you respond to an incident will have a direct influence on the impact that incident may have to your costs, reputation and ability to conduct business.
  • #45 Improved Response provides; Positive Security Posture Incidents Dealt with Quickly, Efficiently and Effectively Rapid and Accurate Assessment of Incidents Choosing Most Appropriate Response. Shortened Recovery Times. Minimised Business Disruption. Confidence to Proceed with a Court Case. Regulatory and Legal Compliance. Potential Reduction in Incidents. Accurate Reporting and Metrics
  • #51 Impossible to monitor everything – add intelligence and automation
  • #55 Behavioural patterns What anonamilies
  • #56 RSA Social Engineer
  • #59 Veris from Verizon