111
1 I’m a Suit in a Cyber World! 16 Jul 2011

1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

Embed Size (px)

Citation preview

Page 1: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

1

I’m a Suit in a Cyber

World!

16 Jul 2011

Page 2: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

2

Employment History

Financial Services

Page 3: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

3

Employment History

Financial Services

Page 4: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

4

Employment History

Ski Bum

Page 5: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

5

Employment History

Ski Bum

Page 6: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

6

Employment History

USAF Officer

Page 7: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

7

Employment History

USAF Officer

Page 8: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

8

Employment History

SAIC

Page 9: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

9

Employment History

SAIC Program Manager

Page 10: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

10

Employment History

SAIC Program Manager

Page 11: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

11

Employment History

SAIC Division Manager

Page 12: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

12

Employment History

SAIC Division Manager

Page 13: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

13

Employment History

SAIC Capture Manager

Page 14: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

14

Employment History

SAIC Capture Manager

Page 15: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

15

Education History

King CollegeBA Economics & Business

Administration

Page 16: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

16

Education History

King CollegeBA Economics & Business

Administration

Page 17: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

17

Education History

Chartered Life Underwriter

Page 18: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

18

Education History

Chartered Life Underwriter

Page 19: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

19

Education History

UMD EuropeBowie State University

MS Management Information Systems

Page 20: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

20

Education History

UMD EuropeBowie State University

MS Management Information Systems

Page 21: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

21

Education History

PMP

Page 22: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

22

Education History

PMP

Page 23: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

23

Large Cyber Procurements

SAIC Capture Manager

Page 24: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

24

Large Cyber Procurements

> $250,000,000

Page 25: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 26: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 27: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

27

Introduction to

cybergamut

Page 28: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

28

History and Why Change• In 2008 SAIC established cybernexus

– Coming together or “nexus” of cyber analysts– Central Maryland

• In 2011 cybernexus renamed cybergamut– Runs the “gamut” of cyber disciplines– Global organization

• cybergamut nodes– San Antonio, Texas– Northern Virginia (Tysons Corner and Herndon)– Sioux Falls, South Dakota

Page 29: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

29

Mission Statement

cybergamut is a worldwide community of practice for cyber professionals across industry, academia, and government providing ongoing education, training, and certification opportunities throughout all phases of a cyber professional’s career, utilizing traditional methods as well as non-traditional techniques like puzzles, Easter Eggs, and problem solving.

Page 30: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

30

Easter Eggs

Page 31: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

31

Easter Eggs (eeggs.com)

Page 32: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

32

Challenge Cards

Page 33: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

33

Challenge Coin

Page 34: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

34

Technical Tuesday

• What it is – a technical exchange

• What it is not– A sales presentation– A product endorsement– For discussion of procurements – For discussion of procurement related issues

Page 35: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

35

PDU and CPE

• PMI PDU’s– PMI Baltimore approved most Technical Tuesday

events as eligible for PMI PDU’s under Category B, Continuing Education

• CPE’s for CISSP– Self certification

• Other certifications– What do you need?

Page 36: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

36

cybergamut Nodes• Established node

– San Antonio– Northern Virginia (Tysons Corner and Herndon)– Sioux Falls, SD

• Node requirements (as of now)– Open and accessible to all

• Industry, academia, and government– Room for at least 20 people

• Computer, projector, conference phone– Guarantee at least five people in the room

• In case someone else shows up so they’re not uncomfortable • Future nodes - ???

– San Diego, CA– Rome, NY– Atlanta, GA

Page 37: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

37

Previous Topics• Defending a Large Network

– Brian Rexroad of AT&T– 2 Dec 2008

• DNI Essentials– Paul Schnegelberger of SAIC and John Sanders of

Northrop Grumman TASC– Nov/Dec 2008

• Digital Forensics– Jim Jaeger of General Dynamics– 13 Jan 2009

• Case Studies in Cyber Attacks – Aaron Wilson of SAIC– 13 Jan 2009

• Trickler– Greg Virgin of RedJack– 27 Jan 2009

• Security Tools– Peiter “Mudge” Zatko of BBN– 27 Jan 2009

• IPv6– David Harris of SAIC– 10 Feb 2009

• Exploitation Prediction – Darryl Ackley of New Mexico Tech– 24 Feb 2009

• Analytic and IO Tools– Clift Briscoe and Nat Cooper of Edge– 24 Mar 2009

• Distributed Systems Technologies and Internet Intelligence

– George Economou of Akamai– 24 Mar 2009

• Exploring the Social World of the Russian Hacker Community

– Tom Holt of Michigan State University– 10 Mar 2009

• Modern Forensic Investigative Techniques – Amber Schroader of Paraben– 10 Mar 2009

• Defending Against BGP Man-In-The-Middle Attacks

– Earl Zmijewski of Renesys– 14 Apr 2009

• Examining the Storm Worm– Nico Lacchini of TDI– 26 May 2009

• No-Tech Hacking– Johnny Long– 11 Jun 2009

• Dirty Secrets of the Security Industry– Bruce Potter of Ponte Technologies– 14 Jul 2009

• Windows Forensic Analysis: Dissecting the Windows Registry

– Rob Lee of MANDIANT and the SANS Institute– 18 Aug 2009

Page 38: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

38

Previous Topics cont.• Silence of the RAM

– Sean Bodmer of Savid Corporation– 22 Sep 2009

• VoIP Security - Attacks, Threats and Countermeasures

– Stuart McLeod of Global Knowledge– 3 Nov 2009

• A Tale of Two Departments – How Commerce and State Dealt With Chinese Intrusions: Lessons Learned Plus: Security Heroes and the 20 Critical Controls

– Alan Paller of the SANS Institute– 9 Mar 2010

• Aurora– Aaron Barr of HBGary Federal– 27 Apr 2010

• Malware reverse engineering at ITT – Paul Frank of ITT– 25 May 2010

• Advanced Cyber Collection Techniques; Extracting and Analyzing Information from the Domain Name System

– Tim Cague of The CYAN Group– 10 Aug 2010

• The Rise of the Social Web – Aaron Barr of HBGary Federal– 5 Oct 2010

• Why Security People S#ck – Gene Bransfield of Tenacity Solutions– 9 Nov 2010

• Insider Threat and Real-World Incident Study– Presented by Michael Collins & Greg Virgin of

RedJack along with Jim Downey of DISA PEO-MA– 30 Nov 2010

• Network Monitoring– Josh Goldfarb of 21st Century Technologies– 4 Jan 2011

• Network Device Exploitation with Universal Plug & Play

– Terry Dunlap of Tactical Network Solutions– 8 Feb 2011

• Deep Packet Inspection for Cybersecurity ASW&R

– Jeff Kuhn of Pangia Technologies– 29 Mar 2011

• Stuxnet Redux: Malware Attribution & Lessons Learned

– Tom Parker of Securicon – 19 Apr 2011

• Special Technical Tuesday and renaming– 10 May 2011

• APT Intrusion Remediation: The Top Do's and Don'ts

– Rob Lee of MANDIANT and The SANS Institute– 24 May 2011

• Deep Packet Inspection– Peder Jungck of Cloudshield and SAIC– 28 Jun 2011

• Our Security Status is Grim– Brian Snow– 19 Jul 2011

Page 39: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

39

Upcoming Technical Tuesdays• Looking for more speakers and topics such as:

– Tor routing– Malware reverse engineering– Cyber situational awareness– Splunk– Cloud computing and cloud forensics– Geolocation of IP addresses and mobile devices– Digital forensics– E-discovery– Attack attribution– Deep packet inspection– Fuzzing– Writing secure code

To suggest topics, volunteer to speak, or to receive an invitation, please contact: [email protected]

Page 40: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

40

Interesting Topics from the Chief 5uit’s Perspective

Page 41: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

41

Remember!

Page 42: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

42

Dash

Page 43: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

43

Foreign Language

• 1337 = LEET = short for elite (maybe)– 5uit = Suit

• Pwn = Own– Your computer has been pwned

• Teh = the– Accidents become purposeful– This was before spell checkers – hard to do now

• Texting– LOL– ROFL– - OMG Powerpoint translated : and ) to this

Page 44: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

44

Different Culture

• 95% male• Black T-shirts• Interesting facial hair• Body art• Add alcohol and mix vigorously• Stickers everywhere• Lock picking for fun (lock sport)• Hackers aren’t all Bad

– I Hack Charities• As a 5uit, I’m counter-counter-culture

Page 45: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 46: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 47: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 48: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

48

Bot in a Botnet

• What’s a Bot and what’s a Botnet?– Computers that have been taken over– Used for distribution of Spam and Malware– Used for other nefarious deeds

Page 49: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

49

Bot in a Botnet

• What’s a Bot and what’s a Botnet?– Computers that have been taken over– Used for distribution of Spam and Malware– Used for other nefarious deeds

• Does your Mom care?

Page 50: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

50

Bot in a Botnet

• What’s a Bot and what’s a Botnet?– Computers that have been taken over– Used for distribution of Spam and Malware– Used for other nefarious deeds

• Does your Mom care?

• Do you care?

Page 51: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

Digital Hygiene

Page 52: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

You can’t Patch Stupid!!!

Page 53: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

You can’t Patch Stupid!!!

Don’t be “Stupid”

Page 54: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 55: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 56: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 57: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 58: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 59: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 60: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 61: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 62: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 63: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 64: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 65: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 66: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 67: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 68: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 69: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 70: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 71: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

Don’t use Reply All in a Mail

Storm!!!

Page 72: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

You can’t Patch Stupid!!!

Page 73: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

73

Social Engineering

• Extremely effective

• DEFCON Social Engineering Contest– Amazing what people will give away– Help desks were overly helpful

Page 74: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 75: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

Click OK to Continue

Page 76: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

76

Should I proceed?

Page 77: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

77

Should I proceed? I did!!!

Page 78: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

78

Phishing and Spearphishing

• E-mails and targeted e-mails– Usually with a link– Watch for typo’s and misspelllings

• V1AGRA

• [Insert company name here] has been sold!

Page 79: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

79

What about this one?

Page 80: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

80

Corporate Response

Page 81: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

81

Another One!

Page 82: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

82

Phishing and Spearphishing

• E-mails and targeted e-mails– Usually with a link– Watch for typo’s and misspelllings

• V1AGRA

• [Insert company name here] has been sold!

• DEFCON Skybox Demo– Trend tracking via Twitter– Tracking an individual via Social Media– Tiny urls and Bit.ly

Page 83: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

83

GPS and other evil devices

• GPS, iPhones, etc remember everything

• iPhones sync EVERYTHING with their host

• Windows 7 Registry saves things a long time

• Forensics examiner’s dream

• Car thieves “Go Home”– You’re not home and now you’re stranded

Page 84: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

84

Supply Chain

• Where was your code written?• Where was your hardware produced?• How did it get to you?

• Thumb drives• Hard drives

Page 85: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

85

X begets Y begets Z…• Needs beget innovation• Innovation begets technology• Policy and strategy follow

– aren’t necessarily “begotten”• Lack of policy begets ineffective or non-strategy• Doctrine is the military word for policy• Tactics are the refinement of military strategy• difference between responsibility and authority

– DHS has responsibilities– DoD has many clearly defined authorities

• National Cyber Policy is challenging– AFCEA story

Page 86: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

86

Steganography

• Stuff hidden in pictures• Stuff hidden in other non-obvious places

Page 87: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

87

Who votes for #1?

Page 88: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

88

Who votes for #2?

Page 89: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

89

Who votes for #3?

Page 90: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

90

Who votes for #4?

Page 91: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

91

Steganography

• Let’s check your votes . . .

Page 92: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

92

#1 Malamute???; not Malware

Page 93: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

93

#2

Page 94: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

94

#2 is Malodorous; not Malware

Page 95: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

95

#3 is Mal-wear; not Malware

Page 96: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

96

#4 is Malicious; not Malware

Page 97: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

97

Steganography

• None of those pictures– I don’t think anyway…

• Very hard to detect in a single picture– Potential detection if you have both pictures

50 KB 450 KB

Page 98: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

98

Other Scary/Cool Concepts

• Segmented polymorphic malware– Bad stuff that changes its looks, delivered in parts

• Metamorphic malware– Bad stuff that changes what it does

• Cloud Computing – distributed virtualization– Which denomination?

• Hadoop – son’s toy elephant– Cloud Security– Cloud Forensics

• Zero-day– Brand new malware or exploits

Page 99: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

99

Should I click?

Page 100: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

100

Social Networking

• “On the Internet, nobody knows you’re a dog”– New Yorker Magazine, 1993– Still true today

• Do you really know who your Friends are?– Would you cross the street to see them in person?– What are you revealing in your posts?

Page 101: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

101

Fake Profile???

Page 102: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

102

Social Networking

• “On the Internet, nobody knows you’re a dog”– New Yorker Magazine, 1993– Still true today

• Do you really know who your Friends are?– Would you cross the street to see them in person?– What are you revealing in your posts?

• “My Daddy’s dating…”• Twitter

– Spontaneous and quick– No filter / no retraction

Page 103: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services
Page 104: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

104

Location-based Services

• Facebook Places and Foursquare• Preparation for Travel

– Set up light timers– Make your home look lived in

• “Check in” at out of state locations• Photo metadata• Okay for my Friends to know• What about Friends of Friends?

– What about Mafia Wars Friends of Friends?

Page 105: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

105

User Names and Passwords

• Anonymous and LULZ Sony Attacks– 77 million users affected

• Other large data thefts

• User Name and Password combinations– How many do you use?

– Remember the Bots?!?

– This got my attention!

Page 106: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

106

What do we do?

• I don’t know…

• I think education helps…

Page 107: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

107

Cyber Increases

• Volume

• Variety

• Velocity

Page 108: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

108

Cyber Increases

• Volume = 111 slides

• Variety

• Velocity

Page 109: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

109

Cyber Increases

• Volume = 111 slides

• Variety = 21 topics

• Velocity

Page 110: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

110

Cyber Increases

• Volume = 111 slides

• Variety = 21 topics

• Velocity = 1 hour = <33 sec per slide

Page 111: 1 Im a Suit in a Cyber World! 16 Jul 2011. 2 Employment History Financial Services

111

That’s all we’ve got!