26
Improving Cyber Ecosystems Health by Metrics, Measurement and Mitigation Support Borderless Cyber Asia 2016, at Keio University,Tokyo Yurie Ito Executive Director, CyberGreen

Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

  • Upload
    others

  • View
    11

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

ImprovingCyberEcosystemsHealthbyMetrics,MeasurementandMitigationSupport

BorderlessCyberAsia2016,atKeioUniversity,TokyoYurieIto

ExecutiveDirector,CyberGreen

Page 2: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

2Copyright©CyberGreen2016AllRightsReserved.

Page 3: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

3Copyright©CyberGreen2016AllRightsReserved.

CyberGreen:Whatwedo

CyberHealthMeasurementWemeasureRisk-to-others.

ProvideaclearingHouseforRiskMiFgaFonBCPs.

SourcingRiskcondiFonsData

Advocacy

CapacityBuildingNeedsanalysisandImpactmeasurement

Page 4: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

4Copyright©CyberGreen2016AllRightsReserved.

CyberGreen:Whoweare–collaborationforGlobalCommonGood

CyberGreenMetricsExperts

Group

SpecialAdvisers

CyberGreenBoard

Directors

TechnicalPartners

MiFgaFonsCSIRTs

GlobalDatasources

Sponsors

Dr.PaulTwomeyFormerICANNCEO)

Dr.RichardSoleyIndustrialInternetConsorFum

Dr.DanGeerSpecialAdviseronMetrics

Dr.JunMuraiDean,KeioUniversity

Dr.PaulVixieFarsightTechnology(SpecialAdviser)

Page 5: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

5Copyright©CyberGreen2016AllRightsReserved.

TheCybersecurityLandscape

ThreatResponse

NaFonalsecurity

Publicsafety

Intelligence

LawEnforcement

Military

EcosystemHealthImprovement

Networkoperators

CSIRTs

ProductVendors

Media

Users CorporaFons

Policymakers

Page 6: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

6Copyright©CyberGreen2016AllRightsReserved.

LackofmaintenanceisriskstoOTHERS

MisconfiguraFon

VulnerabiliFes

InfecFon

Riskfactorsofthehealthyinternet

Page 7: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

7Copyright©2016,CyberGreen Sept2016

Abuse-ablesystemicconditionsposingriskstoothers*includingtoyourself*

OpenrecursiveDNSservers

OpenNTPservers

OpenSSDPservers

OpenSNMPservers

Page 8: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

Copyright©CyberGreen2016AllRightsReserved.

CyberGreenv2.0Metrics:Premise

•  CGwilltaketheperspecFveofrisk-to-

others.

•  On-the-groundrealityisthatDDoSisthedamagingformofa_ackcurrentlymostextensivelyseeninquanFty.

8

Page 9: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

9Copyright©CyberGreen2016AllRightsReserved.

v.2Metricsmethod

Page 10: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

CyberGreenMetrics

10Copyright©CyberGreen2016AllRightsReserved.

Page 11: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

•  Risktoothers•  Don'tmeasurework/effort,measurerisk

reducFon.•  Transparency•  Reproducibility/Repeatability•  Accuracy

Principles

Page 12: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

12Copyright©CyberGreen2016AllRightsReserved.

ETLprocess

Page 13: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

13Copyright©CyberGreen2016AllRightsReserved.

Page 14: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

14Copyright©CyberGreen2016AllRightsReserved.

CyberGreenPlatformTechnical

Objectives

Page 15: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

15Copyright©CyberGreen2016AllRightsReserved.

Page 16: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

16Copyright©CyberGreen2016AllRightsReserved.

Page 17: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

17Copyright©CyberGreen2016AllRightsReserved.

Page 18: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

18Copyright©CyberGreen2016AllRightsReserved.

Page 19: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

19Copyright©CyberGreen2016AllRightsReserved.

Page 20: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

20Copyright©CyberGreen2016AllRightsReserved.

Page 21: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

21Copyright©CyberGreen2016AllRightsReserved.

MoreEfficientandGreaterImpactofMitigationforGlobalCommonGood

Ecosystemownersandstakeholdersmusttakecareofecosystemhealthandclean-upinfecFonssuchaseffortstoeliminateproxya_ackinfrastructure.EliminaFngtherisksposingtotherestoftheworldwouldbuild;o NaFonallevelàConfidenceo Businessàsocialresponsibility,brandingpowero UsersàIndicaFonofmaturityofcybersociety,educaFonalandawarenesslevel

Page 22: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

22Copyright©CyberGreen2016AllRightsReserved.

Futurework:Metricsv.3

•  ImproveAssetOwnerMetrics,CreateNewVendorMetrics

•  AnalyzewhohasgreaterabilityformiFgaFonimpact•  V.2isassetownerfocused•  V.3:howcanweadd“vendorrisktoothers”

CyberGreenislookingfortheSponsorforthisresearchanddevelopmentofMetricsv.3PleasecontactushowtoSupport.

[email protected]/[email protected]

Page 23: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

G7ICTMinisterscommitment

h_p://www.soumu.go.jp/main_content/000416960.pdf

Page 24: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

RegionalhubHighlight:ASEAN

MinisterYaacob’sopeningstatement-13CyberGreenisoneglobaliniFaFvethatwillaidusinsecuringourcommoncyberspace.TheCyberGreenprojectaimstogivecountriesawarenessofthestateofcyberhealthandpotenFalvulnerabiliFeswithinourborders.WiththissituaFonalawareness,countriescanthentakeprevenFveacFontodealwithpotenFalcyberrisksandvulnerabiliFes.Thebe_eracountry’scyberhealth,the“greener”itwillbe.OverFme,CyberGreenwilldeveloprobustcyberhealthmetrics.ThesewillallowpracFFonersandpolicy-makerslikeourselvestoassesshowourcountries,andASEANasawhole,areprogressingonthecybersecurityfront.Cyberincidentresponderscanalsobe_eridenFfyandremediatedifferentclassesofthreats,basedonacFonablethreatinformaFonprovidedbyCyberGreen.14SingaporeisexcitedtobeasponsorofthisglobaliniFaFve.WehavesignedontoCyberGreen,aswerecognisethatASEANMemberStatesincludingourselvescanbenefitfromCyberGreen.Asastart,becauseofoursponsorship,allASEANMemberStateswillbeabletoaccessCyberGreenthroughSingaporeforfree,andgetafirstcutreportonthestateoftheirowncountry’scyberhealthstatus.IwouldliketoinvitefellowASEANMemberStatestocomeonboard,andjoinSingaporeinCyberGreen.Throughthisplaporm,ourcountriescanworktogethertoimproveourcybersituaFonalawareness,sharpenincidentresponse,andthereforesecureASEAN’scommoncyberspace.

Page 25: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

25Copyright©CyberGreen2016AllRightsReserved.

PresidentBarackObamaonwhatAIMeansforNationalSecurity–WIRED

OBAMA:TradiFonally,whenwethinkaboutsecurityandprotecFngourselves,wethinkintermsofarmororwalls.Increasingly,Ifindmyselflookingtomedicineandthinkingaboutviruses,anFbodies.PartofthereasonwhycybersecurityconEnuestobesohardisbecausethethreatisnotabunchoftanksrollingatyoubutawholebunchofsystemsthatmaybevulnerabletoawormgeFnginthere.Itmeansthatwe’vegottothinkdifferentlyaboutoursecurity,makedifferentinvestmentsthatmaynotbeassexybutmayactuallyendupbeingasimportantasanything.

h_ps://www.wired.com/2016/10/president-obama-mit-joi-ito-interview/

WhatIspendalotofFmeworryingaboutarethingslikepandemics.Youcan’tbuildwallsinordertopreventthenextairbornelethalflufromlandingonourshores.Instead,whatweneedtobeabletodoissetupsystemstocreatepublichealthsystemsinallpartsoftheworld,Clicktriggersthattelluswhenweseesomethingemerging,andmakesurewe’vegotquickProtocolsandsystemsthatallowustomakevaccinesalotsmarter.SoifyoutakeapublichealthModel,andyouthinkabouthowwecandealwith,youknow,theproblemsofcybersecurity,alotmayendupbeingreallyhelpfulinthinkingabouttheAIthreats.

Page 26: Improving Cyber Ecosystems Health by Metrics, … CyberGreen Yuri...Future work: Metrics v.3 • Improve Asset Owner Metrics, Create New Vendor Metrics • Analyze who has greater

HelpusfostertheCyberGreenapproach.

Contact:[email protected]