51
CLOUD SUPER SECURE Per Cochrane formicio.com Thursday, 12 July 12

Super Secure Cloud

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Super Secure Cloud

CLOUD

S U P E RSECURE

Peter Cochraneformicio.com

Thursday, 12 July 12

Page 2: Super Secure Cloud

Security is always a cat and mouse game...

Thursday, 12 July 12

Page 3: Super Secure Cloud

And we are always trying to tilt the odds in our favour...

Thursday, 12 July 12

Page 4: Super Secure Cloud

But we cannot leave anything to chance, we cannot afford to gamble, the stakes are far too high..

Thursday, 12 July 12

Page 5: Super Secure Cloud

We have to think like the enemy, war game, test and probe, & constantly keep ahead technically and strategically...

Thursday, 12 July 12

Page 6: Super Secure Cloud

1) There is always a threat

2) It is always in a direction you’re not looking

3) Perceived risk/threat never equals reality

4) Nothing is 100% secure

5) People are always the primary risk

6) Resources are deployed inversely proportional to actual risk

Laws of security...

Thursday, 12 July 12

Page 7: Super Secure Cloud

Laws of security...

7) You need two security groups - defenders & attackers

8) Security & operational requirements are mutually exclusive

9) Legislation is always > X years behind

10) Security standards are an oxymoron

11) Security people are never their own customer

12) Cracking systems is far more fun than defending them

Thursday, 12 July 12

Page 8: Super Secure Cloud

Laws of security...

13) Hackers are smarter than you - they are younger!

14) Hackers are not the biggest threat - governments are!

15) As life becomes faster it becomes less secure

16) Connectivity and data half lives are getting shorter too

17) We are most at risk during a time of transition

18) The weakest link generally defines the outcome

Thursday, 12 July 12

Page 9: Super Secure Cloud

If we continue to do what we’ve always done our Cloud exposure will accelerate..

Thursday, 12 July 12

Page 10: Super Secure Cloud

In The Cloud - the attack surface is the entire planet...

Thursday, 12 July 12

Page 11: Super Secure Cloud

We w i l l n e e d more and smarter firewalls...

Thursday, 12 July 12

Page 12: Super Secure Cloud

All forms of malware protection will have to become evolutionary...

Thursday, 12 July 12

Page 13: Super Secure Cloud

Has to become far more sophisticated...

Thursday, 12 July 12

Page 14: Super Secure Cloud

Enhancing login vectors...Something you:

- Do- Are- Know- Possess- Deduce- Relate to- Recognise- Remember- Understand

A concatenation of weak vectors rapidly becomes very strong...

Thursday, 12 July 12

Page 15: Super Secure Cloud

Concatenating numerous low cost biometrics is a good example...

- Eye- Face- Hand- Voice- Typing- Habits- Devices- Locations- ++++

Thursday, 12 July 12

Page 16: Super Secure Cloud

Automated & stronger encryption...

...but only where needed !Thursday, 12 July 12

Page 17: Super Secure Cloud

More anonymity applications...

Thursday, 12 July 12

Page 18: Super Secure Cloud

More url hopping, identity, & location cloaking applications...

Thursday, 12 July 12

Page 19: Super Secure Cloud

What does The Cloud offer beyond all this ?

Thursday, 12 July 12

Page 20: Super Secure Cloud

So what are the extras The Cloud brings to the party ?

It will destroy dominant mono-cultures of:- Devices- Browsers- eMail clients- Application sets- Operating modes- Operating systems

Hackers love mono-cultures - it makes their lives so very

much easier...

Thursday, 12 July 12

Page 21: Super Secure Cloud

More variety, dynamism, and faster change...

Thursday, 12 July 12

Page 22: Super Secure Cloud

Clouds of all sizes will form and dissipate by demand . . .w i t h t h e clustering of people and devices +++

Thursday, 12 July 12

Page 23: Super Secure Cloud

Connectivity will be less static, comms between Clouds sporadic and far more varied...

Movie

Thursday, 12 July 12

Page 24: Super Secure Cloud

Moving targets are very hard to hit

Thursday, 12 July 12

Page 25: Super Secure Cloud

Thin clients offer very limited processing and memory, making it far harder for malware to be effective...

Thursday, 12 July 12

Page 26: Super Secure Cloud

Cloud services now a v a i l a b l e f r o m multiple suppliers...

- Infrastructure- Platform- Software

Thursday, 12 July 12

Page 27: Super Secure Cloud

Use multiple suppliers for connectivity, apps, storage, security et al and employ in a randomised fashion...

Thursday, 12 July 12

Page 28: Super Secure Cloud

...seamlessly flip between devices...Thursday, 12 July 12

Page 29: Super Secure Cloud

Why

Thursday, 12 July 12

Page 30: Super Secure Cloud

To make it incredibly difficult for the dark side:

- No single log-on device- No single log-on location- Variable log-on routine- Distributed applications- Distributed filing system- Parsed and distributed data- Multiple clouds and providers- Dynamic creation of clouds- Dynamic cloud interconnection- Inter-cloud encryption and coding- Corporate strength security for all

Thursday, 12 July 12

Page 31: Super Secure Cloud

App

App App

App

App Storage

Storage Corporate

Corporate

Corporate

Personal Personal Storage

One of manyConnection

Clouds

SurroundedBy

Clouds

Thursday, 12 July 12

Page 32: Super Secure Cloud

Parsed data flows to/frommultiple destinations...

...are incredibly difficult to intercept and decode...

Thursday, 12 July 12

Page 33: Super Secure Cloud

Parsed, encrypted & distributed folders over multiple global ser vers . . . i s even harder!

Thursday, 12 July 12

Page 34: Super Secure Cloud

Parsed, encrypted and distributed data folders over multiple global servers...is even worse!

The biggest threat is still people laxity and the insider...

Thursday, 12 July 12

Page 35: Super Secure Cloud

Behavioural monitoring and analysis will become an essential cloud service for SMEs, corporations & .gov...

Thursday, 12 July 12

Page 36: Super Secure Cloud

Half lives of connections, data, info and knowledge...are going to get much shorter!

Thursday, 12 July 12

Page 37: Super Secure Cloud

We have toreduce theopportunityand the time available forThe Dark Sideto infiltrate and take action...

Thursday, 12 July 12

Page 38: Super Secure Cloud

And should they break in we confront them with partial access and a very confusing picture...

Which door to choose, and to which cloud, for how long, with access to what ?

Thursday, 12 July 12

Page 39: Super Secure Cloud

How many layers, combinations,connections, locks,types ?

How long will they be open,

and what is in each of the many clouds ?

Thursday, 12 July 12

Page 40: Super Secure Cloud

The Dark S i d e w i l l thus have far less time to infiltrate a n d t a k e action...

The day of the lone hacker is coming to an end...

Thursday, 12 July 12

Page 41: Super Secure Cloud

The New Dark Side are gov agencies and criminal organisations with huge budgets, people & tech resources...

Thursday, 12 July 12

Page 42: Super Secure Cloud

The sophistication of StuxNet and Flame surprised industry and governments .. .and they mark the start of a new era...

Thursday, 12 July 12

Page 43: Super Secure Cloud

We may be transiting to‘Cyber Warfare’...

Thursday, 12 July 12

Page 44: Super Secure Cloud

Fending off such threats

demands more capability

than individual corps can

muster

Thursday, 12 July 12

Page 45: Super Secure Cloud

Global cooperation will be required, to develop military grade solutions ...

Thursday, 12 July 12

Page 46: Super Secure Cloud

To survive and prosper we have to think and act differently whilst leverag ing new technology, and techniques...

Thursday, 12 July 12

Page 47: Super Secure Cloud

The DIYcompanies

will not survive...

Thursday, 12 July 12

Page 48: Super Secure Cloud

Malware is now open code for free or a modest price f r o m m u l t i p l e sources...

...it is also breeding by the hand of man and by a digital life force we created...

Thursday, 12 July 12

Page 49: Super Secure Cloud

The Art of War by Sun Tzu, 600 BC

“Speed is the essence of war. Take advantage of the enemy's unpreparedness ; t rave l by unexpected routes and strike him where he has taken no precautions”

Thursday, 12 July 12

Page 50: Super Secure Cloud

Be prepared !Thursday, 12 July 12

Page 51: Super Secure Cloud

Thank You

formicio.com

Thursday, 12 July 12