60
CYBER SECURITY Sanjay Sahay The biggest emerging threat!

Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Embed Size (px)

Citation preview

Page 1: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

CYBER SECURITY

Sanjay Sahay

The biggest emerging threat!

Page 2: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

How big is this

bubble?

Page 3: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Chronology of Computerization

1994: CCIS

2005: G-CARE

2008: e-Beat

2009: KSP WAN

2010: 'Police IT'

2011: KSP DC

2012: CCTNS

2014: DRC

2015: Private Cloud

Page 4: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

NetworkData

Center

Training for 75

System Administ-

rators

Creation of Skilled Internal

Resource pool

Training for End-

Users

Police IT ERP

Gover-nance

Structure

Enforce-ment

Stabiliza-tion

Police-IT Ecosystem Development

Page 5: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Police IT ERP Application

MIS417Reports

64Roles

Core Function-alities

• Crime• Law & Order• Traffic

Admin-istration

• Administration• Finance• Stores

Ancillary support

• Armed Reserve• Motor Transport• Training

Technical Modules

• Wireless• Forensic Science • Laboratory

522Screens

11Modules

Page 6: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Architecture Diagram of KSPWAN

Page 7: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

DIGITAL INDIA IS

The transformational enablement of

1. Governance

2. Citizen Services and

3. Ease of business using…

…ICT in the creation of

• digital infrastructure (technological and human), competent enough to enable

• dynamic and

• real time decision making

• and service delivery

• with seamless backend processes and

• creation of databases and its integration at differential levels

catering to all requirements of the nation

Page 8: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

DEDICATED CLOUD INFRASTRUCTURE

DIGITAL INDIA

Page 9: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

PARAMETERS AND MEASUREMENTS

VISION TO WORKABLE DOCUMENTS

THE WHEREWITHAL

SECTOR WISE

PHASE WISEBLUEPRINT

GAPANALYSIS

BRIDGING

LONG LASTING PUBLIC PRIVATE PARTNERSHIPS

VISIONARY DOCUMENTATION

TRUST

SECURITY

DIGITAL INDIA

Page 10: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

IN THE LAST FEW MONTHS..,

• Sony & Anthem attacks

• Chinese breach data of 4 million federal workers

• Obama seeks $14 billion to boost U.S. cybersecurity defenses

• Obama Calls on US Firms to Help Fight Cyberattacks

• Obama signed an executive order laying out a framework for companies to share data about cyber threats with each other and the government

• New agency to sniff out threats in cyberspace - Cyber Threat Intelligence Integration Center

Page 11: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Zero-Day Flaw Found in 'Linux Kernel' leaves Millions

Vulnerable

US Intelligence Chief Hacked by the Teen Who Hacked CIA

Director

602 Gbps! This May Have Been the Largest DDoS Attack in

History

Hacking News

Page 12: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

After Paris Attacks, Encrypted

Communication Is Back In Spotlight

"the ISIS geek squad is teaching terrorists how

to use encryption and communication

platforms like Silent Circle, Telegram and

WhatsApp."

Page 13: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

A HACKER who claims to have broken into the AOL

account of CIA Director John Brennan says he

obtained access by posing as a Verizon worker to trick another employee into revealing the spy chief’s personal information.

Page 14: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

The country which built a Digital Iron Dome, Israel had undergone one of the largest serious cyber attack this year.

This time, the name of Israel is being popped up in the current headlines is for the massive cyber attack which triggered against the Nation's Electrical Power Grid.

Page 15: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Someone Just Leaked Hard-Coded Password Backdoor for Fortinet Firewalls

Anyone with "Fortimanager_Access" username and a hashed version of the "FGTAbc11*xy+Qqz27" password string, which is hard coded into the firewall, can login into Fortinet's FortiGate firewall networking equipment

Page 16: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Juniper Firewalls with ScreenOS Backdoored Since 2012

Juniper Networks has announced that it has discovered "unauthorized code"in ScreenOS, the operating system for its NetScreen firewalls

Date back to at least 2012

Allows anyone to decrypt VPN traffic

Page 17: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Ridiculous Bug in Trend Micro Antivirus Allows

Hackers to Steal all Your Passwords

Product that allow hackers to execute arbitrary commands

remotely as well as steal your saved password from Password

Manager built into its AntiVirus program

Page 18: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

FORTUNE 500 COMPANIES

97% HAS BEEN HACKED!

Page 19: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

“If builders built buildings the way programmers wrote programs, then the first woodpecker that came along would destroy civilization.”

-Weinberg's Second Law

Page 20: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

LinearVs

Exponential

Page 21: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

from pace maker to nuclear

power plants

from text documents to the hybrid cloud

Page 22: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Internet of things!

Global Information GridA very vulnerable one!

Page 23: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

DATAis at the center of our universe

Page 24: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Resilience

What the System Ought to Provide

Page 25: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police
Page 26: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Curiosity

Monetary Gain

National Security

Espionage,Political Activism

The sophistication of cyber threats, attackers and motives is rapidly escalating.

Motive

1995 – 20051st Decade of the Commercial Internet

Revenge

Script-kiddies or hackers using tools, web-based “how-to’s”

Insiders, using inside information

Organized Crime, Hackers and Crackers using sophisticated tools

Competitors, Hacktivists

Nation-state Actors; Targeted Attacks / Advanced Persistent Threat

2005 – 20152nd Decade of the Commercial Internet

Adversary

*X-Force Research - 2013

March 10, 2016 26

Page 27: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

WORLD AT CROSSROADS…Internal Security

External

Security

Counter

Terrorism

Rogue States

Cyber War

Money

Laundering

Underworld

Underground

Economy

Naxalism

Data Brokers

Hacktivists

Page 28: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

WORLD AT CROSSROADS…

And the IT companies themselves!!!

Privacy has no meaning

More data, more money!

Everything for a price

Page 29: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police
Page 30: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Access Control Policy

Page 31: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Access Control Policy

Page 32: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Ubiquitous Surveillance Military - Internet Complex

Page 33: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

“The corrupt fear us. The honest support us. The heroic join us.”

Page 34: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

I

S

I

S

V

S

Page 35: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

The Malware Story Criminals & Virus writers outinnovating and

outmaneuvering the anti-virus industry

First information

Detection rate

“time – to – detection rate”

“out of their leagues in their own game”

Page 36: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Precision is the key

Outstanding Coding and Testing

Absolute Game Changer

Page 37: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

One of its kind

Who will take a call?

Page 38: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Zero Dayat the heart of it all

Page 39: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Asymmetric Warfare – A new form

2009 Iraq-$45 billion drone and satellite surveillance system

Skygrabber-$25.95

The costing

Page 40: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Cloud The most happening place

How secure are we?Sanjay Sahay

Page 41: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

CLOUD COMPUTING

Results of IDC survey ranks Security 74.6% as the biggest challenge

Page 42: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

WEAKEST LINK

the human factor

Page 43: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Where should you start?These three controls can help you address the top vulnerabilities

and begin to reduce risk.

Build a

risk-aware

culture

Protect the

network &

end-points

Automate security

hygiene & manage

incidents with

intelligence

Page 44: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police
Page 45: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

The Dark Net, The Secret Web, The Digital Underground, The Invisible Internet

Page 46: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

The Internet provides a delivery system for the pathological states of mind

Page 47: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Blatant

Is there a desire to control?

Is there a mechanism in place?

Page 48: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Crime Inc.

Page 49: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Crime as a service!Payment mechanism in place!

Page 50: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Information Sharing!

Page 51: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Data Brokers

Page 52: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

UNDERGROUND ONLINE MARKETS

Page 53: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

What we buy?

What we use?

What we know?

Page 54: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

The Issues The hardware The software Networking Data Center Human Resources Standards Uniformity Audit

Page 55: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Cyber Security Public Private Partnership

NSA CIA FBI Homeland Security Booz Allen Hamilton Lockheed Martin Fire Eye, Crowd Source, Mandiant Raytheon And large number of IT companies globally

Page 56: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Asymmetric Warfare – A new form

This is a battle of knowledge, effort, focus and precision

Govt’s glacial age response and MNCs blindfolded commercial focus is not the answer

Page 57: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Foster information security without trying to fight the internet architecture

the way forward

Page 58: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

There’s no reason

that the good guys can’t be the same !!!.

The bad guys are smart, well equipped, and determined.

Page 59: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

the way forward

A seamlessly connected, data driven and digitally serviced India is also more vulnerable Digital India. If recent history is to go by the cyber security landscape is worsening by the day. Security ought to be a design element and creating a risk aware culture will facilitate in achieving Digital India with confidence. Adoption of technology is directly proportional of the comfort levels it provides with least risks. This is the way forward.

Page 60: Cyber Security - Sanjay Sahay, Additional Director General, Karnataka Police

Thank you all for the rapt attention!