{"id":35629,"date":"2019-06-19T12:21:36","date_gmt":"2019-06-19T04:21:36","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=35629"},"modified":"2019-06-19T12:21:38","modified_gmt":"2019-06-19T04:21:38","slug":"what-will-drive-cyber-security-hacking-crime-warfare-and-or-terrorism","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/06\/19\/what-will-drive-cyber-security-hacking-crime-warfare-and-or-terrorism\/","title":{"rendered":"What will drive cyber security: Hacking, crime, warfare and\/or terrorism?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong><em>By Lionel Snell<br>Editor, NetEvents<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>At first it seems a logical question: understand the enemy and you will understand the threat. If the threat is cyberwar, then military and armaments organizations are an obvious target. If it is cybercrime, then financial institutions should be concerned. If it is hacktivism, then any company with considered malicious by a significant portion of the public should be alert for attacks by campaigners.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But on second thoughts, the scene becomes far more confused. An attack on the national electricity grid could severely compromise military suppliers. One that caused traffic chaos could make it harder for an enemy to mobilise ground forces. Financial companies are already heavily guarded, so it is far easier for criminals to make money by blackmailing hospitals with stolen data. Hacking has always been an irritant, if not a major problem, because the motives can be so arbitrary \u2013 maybe an institution was hacked for no other reason than that it claimed to be unhackable? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the case of hacktivism against a broad target like the present government, then any attack that disrupts the economy or draws attention to the cause could be an effective weapon when followed by a public announcement. Terrorism is similarly almost impossible to predict because the aim is to do absolutely anything that might invoke public terror \u2013 and that makes it highly threatening. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Joel Stradling, Research Director for the analyst company GlobalData, chairing a recent NetEvents session, mentioned a call for half a million heart pacemakers in the US to be recalled because of vulnerability to cyberterrorism. That is a very good example, because any family or group with a heart patient that might drop dead will feel threatened, and that fear generates panic that could spread far and wide. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also raises another key point about cyberterrorism: that the threat can be more effective than the actual attack. Terrorists know that a failed bomb attack can be just as effective as a successful one, because the public starts thinking about all the deaths that might have happened.   Terrorist groups have far broader agendas than before, going beyond physically harming civilians.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ray Ottey, Fellow Cybersecurity Practitioner at Verizon, responding to Joel Stradling, described two distinct areas: cyberwar is really just another weapon in the evolution of war, while cyberterrorism has a different motive: \u201cIt&#8217;s a subset of the wider threat, but it&#8217;s just coming with a different motive. There&#8217;s no different toolset, and it&#8217;s not in some cases different people either. So, it can be the same person during the day being a hacker, or having a normal day job, and by evening a gun to hire\u201d.   Attacks may have different political or criminal aims, but the symptoms are the same.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Internet of Things (IoT) adds a major terrorism threat because it brings what was seen as information war down to physical manifestation \u2013 like a compromised pacemaker causing a friend to drop dead. A loss of data is one thing, but if it compromises an entire electricity network or water supply, then you have terror potential. Another factor is that it suddenly extends what has become a pretty well secured IT network by added a mass of far less secure endpoints previously air-gapped from the Internet. As Roark Pollock, Chief Marketing Officer, Ziften Technologies put it: \u201cYou&#8217;re trying to protect a network that&#8217;s very different than your IT infrastructure. From a security standpoint it\u2019s 20 years behind traditional IT. We&#8217;ve integrated those devices into our traditional IT networks, so they become a big part of what you&#8217;re trying to protect now, as opposed to just trying to protect the underlying data\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Optiv\u2019s European Director of Strategy and Technology, Andrzej Kawalec, explained: \u201cIoT is going to completely explode it, and it forces us to think about devices again \u2013 which is something we&#8217;ve forgot about for a while. We need to start doing that again\u2026 To create physical safety implications on a network, you used to have to have quite specific deep domain capability\u2026 the integrated industrial cybercriminal global network allows you to do anything, whether it&#8217;s malware as a service, ransomware as a service, being attacked by swarms of kettles\u201d \u2013 a reference to the story that the UK company Hargreaves Lansdown was attacked by a botnet of smart kettles last year.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another factor that blurs the boundaries is the way that cybercrime and drug cartels provide funding for terrorism. IT can also be misused for recruitment and propaganda \u2013 as it was recently in New Zealand to amplify the impact of an isolated terrorist incident. Kawalec pointed out that cybercrime had overtaken the global illegal drugs trade: \u201cNational crime agency in the UK moved drugs off their top three focus areas, and put online fraud and cybercrime on. I think there&#8217;s a lot in there to be unpacked, but I think it&#8217;s actually about digital world influencing cyberterrorism, rather than cyberterrorism influencing the digital world\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kawalec concluded: \u201cIf there&#8217;s anything, it&#8217;s going to make us focus on the safety component of cybersecurity, rather than the confidentiality, the integrity, the financial impact. It&#8217;s the human implication of hacking into an autonomous car via the DAB radio to turn the brakes off. Who thought that was going to be a thing, but it is.\u201d Roark Pollock agreed that the IT fundamentals had not changed as much as the motives for attack. And with IIoT the user is no longer only an office working with years of PC experience: \u201cAs we talk about industrial terrorism we&#8217;re bringing in a whole new user group. Now you&#8217;re talking about a user in some industrial facility, managing the safety and reliability of its devices. That person is not used to talking about cybersecurity\u201d. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Joe Baguley, VMware\u2019s VP and CTO for EMEA: \u201cThe biggest problem is IT meeting OT. I\u2019m seeing fundamental failings in basic principles of security when we get to IT and OT\u201d. He gave the example of ubiquitous security cameras: \u201cI found cheap USB ones of which there is no patching model and no way to update them. It&#8217;s just people missing basic fundamental steps in deploying IoT systems. That will set us up for massive failure in the future\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ray Ottey pointed out that security for the new users Pollock mentioned was about physical, not cyber, security: \u201cSo that MRI scanning machine, or that nuclear control system, whatever it was, the security around that was all entirely physical \u2013 you can&#8217;t get into it, can&#8217;t touch it \u2013 security badges etc\u201d He outlined a scenario where the industrial control manager is approached by a the new network manager and says: \u201cSo you want to try and connect your IT systems to my control system? But you are the guys that gave me that XP laptop riddled with viruses that never really worked, and you&#8217;re now telling me you want to try and connect to my OT system? Get stuffed!\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adding a more positive note, Roark said: \u201cIt&#8217;s taken us 20 odd years to get to today\u2019s security perspective. At least we now have mature frameworks we can start to apply to those industrial control networks, whether the NIST framework, or any other framework\u201d. Hopefully we can implement these existing frameworks a lot quicker than it had taken to develop them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Joe Baguley returned to the prevention theme and the principles of cyber hygeine that are so blindingly obvious to people in the security industry, but not to others: \u201cThings like least privilege, micro segmentation, and encryption. Encryption 10 years ago was a horrible thing, because it was hard. Now it&#8217;s really easy and it&#8217;s not a burden on processors, so let&#8217;s just do it everywhere. Multifactor authentication: Tesla owners are crying out for multifactor authentication on their cars \u2013 even Tesla aren&#8217;t applying it now \u2013 and patching. People are deploying stuff and not thinking about the ongoing lifecycle management\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Questions from the floor brought the discussion back to the specific issue of cyber terrorism, when the panel was trying more to focus on general prevention. Joe Baguley referred to the Spectre processor issues: \u201cHow long had certain nation states known that those vulnerabilities were there, and kept it to themselves, before the wider world found out? You know, it&#8217;s those kind of things were actually more worrying\u2026 We&#8217;re looking again at how do you build a layer on top of that, that almost abstracts you from that threat?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Andrzej Kawalec said the whole issue is even more blurred when several cybercriminal gangs share malware using an existing vulnerability hijacked through another service to some industrial ecosystem. Hence the need to focus on the continuous hunting and analysis of threat: \u201cYou need to go back to what you can control best.\u201d Baguley agreed that there can be too much trying to anticipate what the next big threat is going to be, rather than just going back to base and how the system is built and made rock solid. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Ray Ottey part of the problem is that people often do not even know they are under attack: \u201cA process running a bit longer every day, because it&#8217;s doing something else. A machine occasionally pinging some other machine, which isn&#8217;t necessarily out of the ordinary\u2026 and many organisations don&#8217;t know what their normal is\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Roark Pollock had the final word in what was a great debate session. He suggested a gaming approach to security training: \u201cThese companies need to create some sort of cyber range, where they can play red team, blue team, and train their people, of how to respond when something does occur. Because it&#8217;s too late once it happens\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"text-align:center\"><em>The transcript of the entire discussion is available at <\/em><a href=\"https:\/\/www.netevents.org\/wp-content\/uploads\/2019\/01\/Debate-I-CyberSecurity-GlobalData-final.pdf\"><em>https:\/\/www.netevents.org\/wp-content\/uploads\/2019\/01\/Debate-I-CyberSecurity-GlobalData-final.pdf<\/em><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A panel discussion on cyber terrorism opened up a wide range of vital security issues.<\/p>\n","protected":false},"author":7,"featured_media":35630,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[1481,54],"class_list":["post-35629","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-cybersecurity","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35629","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=35629"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/35629\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/35630"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=35629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=35629"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=35629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}