Threat hunting is all about being proactive and looking for signs of compromise that other systems may have missed. As defenders, we want to cut down the time it takes to detect attackers. To accomplish this, we assume the bad guys have penetrated our defenses, and then proceed to look for traces that their activities have left behind.
Putting aside the technical details, it is extremely important to consider the person, or perhaps the team, who is doing the hunting. I describe a good threat hunter as a person with a wide skill set who has “been there and done that” in multiples areas of IT and security. There are four main dimensions that help shape a good hunter:
Curiosity
A threat hunter needs to be patient, highly motivated, and driven by a desire to know more. The person needs to start asking questions such as why in order to understand whatever activity may be under analysis. In order to be able to answer the why, the drive to go deep into the rabbit hole is essential.
Critical thinking
Being able to analyze and solve problems also is important. The hunter must always keep an open mind and be able to consider alternative solutions to the problem. Thinking like an attacker usually helps frame an investigation from a different angle and could be the key to uncovering evil within your systems.
Technical expertise
A wide array of technical knowledge is essential. A person who is an expert in network and knows very little about other disciplines such as forensics, applications, databases, etc., may not be able to see the big picture. Ideally, the hunter has cross-discipline knowledge and knows who to reach out to when more in-depth analysis is required.
Ability to connect the dots
This is one of the most important aspects. Many analysts struggle when presented with multiple sets of information and therefore are unable to connect the dots and put together the puzzle. An efficient hunter should be able to understand the data and its business context, perform the appropriate correlations, and reach conclusions.
Professionals with this sort of talent and skill are scarce. Remember that in many cases it makes perfect sense to develop hunting talent in-house. An employee who has worked in a few IT or information security disciplines who knows your business brings great value to the table. Look around and see who is up to the challenge.
Editor’s note:Roger O’Farril will be presenting further insights on this topic at ISACA’s CSX North America conference, to take place 15-17 October in Las Vegas, Nevada, USA.
Roger O’Farril, Information Security Team Lead, Federal Reserve Bank of Chicago
Threat hunting is all about being proactive and looking for signs of compromise that other systems may have missed. As defenders, we want to cut down the time it takes to detect attackers. To accomplish this, we assume the bad guys have penetrated our defenses, and then proceed to look for traces that their activities have left behind.
Putting aside the technical details, it is extremely important to consider the person, or perhaps the team, who is doing the hunting. I describe a good threat hunter as a person with a wide skill set who has “been there and done that” in multiples areas of IT and security. There are four main dimensions that help shape a good hunter:
Curiosity
A threat hunter needs to be patient, highly motivated, and driven by a desire to know more. The person needs to start asking questions such as why in order to understand whatever activity may be under analysis. In order to be able to answer the why, the drive to go deep into the rabbit hole is essential.
Critical thinking
Being able to analyze and solve problems also is important. The hunter must always keep an open mind and be able to consider alternative solutions to the problem. Thinking like an attacker usually helps frame an investigation from a different angle and could be the key to uncovering evil within your systems.
Technical expertise
A wide array of technical knowledge is essential. A person who is an expert in network and knows very little about other disciplines such as forensics, applications, databases, etc., may not be able to see the big picture. Ideally, the hunter has cross-discipline knowledge and knows who to reach out to when more in-depth analysis is required.
Ability to connect the dots
This is one of the most important aspects. Many analysts struggle when presented with multiple sets of information and therefore are unable to connect the dots and put together the puzzle. An efficient hunter should be able to understand the data and its business context, perform the appropriate correlations, and reach conclusions.
Professionals with this sort of talent and skill are scarce. Remember that in many cases it makes perfect sense to develop hunting talent in-house. An employee who has worked in a few IT or information security disciplines who knows your business brings great value to the table. Look around and see who is up to the challenge.
Editor’s note:Roger O’Farril will be presenting further insights on this topic at ISACA’s CSX North America conference, to take place 15-17 October in Las Vegas, Nevada, USA.
Roger O’Farril, Information Security Team Lead, Federal Reserve Bank of Chicago
KUALA LUMPUR, MALAYSIA – August 20, 2018 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, and Malaysia Digital Economy Corporation (MDEC) today released the results of a joint survey, Cloud Adoption in the Malaysia FSI Sector, which surveyed IT and security professionals in Malaysia’s FSI about their cloud service adoption plans and priorities. The results were announced in Kuala Lumpur at the inaugural CSA Malaysia Summit, where Dato’ Ng Wan Peng, COO of MDEC; Jim Reavis, co-founder & CEO of CSA; and Ramesh Narayanaswamy, CIOO of CIMB Group Holdings were among the keynote speakers.
As a part of the Summit, CSA also organized a Roundtable on “Banking 4.0 – Digital Transformation, Opportunities & Challenges” aimed to work on the next level study of the survey conducted. This Roundtable was sponsored by Microsoft.
Although heavily regulated internationally, today’s financial services institutions (FSI) face similar pressures experienced by their compatriots in lesser-regulated sectors. There is an urgent need to embrace digital transformation to leapfrog competitors, enhance agility, and increase efficiency to better serve the modern digital consumer in this fast-paced economy. Significantly higher confidence levels in cloud security today have rendered the cloud a key enabler in overcoming these challenges. Seeing this trend, CSA and MDEC jointly conducted the “Cloud Adoption in the Malaysia FSI Sector” survey to gain a deeper understanding of the current and future state of cloud adoption in the region.
“Besides raising awareness of cloud adoption in the FSI sector, the survey also aimed to uncover obstacles that may have impeded cloud adoption by the banking sector within Malaysia,” said Dr. Lee Hing-Yan, Executive Vice President, CSA Asia Pacific. “Although separate studies have shown that the Malaysian government has done well in putting strong e-government plans in place, the government can further accelerate cloud adoption by introducing progressive guidelines. The increased clarity will help FSIs to continue reaping the benefits of cloud, while maintaining adherence to regulations.”
MDEC’s Director/Enabling Ecosystem Wan Murdani Wan Mohamad, Ir, commented:
“Malaysia’s shift towards becoming a developed, sustainable digital economy requires the transformative use of a secure and robust cloud ecosystem. As indicated by the study, a vital aspect of Malaysia’s transformation encompasses successful cloud adoption, which means that we must prioritise the future-proofing of our cybersecurity sector as an important aspect of our drive to build on the growth of cloud adoption by the FSI and, indeed, all sectors of our economy.”
The report published key findings in the areas of cloud adoption, IT security budgets, cloud computing, and cyber security skills, as well as cloud service compliance and regulations. Among the main findings:
Sixty five percent (64.7 %) of the FSI in Malaysia said they are developing a cloud strategy, while 17.6 percent have already developed a cloud strategy. The remaining 17.6 percent have a strict no-cloud policy.
Twenty four percent (23.5 %) of respondents mentioned that no cloud service data security and compliance regulations are predetermined in their organization, while 11.7 percent mentioned that their organizations have some form of cloud service data security and compliance management.
The majority of the survey respondents pay considerable attention to international standards when selecting a cloud service provider (CSP). This suggests that certification should be an important benchmark for CSPs as a measure and demonstration of their compliance with industry standards.
Fifty three percent (52.9%) of the respondents said that the top cloud threat in their organization is the lack of security assessments on cloud services provided by CSPs. In other words, there is a lack of necessary knowledge to properly address the challenges, with some being unaware even when these threats occur.
Due to the lack of commitment at the senior level, 58.8 percent of all cloud computing and cybersecurity professionals indicated they have never participated in nor organized any cloud application development or cloud-security-related training.
“We would like to thank MDEC for their ongoing support and contributions to this survey and to our broader efforts to understand and educate the market on cloud adoption in APAC,” added Dr. Lee.
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security- specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem.
Cybersecurity continues to grab spotlight and mindshare as it pertains to computing and social trends.
The topic itself is broad and expansive, and the true impact of this segment of computing will be around for generations to come. For strong perspective on where the industry stands in its current state, ISACA’s State of Cybersecurity 2018 research is a must-read. This report provides a great assessment of what needs to happen in the cybersecurity field to move from reactive to proactive.
Challenges around cybersecurity are not new and have actually been around since the dawn of computing. However, it is now a topic that everyone talks about. It is a board topic, it is a public safety and livelihood topic, and it is a personal topic. Hitting this trifecta of impact has finally created the sense of urgency and the attention that is needed. Now, the key is that as an industry, as a country, and as a world of over 7 billion people, we need to effectively address these industry challenges to preserve the computing environment for the future.
Today, most cybersecurity efforts are focused on what is referred to as the “EMR” model of educate, monitor, and remediate. This approach is effective but is essentially like the game of “whack-a-mole,” where the core underlying risks and issues are never solved and keep popping up.
So, how does the governing of cybersecurity become proactive?
While EMR is essential, the core foundation of a more secure and trustworthy computing experience requires being more proactive. Proactive means ongoing, real-time, continuous self-testing and self-assessment, and a laser focus on education as it pertains to best practices. This, combined with a continued evolution on the new SaaS (security-as-a-service), will help mitigate and ensure more trust in the future. Still, it will be very difficult to solve all cybersecurity challenges due to the technical debt that exists and will exist for the immediate future.
Safe and secure computing can occur with a connected, comprehensive approach to security embedded in each of the leading digital disruption levers, from the Internet of Things, to conversational artificial intelligence, to blockchain and distributed ledger technology, to wearables and mobility. Industry focus, industry standards, close adherence to best practices, and the constant ability to randomize to protect digital identities is on the horizon and needs to continue to gain acceleration.
However, first and foremost, security best practices begin at the code level. As software engineers and as an innovation industry, we must make sure this is well-executed in each and every opportunity we have.
Author’s note:Mike Wons is the former CTO for the state of Illinois and is now serving as Chief Client Officer for Kansas City, Missouri-based PayIt. Mike can be reached at mwons@payitgov.com
While artificial intelligence and machine learning deployment are on the rise – and generating plenty of buzz along the way – organizations face difficult decisions about how, where and when to introduce AI.
In a session Tuesday at the 2018 GRC Conference in Nashville, Tennessee, USA, co-presenters Kirsten Lloyd and Josh Elliot laid out many of the ethical considerations that should be part of those deliberations.
The pair detailed several instances of high-profile AI events over the past decade that highlighted the need to give ethical components of AI deployment a high level of focus early in a product or service’s design, as opposed to risking unforeseen fallout. The examples included the development of a controversial algorithm that predicted higher rates of recidivism for black defendants in the judicial system and a Stanford University study exploring how often AI could determine a person’s sexual orientation based on photos of their faces.
Yet, for all of the questionable or even potentially malicious use cases of AI, Lloyd and Eliot highlighted an extensive list of powerfully compelling uses for AI, such as advancing new medical treatments, preventing cyber attacks, improving energy efficiency and increasing crop yields. Elliot, Booz Allen Hamilton’s director of artificial intelligence, noted that AI also may prove transformative in missing person crises, such as being able to swiftly locate missing children in AMBER Alert child abductions.
Whether the potential ethical implications of AI and machine learning outweigh the good that can be accomplished is very much a case-by-case judgment call, Elliot said, requiring a holistic evaluation of the possible outcomes through a risk management lens. Successful, ethical implementation of AI and machine learning also call for strong governance, with emphasis on benefits realization, risk optimization and resource optimization. Elliot and Lloyd said organizations should identify and engage key stakeholders in AI projects, including the creation of an ethical review board and a chief ethics officer. Some high-impact deployments might also require direct access to the C-Suite for input on risk considerations.
Elliot and Lloyd suggested that organizations consider the following questions when deciding how they might want to deploy AI and machine learning:
What are our goals?
How much risk are we willing to tolerate?
What is the state of our data assets?
What talent assets do we have?
What are our values?
From a people talent standpoint, Elliot noted there is a serious shortage of professionals with the expertise to help enterprises effectively and securely implement AI and machine learning, causing many organizations to turn to the ranks of academia and research to fill in the personnel gaps. Lloyd, an AI strategist with Booz Allen Hamilton, acknowledged the workforce worries many harbor regarding the potential for AI and machine learning to displace large numbers of practitioners, but said that there will remain an enduring need for humans’ critical thinking skills, while machines continue to introduce process improvements in computational thinking.
Taking the long view, Elliot and Lloyd said AI and related disciplines have transitioned from their previous state of simple task execution to the current era of pattern recognition, with a future that will be reshaped by added capabilities of contextual reasoning. Elliot said many of today’s common uses, such as robotic process automation (RPA), are a mere “gateway drug” to more sophisticated technologies and applications that are being aggressively researched in Silicon Valley and beyond.