+ All Categories
Home > Technology > OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

Date post: 10-Jul-2015
Category:
Upload: opendns
View: 7,471 times
Download: 2 times
Share this document with a friend
Popular Tags:
129
1 CONFIDENTIAL Paris, France, November 2014 Dan Hubbard, CTO OpenDNS VizSec 2014
Transcript
Page 1: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

1 CONFIDENTIAL

Paris, France, November 2014 Dan Hubbard, CTO OpenDNS

VizSec 2014

Page 2: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

2 CONFIDENTIAL

Security people have a legacy of being curious.

Page 3: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

3 CONFIDENTIAL

We pull things apart.

Page 4: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

4 CONFIDENTIAL

we break them

Page 5: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

5 CONFIDENTIAL

we explore

Page 6: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

6 CONFIDENTIAL

we discover

Page 7: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

7 CONFIDENTIAL

we defend.

Page 8: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

8 CONFIDENTIAL

We are curious explorers.

Page 9: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

9 CONFIDENTIAL

Turns out curious explorers makes for good defenders.

Page 10: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

10 CONFIDENTIAL

Since the mid 80’s

Page 11: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

11 CONFIDENTIAL

Yes, 30 years now

Page 12: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

12 CONFIDENTIAL

We have been defending through gaining knowledge (samples), exploring them (RCE), and creating vaccines (updates) .

Page 13: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

13 CONFIDENTIAL

As the problem scaled we scaled with more curious explorers.

Page 14: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

14 CONFIDENTIAL

And more…

Page 15: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

15 CONFIDENTIAL

And more…

Page 16: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

16 CONFIDENTIAL

And more…

Page 17: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

17 CONFIDENTIAL

We got to a point where we could not hire enough defenders.

Page 18: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

18 CONFIDENTIAL

So, we automated.

Page 19: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

19 CONFIDENTIAL

Hashes, fingerprints, behavior analysis, sandboxing

Page 20: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

20 CONFIDENTIAL

Then signatures, heuristics, and anomalies.

Page 21: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

21 CONFIDENTIAL

But we still could not scale!

Page 22: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

22 CONFIDENTIAL

And along the way we lost our curiosity and we stopped being explorers.

Page 23: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

23 CONFIDENTIAL

Meanwhile other industries starting understanding the value of data.

Page 24: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

24 CONFIDENTIAL

And the value of large scale compute.

Page 25: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

25 CONFIDENTIAL

The information age started

Page 26: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

26 CONFIDENTIAL

And we created a culture with an unlimited thirst for data.

Page 27: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

27 CONFIDENTIAL

Our appetite for data skyrocketed.

Page 28: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

28 CONFIDENTIAL

And the “Big Data” movement started.

Page 29: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

29 CONFIDENTIAL

Big Data gave us the ability to absorb a massive amount of data and query it with meaningful results.

Page 30: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

30 CONFIDENTIAL

Data helped us solve BIG PROBLEMS.

Page 31: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

31 CONFIDENTIAL

Creating cures for disease.

Page 32: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

32 CONFIDENTIAL

Mapping critical genomes.

Page 33: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

33 CONFIDENTIAL

Predicting natural disasters.

Page 34: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

34 CONFIDENTIAL

The world became a lot different.

Page 35: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

35 CONFIDENTIAL

Google, Facebook, Amazon, Twitter

Page 36: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

36 CONFIDENTIAL

Meanwhile…….

Page 37: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

37 CONFIDENTIAL

Security made incremental attempts at better mousetraps.

Page 38: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

38 CONFIDENTIAL

Whitelisting, HIPS, Containerization.

Page 39: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

39 CONFIDENTIAL

“Next Generation” this.

Page 40: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

40 CONFIDENTIAL

“Cyber Defender” that.

Page 41: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

41 CONFIDENTIAL

Bottom line…

Page 42: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

42 CONFIDENTIAL

We lost pace with technology.

Page 43: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

43 CONFIDENTIAL

Which in turn, left us a long way behind in defending.

Page 44: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

44 CONFIDENTIAL

And we suffer massive decreases in our efficacy.

Page 45: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

45 CONFIDENTIAL

So, lets get back to our roots.

Page 46: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

46 CONFIDENTIAL

Embrace the Big Data movement.

Page 47: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

47 CONFIDENTIAL

Innovate in Security Visualization.

Page 48: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

48 CONFIDENTIAL

And get back to being the curious explorers were are.

Page 49: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

49 CONFIDENTIAL

How ?

Page 50: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

50 CONFIDENTIAL

To start you need some data to explore.

Page 51: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

51 CONFIDENTIAL

More = better

Page 52: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

52 CONFIDENTIAL

Diversity in data is important.

Page 53: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

53 CONFIDENTIAL

Don’t underestimate the ability to query that data!

Page 54: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

54 CONFIDENTIAL

Remove all data silos.

Page 55: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

55 CONFIDENTIAL

API’s are critical.

Page 56: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

56 CONFIDENTIAL

Science and Art come together.

Page 57: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

57 CONFIDENTIAL

Security Visualization Today

Page 58: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

58 CONFIDENTIAL

We have made some progress in 2D Security Viz.

Page 59: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

59 CONFIDENTIAL

Examples.

Page 60: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

60 CONFIDENTIAL

Red October Infrastructure

Page 61: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

61 CONFIDENTIAL

SEA: Twitter, Huffington Post, NY Times Hijack

Page 62: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

62 CONFIDENTIAL

Moneypak 1

Page 63: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

63 CONFIDENTIAL

Moneypak 2

Page 64: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

64 CONFIDENTIAL

Kelhios

Page 65: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

65 CONFIDENTIAL

Customer Botnet Connections

Page 66: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

66 CONFIDENTIAL

Clusters of Algorithmic Scores

Page 67: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

67 CONFIDENTIAL

Image are great because they tell a story.

Page 68: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

68 CONFIDENTIAL

But its at best a short story.

Page 69: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

69 CONFIDENTIAL

Its actually more like a magazine than a book

Page 70: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

70 CONFIDENTIAL

Image sequences.

Page 71: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

71 CONFIDENTIAL

Page 72: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

72 CONFIDENTIAL

This is OK, but it limits our exploration capabilities.

Page 73: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

73 CONFIDENTIAL

So we can add context to the visuals.

Page 74: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

74 CONFIDENTIAL

Page 75: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

75 CONFIDENTIAL

This is a LOT better than “flat” images.

Page 76: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

76 CONFIDENTIAL

Helps tell a more complete story.

Page 77: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

77 CONFIDENTIAL

But does not open up enough exploration.

Page 78: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

78 CONFIDENTIAL

And two dimensions limits the representation and exploration of the data.

Page 79: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

79 CONFIDENTIAL

So, how can we REALLY explore the data in a meaningful way?

Page 80: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

80 CONFIDENTIAL

We need to be able to interact and explore the data.

Page 81: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

81 CONFIDENTIAL

3D models and Interactive visualization allows us to do this.

Page 82: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

82 CONFIDENTIAL

Examples.

Page 83: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

83 CONFIDENTIAL

These are best viewed in the keynote recording here:

http://labs.opendns.com/2014/12/01/vizsec2014

Page 84: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

84 CONFIDENTIAL

Kelhios BotNet

Page 85: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

85 CONFIDENTIAL

Kelhios BotNet Over Time

Page 86: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

86 CONFIDENTIAL

Red October APT Infrastructure

Page 87: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

87 CONFIDENTIAL

Customer BotNet Connection / Relationships

Page 88: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

88 CONFIDENTIAL

Ukraine Networks

Page 89: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

89 CONFIDENTIAL

Cryptolocker Co-occurrences

Page 90: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

90 CONFIDENTIAL

Lets Explore!

Page 91: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

91 CONFIDENTIAL

Future Present.

Page 92: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

92 CONFIDENTIAL

What if the interface was the visualization?

Page 93: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

93 CONFIDENTIAL

What if the interface was the visualization?

Page 94: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

94 CONFIDENTIAL

Through the visualization you could manipulate the data.

Page 95: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

95 CONFIDENTIAL

Assign  Malware    

Page 96: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

96 CONFIDENTIAL

Assign  Malware    

Page 97: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

97 CONFIDENTIAL

Lastly…

Page 98: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

98 CONFIDENTIAL

Viz. is also very good at two key areas in security.

Page 99: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

99 CONFIDENTIAL

Education

Page 100: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

100 CONFIDENTIAL

Awareness

Page 101: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

101 CONFIDENTIAL

People like art.

Page 102: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

102 CONFIDENTIAL

All people are curious!

Page 103: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

103 CONFIDENTIAL

OpenGraphiti Art

Page 104: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

104 CONFIDENTIAL

Page 105: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

105 CONFIDENTIAL

Page 106: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

106 CONFIDENTIAL

Page 107: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

107 CONFIDENTIAL

OpenGraphiti Art Experiment

Page 108: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

108 CONFIDENTIAL

Page 109: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

109 CONFIDENTIAL

Page 110: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

110 CONFIDENTIAL

Page 111: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

111 CONFIDENTIAL

Page 112: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

112 CONFIDENTIAL

Page 113: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

113 CONFIDENTIAL

Page 114: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

114 CONFIDENTIAL

Page 115: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

115 CONFIDENTIAL

Page 116: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

116 CONFIDENTIAL

Page 117: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

117 CONFIDENTIAL

The art project was so popular we use it in marketing material.

Page 118: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

118 CONFIDENTIAL

And the images are talking points of interest.

Page 119: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

119 CONFIDENTIAL

What’s next?

Page 120: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

120 CONFIDENTIAL

People like new interfaces.

Page 121: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

121 CONFIDENTIAL

Leap Motion

Page 122: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

122 CONFIDENTIAL

Oculus Rift

Page 123: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

123 CONFIDENTIAL

Predictive modeling with Viz.

Page 124: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

124 CONFIDENTIAL

Pour conclure…

Page 125: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

125 CONFIDENTIAL

Security needs to get back into the forefront of innovation.

Page 126: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

126 CONFIDENTIAL

Embrace the Big Data movement.

Page 127: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

127 CONFIDENTIAL

And not just become leaders in Security Visualization

Page 128: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

128 CONFIDENTIAL

But innovators in the entire visualization movement.

Page 129: OpenDNS CTO Dan Hubbard VizSec 2014 Keynote Slides

129 CONFIDENTIAL

Merci Beaucoup

Dan Hubbard dan @ opendns.com Opengraphiti.com

Opendns.com


Recommended