+ All Categories
Home > Documents > Prof. Dr. B. M. Hämmerli, [email protected] EAPC / PFP Workshop ICT Vulnerabilities.

Prof. Dr. B. M. Hämmerli, [email protected] EAPC / PFP Workshop ICT Vulnerabilities.

Date post: 25-Dec-2015
Category:
Upload: jemimah-golden
View: 215 times
Download: 1 times
Share this document with a friend
15
Prof. Dr. B. M. Hämmerli, [email protected] EAPC / PFP Workshop ICT Vulnerabilities
Transcript
Page 1: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

Prof. Dr. B. M. Hämmerli, [email protected]

EAPC / PFP Workshop

ICT Vulnerabilities

Page 2: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 2

Vulnerabilities

Whatever its cause, critical service disruption shall only occur infrequently impact only a small area have a short duration have only limited impact be a continuously managed & controlled process

Page 3: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 3

Vulnerabilities

Something is vulnerable, if it can be exploited by a threat

A vulnerability is a “place” that is especially prone to threats where damage can easily occur / has serious consequences easily “accessed” / difficult to protect from where damage can spread

understand threats, and that threats can hook in vulnerabilities only understand vulnerabilities, and not well mitigated threats understand human intent, and its deliberated risk

Page 4: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 4

Vulnerabilities an Risks

Risk = Probability x Damage [$] I for each vulnerability

Page 5: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 5

ICT is a Local and a Global Issue

Page 6: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 6

Example 1: 150 Fiber connections are cut!

Angle Grinder, August 2005, Switzerland

Betondecke

Fiberkabel

ca. 250 Verbindungen

Page 7: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 7

Dependency and Vulnerability

Bancomat

POSTankautomat

kontoführende Banken

5400 Geldausgabe-Geräte bei Finanzinstituten

89‘000 POS-Terminals bei Kaufhäusern,Supermärkten,Tankstellen, etc.

Page 8: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 8

Day before Christmas 2000300 Billion SFr. per diem

Page 9: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 9

Impact of ICT Vulnerabilities on Banks

Kennzahlen 2005 - 321 Teilnehmer - 800‘000 Tx / Tag - 300 Mia. CHF / Spitzentag

remoteGateremoteGate

SIS

SWX

Postfinance

SNB

Service Büro

CLS Interbank- Produkte

Banken

Schweizerische Nationalbank

Börse Schweiz

BankenSega Intersettle

Continuous Linked

Settlement

Page 10: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 10

European CIIP R&D by Sector

0 1 2 3 4 5 6 7 8 9

4. Transportation

2. ICT services

8. Emergency/security services

1. Energy sector

9. Governmental services

5. Health care

10. High risk industries

3. Financial Services

6. Water management

7. Food management

Page 11: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 11

Expenses for Countermeasures

Expenses for IT Security III: Dollar Amount of Losses by Type

Page 12: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 12

Reported Incidents

Vulnerability Types vs. Year

Intranet incidents are as well a topic of InfoSec

Viruses and malware are on place 2

Mobile incidents grow rapidly

Generally all incidents are decreasing. Cause is unclear. Might be it is good prevention.

Page 13: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 13

Some Facts about dealing with ICT Vulnerability

Computer Zeitung (D): In 2010 will 90% of US corporation have IT security outsourced.

The incidents decrease, the complexity and the damage increase.

The complexity of IT security is far beyond the capabilities of SME’s. The tendency for future will enlarge this gap. From DoD US study: The complexity of attacks will relevantly increase.

Modern malware distributes itself within few minutes over the whole world. Which enterprise can build a service with an adequate reaction time ever day day and night? (Alternative scenario: Business Continuity Planning BCP)

Actual Trend: More and more intranet user are involved in attacks. Intranet monitoring must absolutely be an additional topic to the existing perimeter security.

With outstanding IT security corporations do not have Information security. Trend: holistic security. Common security management for all threats.

The facts can be downloaded from: http://i.cmpnet.com/gocsi/db_area/pdfs/fbi/FBI2004.pdf

Page 14: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 14

Preparing for Incidents

Page 15: Prof. Dr. B. M. Hämmerli, bmhaemmerli@acris.ch EAPC / PFP Workshop ICT Vulnerabilities.

EAPC / PFP Workshop

Zurich, September 23, 2005 Prof. Dr. Bernhard M. Hämmerli Page 15

Questions


Recommended