+ All Categories
Home > Technology > Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

Date post: 18-Nov-2014
Category:
Upload: jeremiah-grossman
View: 963 times
Download: 1 times
Share this document with a friend
Description:
In 2011, attitude towards hacks shifted from "It happens," to "It is happening.” A poorly coded website and web application is all that’s needed to wreak havoc – expensive firewall, pervasive anti-virus and multi-factor authentication be damned. But what is possible? What types of attacks and attackers should we be mindful of? This presentation will show the real risks in a post-2011 Internet.
88
Transcript
Page 1: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 2: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 3: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 4: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 5: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 6: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 7: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 8: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 9: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 10: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 11: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 12: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 13: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

“One intrusion set [hacker attack], not the most prolific, we see pulling data out globally that is 50 times greater than Wikileaks ever day.” General Keith B. Alexander,

USA, Commander, U.S. Cyber Command

Page 14: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 15: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 16: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 17: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 18: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 19: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 20: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 21: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 22: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 23: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 24: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 25: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 26: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 27: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 28: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 29: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 30: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

"French espionage is so widespread that the damages (it causes) the German economy are larger as a whole than those caused by China or Russia."an undated note from the US embassy in Berlin said, according to a Norwegian translation by Aftenposten.

Page 31: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 32: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 33: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 34: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 35: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 36: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

"It [cyber-attack] could theoretically cause a loss of life, but also a huge economic loss.”Janet Napolitano

Department of Homeland Security Chief

Page 37: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 38: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 39: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 40: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 41: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 42: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

“This summer a significant attempt on the Foreign Office system was foiled. These are attacks on our national interest. They are unacceptable. And we will respond to them as robustly as we do any other national security threat.”David Cameron, UK Prime Minister

Page 43: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

“When warranted, we will respond to hostile acts in cyberspace as we would to any other threat to our country.” Department of Defense

Cyberspace Policy Report (Nov. 2011)

Page 44: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 45: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 46: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 47: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

“China is playing by different rules. One, they are stealing intellectual property. Number two, they're hacking into our computer systems, both government and corporate.”Mitt Romney

Page 48: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 49: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 50: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 51: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 52: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

“Rogers has actually spoken with executives from some of the American businesses hit by cyberattacks, and he says stolen intellectual property from just one hi-tech company cost them billions of dollars in research and revenue as well as thousands of U.S. jobs.” The Chairman of the House Intelligence Committee

Republican Rep. Mike Rogers of Michigan

Page 53: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 54: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 55: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 56: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 57: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 58: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 59: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 60: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 61: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 62: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

"When nations steal terabytes of information our nation suffers for 20, 30, 40 years.” (Retired) Lt. Gen. Steven BoutelleFormer U.S. Army's Chief Information Officer

Page 63: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 64: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 65: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 66: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 67: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 68: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 69: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 70: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 71: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 72: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 73: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 74: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 75: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 76: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 77: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 78: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 79: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 80: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 81: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 82: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 83: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"
Page 84: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

BuildersThose who develop of secure code.

BreakersThose who locate vulnerabilities in written code.

DefendersThose who fend off active website attacks.

The biggest problem in application security today…

The need for qualified people.

Page 85: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

BuildersGary McGraw (CTO, Cigital) says roughly 1% of all programmers should be software security pros, or “Builders” in our case. Gary, through a project called BSIMM, arrived at 1% by surveying dozens of software security programs among large companies and measuring what they do.

Worldwide programmer population: 17 million

We’ll need 170,000 “Builders”

Page 86: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

BreakersWe’ll use a ratio of 1 “breaker” per to 100 websites. This ratio comes from internal metrics at WhiteHat Security generated from assessment conducted over the last 8 years and encompassing more than 5,000 websites.

“Important” (SSL) website population: 1.2 million

We’ll need 12,000 “Breakers”

Out of 550 million total websites that should be assessed continuously for vulnerabilities.

Page 87: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

Defenders

No idea how to begin to estimate the Defender need, but it’ll be in the tens of thousands at least. Considering the vast number of website assets that must be protected, the 1 billion online users who someone needs to ensure are playing nice, and monitoring the serious volume of Web traffic they generate.

?

Page 88: Web Breaches in 2011-“This is Becoming Hourly News and Totally Ridiculous"

Hack Yourself

First


Recommended