2 Discussion questions and 1 weekly Summary 1 Page

profileShrikaa
AdvancedPersistentThreatHacking-Chapter1.pptx

Advanced Persistent Threat Hacking

Chapter 1 Lecture By

Professor Henry A. McKelvey

What This is and Is Not

This is a lecture session

This is not a review of the PDF Slides

You are to read these (PDF Slides) in conjunction with your book

This is a chance to ask questions about the assignments and to understand what is required

This is not a chance to call your friends and family via the Internet

I require your full time and attention.

Objectives

Define The players

Define and describe threats

Describe advanced persistent threats (APT)

Describe what impact this has on our youth

Describe what impacts security has on our economy

Describe what the future of security might look like

The Players

Hacker: A person who has a curiosity about the world around them (Technological, Mechanical, Biological, etc…) They have a profound interest in things

Cyber-Criminal: A person who uses the abilities of a Hacker to carry out criminal exploits (Monetary or Political Gain)

Hacktivist: A person who uses the abilities of a Hacker to carry out a purely political agenda

The Players (Continued)

Hacking Groups: Collection of Hackers who are motivated by fame and group recognition

Nation-States: Countries that are motivated by National security and political/national agendas (Employ Hackers to carry out these agendas)

Organized Crime: Employs Cyber-Criminals to carry out crimes using technology and Hacking Skills

Techno-Criminals: Independent Criminals who use technology to commit crimes (Another term for Cyber-Criminal)

Define and Describe Threats

Threats are any event, object, or person that can exploit a vulnerability(weakness) in a Network or System.

Threats can be visualized as an equation

Motives + Capabilities = Threat Class

Threat Class + History = Threat

Motives are drivers to actions (See pages 4-5 of APTH)

Capabilities are the ability to perform a task at a certain level of expertise (See pages 5-8 of APTH)

Threat Class is the skill level and ability to execute an attack

Threat History is the past success or failure at a task

Describe Advanced Persistent Threats (APT)

First Let’s engage in some reality.

When people (Security Experts) first heard the term Advanced Persistent Threat (APT) They thought it was a joke. (See Pages 7-8 of APTH)

APT is hard to define because it is like talking about Religion, the Martial Arts, or anything else, that involves a comparison

So for simplicity we will say that APT the resultant and goal of an attack that is carried out, over time, and is only limited by the resources of the attacker. However, the goals are limitless

Describe Advanced Persistent Threats (APT) (Continued)

Stealing Intellectual Property (Corporate Espionage)

Stealing Private Data (Insider Trading, Blackmail, Espionage)

Stealing Money (Electronically Transferring Funds, Stealing ATM Credentials, etc…)

Stealing Government Secrets (Spying, Espionage, etc…)

Political or Activist Motives

Effect on Modern Youth

“Too Much” data input and access

Youth are overloaded by access

Youth expect instant gratification

Unreal Expectations About Security

Data and Systems are becoming ubiquitous

Security is not ubiquitous

It was here when I got here

No knowledge about the way the Internet was

The Internet has always been, security is built in

No Defense of the Indefensible

Effect on the Economy

More companies are going to feel the effects of APT attacks

Inability to afford proper protection

Risk Management becomes useless

Companies and people can not afford the needed protective measures

The attacks drain the economic resources of the infected

Too much technology to fight too much technology

ROI is not enough to invest in new security measures

Too much time to do too little

Cost is king and there is not enough of the kingdom

What will be the Future of Security

Offensive Thinking vs. Defensive Thinking

More focus needs to be on the “Big Picture”

Viet Cong vs. US Military

Things are too complex, Complexity = Vulnerability

Lines of code / 1000 = # of possible vulnerabilities

The more complex your code, the more possible vulnerabilities you will have.

Exploits are not based on deficiencies of the system, they are the system.

Hammers are hammers until they are used as cudgels

See pages 23 - 26

Basic Network

The fact is APTs are more advanced than the networks they are designed to attack.

Questions and Answers

Feel free to ask questions, if not I have some questions for you.

Why are Advanced Persistent Threats so dangerous?

How did we get here, at the mercy of our own technology?

In your honest opinion how would you go about stopping or at least mitigating APTs?

In your own words give me your opinion of this presentation?

This is “The End”