Yhtomit 3
Goldberg Describes options for the Hardware Cybersecurity Prrofessional (VIF 02_03) (5:06)
What are your thoughts on the cyber security industry which is increasingly automated? What advice do you have to new professionals in this field?
I think if there are students looking at the area for purposes of a career, keep in mind that this is the technological and policy arena that is upon us and every so often we get new tasks that we have to attend to. When Al Qaeda attacked the twin towers in New York it was blast mitigation and it was the need to harmonize and share information across federal agencies that dominated the next decade. Well, this is the decade of cyber insecurity requiring cyber security professionals to step up earn their credentials, we encourage everyone to do that, do not go into this without earning some degree of credentialing here. It is very hard to get a job without it. But, more importantly, if you are looking to be entrepreneurial, this is a wide open domain. Making hardened systems that are impervious to attack I don’t think is entirely possible, but making things more impervious to attack is possible. Some of that really is in very mundane areas, such as training.
You can train people to behave on their computers and over the internet and in social networking in a much more responsible manner than is common today. We call this “cyber-hygiene”… is abominable, but it is not any less abominable than in centuries past when people did not bathe for fear that bathing would lead to disease. We learned that was counter intuitive, and today we need to behave better. This could extend to technological innovation. If you go back in history (student of history) and look at what Carnegie Mellon’s software engineering gurus spoke about 25-30 years ago, is that the way in which we drafted our software was highly vulnerable because we always left back doors open so they could be improved upon and that was simply a path to market decision by the people making software in those days and CMU had argued that those things would one day come back to haunt us and I suppose that we today could consider that advise prescient.
In terms of developing software that are less vunerable would be important. The same goes with hardware. Let me be really clear about this: when we approach this technology we approach it from the view of Moore’s Law. Every eighteen months or so the capability on a chip increases tenfold so in order of magnitude and that includes its density in terms of circuitry but its capabilities as well.
We’re now putting features down on chips that are 7 nanometers. We’re not able to find them once they’re down in terms of post-production verification we lack the methods and the technology – and in our field we call that metrology by which to do the post-production verification. So there’s a lot of use of statistics and other methods to get as close to an understanding of what’s on a chip and what is not on a chip. When we get into that rather scary uncertainty realm you have to understand that if you don’t build in security at the very onset there is a very high likelihood that there are a lot of zero day moments in that technology.
Now, we are all going in that direction. We need to have the functionality, the capabilities, the speed so you can download videos in real time streaming fashion as your on the subway watch whatever movie you want to watch. That capability comes at a technological cost so we need people who will go into the design arena. So we need electrical engineering and computer engineering expertise that is able to bring a much higher level of security focus to these product designs. That’s what I would advise students to really aim for from our perspective. That’s where we’re hiring. That’s what we need in order to enhance our ability to claim security when we put our good housekeeping seal of approval on our products