jan guldentops - The changing world and the technical impact on your security

25
Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 The changing world and the technical impact on your security Jan Guldentops ( Jan Guldentops ( Jan Guldentops ( Jan Guldentops ( [email protected] [email protected] [email protected] [email protected] ) ) ) BA N.V. ( BA N.V. ( BA N.V. ( BA N.V. ( http://www.ba.be http://www.ba.be http://www.ba.be http://www.ba.be ) ) )

description

 

Transcript of jan guldentops - The changing world and the technical impact on your security

Page 1: jan guldentops - The changing world and the technical impact on your security

Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 Infosecurity 2011 The changing world and the technical

impact on your security Jan Guldentops ( Jan Guldentops ( Jan Guldentops ( Jan Guldentops ( [email protected]@[email protected]@ba.be ))))BA N.V. ( BA N.V. ( BA N.V. ( BA N.V. ( http://www.ba.behttp://www.ba.behttp://www.ba.behttp://www.ba.be ))))

Page 2: jan guldentops - The changing world and the technical impact on your security

Who am i ?Who am i ?Who am i ?Who am i ?

� Jan Guldentops

� Historian by education, techie by vocation

� > 15 years experience in the field of � > 15 years experience in the field of networking and security.

� Strong focus on open source / standards in my solutions

� Open source fundamentalist after houres

� Founder / consultant @ BA since 1996

� Do a lot of research

Page 3: jan guldentops - The changing world and the technical impact on your security

Who is BA ?Who is BA ?Who is BA ?Who is BA ?

� BA

� Team of technical consultants

� Design – built – support – troubleshoot

� Strong R&D division doing tests in our lab and researching new technologylab and researching new technology

� Focus on infrastructure / networking / security

� Vendor neutral advice

� Focus on openess

� Open standards / source

Page 4: jan guldentops - The changing world and the technical impact on your security

Security Security Security Security –––– what is it ? (again)what is it ? (again)what is it ? (again)what is it ? (again)

CIA

CONFIDENTIALITYCONFIDENTIALITY

INTEGRITY

AVAILIBILITY

(+ Accountability, Non-repudiation, Authenticity, Reliability)

Page 5: jan guldentops - The changing world and the technical impact on your security

What is it not ?What is it not ?What is it not ?What is it not ?

� Marketing :

� Abused by the sales guy

� Abused by the marketing guy

� Abused by the politician � Abused by the politician

� FUD

� Fear Uncertainty Doubt

� Mythology

Page 6: jan guldentops - The changing world and the technical impact on your security

Confessions of a dangerous mind Confessions of a dangerous mind Confessions of a dangerous mind Confessions of a dangerous mind

� I've been playing with security / insecurity my whole life

� Intellectual challenge

� 198* � 198*

� Arms race around copyright protection

� First BBS systems

� Phreaking

� Bypassing analog PBX'es

� Green numbers

Page 7: jan guldentops - The changing world and the technical impact on your security

Confessions of a dangerous mind Confessions of a dangerous mind Confessions of a dangerous mind Confessions of a dangerous mind

� 199* @University

� Got a big network / internet to play with

� Linux

� “discussed” securityproblems with staff

� 1996 exposed security-problems in the first Belgian Online bank

� 1998 proved and documented problems in Lotus Notes / Domino

� 2001 proved / documented problems

Page 8: jan guldentops - The changing world and the technical impact on your security

I sometimes feel so 1996I sometimes feel so 1996I sometimes feel so 1996I sometimes feel so 1996

� People are still... well... people

� (and this also applies to ICT / security “experts”)

� e.g.

Passwords� Passwords

� Social engineering

� All the other human vices

Page 9: jan guldentops - The changing world and the technical impact on your security

I sometimes feel so 1996I sometimes feel so 1996I sometimes feel so 1996I sometimes feel so 1996

� Websites are still being hacked by scriptkiddies with simple tools

� Got an LSEC statistic yesterday

� In 2010 16134 .be were defaced!

� Encryption is still not used everywhere

� Or we use selfsigned certificates !

� SMTP is still not fixed!

� Relatively simple worms and viruses can still cause havoc

� Stuxnet, Conficker

Page 10: jan guldentops - The changing world and the technical impact on your security
Page 11: jan guldentops - The changing world and the technical impact on your security

I sometimes feel so 1996I sometimes feel so 1996I sometimes feel so 1996I sometimes feel so 1996

� Companies still don't think about security when designing a (web)application :

� Play around with webscarab or firebug

� On 99% of my customers networks i can still set up a reverse tunnel !

� Ssh on an open tcp/port

� Openvpn

� Tunnel over dns

Page 12: jan guldentops - The changing world and the technical impact on your security

Yelo is bedoeld voor residentieel gebruik. De meeste klanten gebruiken Yelo dan ook thuis,

via een beveiligd thuisnetwerk. Voor hen is er geen enkel probleem

Page 13: jan guldentops - The changing world and the technical impact on your security

What has changed ?What has changed ?What has changed ?What has changed ?

� Moore's Law

� CPU

� 1996 i had a Pentium 1 - 133Mhz workstation, now I have some quad core Intel processorcore Intel processor

� Or I can rent tempory computing power in the cloud from Amazon (EC2)

� Networking

� 1996 I had an expensive 64Kbit ISDN internet connection at home, now we have all Mbits of connectivity

Page 14: jan guldentops - The changing world and the technical impact on your security

What has changed ?What has changed ?What has changed ?What has changed ?

� Speed

� You could get away with security stupidities for weeks, months, years.

� Now a stupidity like an open proxy or an sshd with a trivial password gets an sshd with a trivial password gets hacked in minute.

� Legal framework

� We have a CCU now

� They have laws to prosecute cybercriminals

Page 15: jan guldentops - The changing world and the technical impact on your security

What has changed ?What has changed ?What has changed ?What has changed ?

� Perimeter has disappeared

� The scope of who attacks you is different ?

� Globalisation Globalisation

� Used to be cyberpunks

� Now organized crime, nations (cyberwar), etc.

� People live their lives

Page 16: jan guldentops - The changing world and the technical impact on your security

Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?

� Data leakage

� We are loosing confidential information to the outside world

� Mobile devices

Phones, smartphones, laptops, ipads, etc.� Phones, smartphones, laptops, ipads, etc.

� Public services

� Theft

� Once it is out there you are never getting it back in !

Page 17: jan guldentops - The changing world and the technical impact on your security

Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?

� New civil movements

� People organising on the internet via facebook, twitter, etc.

� Using the internet for communication

But also going for orchestrated Dos-� But also going for orchestrated Dos-attacks

� LOIC aka Low Orbit Ion Cannon

� Examples :

� Revolutions in the middle east

� Movement supporting wikileaks

� What if you are the target ?

Page 18: jan guldentops - The changing world and the technical impact on your security

Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?

� Social media

� People are living their lives online

� Putting potentialy confidential and dangerous info on their profiles

� We see a lot of targeted attacks based on info gained from social media. info gained from social media.

� Information is leaking out of your organisation

� Social networks are not very secure

� Session key sniffing, no encryption, bad privacy

� Instant news

� reputation / crisis management

Page 19: jan guldentops - The changing world and the technical impact on your security
Page 20: jan guldentops - The changing world and the technical impact on your security

Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?

� Consumerism

� Bringing consumer applications / toys into the corporate organisation

� e.g. The ipad

� But also using google docs, facebook, But also using google docs, facebook, msn, etc. For business purposes

� Security is the last thing on their mind, ICT looses controll

� 0/1 approach -> IT becomes mister no

� Often pushed by the higher management

Page 21: jan guldentops - The changing world and the technical impact on your security

Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?Trends in 2010/11?

� Hacking tools get GUIS

� Everybody is a threat

� Goes further then scriptkiddies

� Really everbody can hack

� “sneakers” has become a reality� “sneakers” has become a reality

� Examples :

� Firesheep

� Aircrack-NG, backtrack

� Speeds up security !

Page 22: jan guldentops - The changing world and the technical impact on your security
Page 23: jan guldentops - The changing world and the technical impact on your security

How are we going to fix this ?How are we going to fix this ?How are we going to fix this ?How are we going to fix this ?

� There is no technology fix for all this

� Next generation firewalls look promising

� Palo Alto

� Becomes a marketing term everybody Becomes a marketing term everybody uses like UTM

� Good security practices ! � Create / Implement a good security

policy

� Audit

� Limit access

� Educate your users

Page 24: jan guldentops - The changing world and the technical impact on your security

Questions / remarks ?Questions / remarks ?Questions / remarks ?Questions / remarks ?

� Pass by booth B116

� E-mail:

[email protected]

� Twitter:

JanGuldentops (me)� JanGuldentops (me)

� Linkedin:

� http://be.linkedin.com/in/janguldentops

� Website :

� http://www.ba.be

Page 25: jan guldentops - The changing world and the technical impact on your security

Thank YouContact us

www.ba.be

016/29.80.45

016/29.80.46

www.ba.be

Dalemhof 28 B-3000 Leuven

[email protected]