Shyam's Slide Share Presentations

VIRTUAL LIBRARY "KNOWLEDGE - KORRIDOR"

This article/post is from a third party website. The views expressed are that of the author. We at Capacity Building & Development may not necessarily subscribe to it completely. The relevance & applicability of the content is limited to certain geographic zones.It is not universal.

TO VIEW MORE CONTENT ON THIS SUBJECT AND OTHER TOPICS, Please visit KNOWLEDGE-KORRIDOR our Virtual Library

Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Saturday, June 22, 2019

3 technologies that could define the next decade of cybersecurity 06-22





In little over a decade, cybercrime has moved from being a specialist and niche-crime type to one of the most significant strategic risks facing the world today, according to the World Economic Forum Global Risks Report 2019. Nearly every technologically advanced state and emerging economy in the world has made it a priority to mitigate the impact of financially motivated cybercrime. 


The global experience of the past decade has largely been dominated by the emergence of a professional underground economy that provides scale, significant return-on-investment and entry points for criminals to turn a technical specialist crime into a global volume crime. The cybersecurity landscape in the past decade has been shaped by the targeting of financial institutions, notably with malware configured to harvest payment information and target financial platforms. The early cybercrime market that gave rise to the criminal online ecosystem was centred on the trading of harvested stolen credit cards, and some of the most high-profile and sophisticated global attacks focus on the penetration and manipulation of the internal networks of complex global payment systems. 


The Russian-speaking world has not been immune from these trends. Cyberattacks on financial organizations in Russia, Central Asia and Eastern Europe by some of the most sophisticated cybercrime gangs in the world have targeted clients, digital channels and networks. The Russian-speaking underground economy is one of the most active globally, with hundreds of fora and tens of thousands of users. Criminal groups exploit the margins of co-operation to conduct global campaigns, and their threat capacity is always adapting as groups work together in a borderless environment to combat technical defences. 



The past 10 years mark only the start of the global cybersecurity journey. New architectures and cooperation are required as we stand at the brink of a new era of cybercrime, which will be empowered by new and emergent technology. These three technologies might very well define the next 10 years of global cybersecurity: 

1. 5G networks and infrastructure convergence

A new generation of 5G networks will be the single most challenging issue for the cybersecurity landscape. It is not just faster internet; the design of 5G will mean that the world will enter into an era where, by 2025, 75 billion new devices will be connecting to the internet every year, running critical applications and infrastructure at nearly 1,000 times the speed of the current internet. This will provide the architecture for connecting whole new industries, geographies and communities - but at the same time it will hugely alter the threat landscape, as it potentially moves cybercrime from being an invisible, financially driven issue to one where real and serious physical damage will occur at a 5G pace. 

5G will potentially provide any attacker with instant access to vulnerable networks. When this is combined with the enterprise and operational technology, a new generation of cyberattacks will emerge, some of which we are already seeing. The recent ransomware attack against the US city of Baltimore, for example, locked 10,000 employees out of their workstations. In the near future, smart city infrastructures will provide interconnected systems at a new scale, from transport systems for driverless cars, automated water and waste systems, to emergency workers and services, all interdependent and - potentially - as highly vulnerable as they are highly connected. In 2017, the WannaCry attack that took parts of the UK’s National Health Service down took days to spread globally, but in a 5G era the malware would spread this attack at the speed of light. It is clear that 5G will not only enable great prosperity and help to save people’s lives, it will also have the capacity to thrust cybercrime into the real world at a scale and with consequences yet unknown. 

2. Artificial intelligence

To build cyber defences capable of operating at the scale and pace needed to safeguard our digital prosperity, artificial intelligence (AI) is a critical component in how the world can build global immunity from attacks. Given the need for huge efficiencies in detection, provision of situational awareness and real-time remediation of threats, automation and AI-driven solutions are the future of cybersecurity. Critically, however, the experience of cybercrime to-date shows that any technical developments in AI are quickly seized upon and exploited by the criminal community, posing entirely new challenges to cybersecurity in the global threat landscape. 

The use of AI by criminals will potentially bypass – in an instant – entire generations of technical controls that industries have built up over decades. In the financial services sector we will soon start to see criminals deploy malware with the ability to capture and exploit voice synthesis technology, mimicking human behaviour and biometric data to circumvent authentication of controls for people’s bank accounts, for example. But this is only the beginning. Criminal use of AI will almost certainly generate new attack cycles, highly targeted and deployed for the greatest impact, and in ways that were not thought possible in industries never previously targeted: in areas such as biotech, for the theft and manipulation of stored DNA code; mobility, for the hijacking of unmanned vehicles; and healthcare, where ransomware will be timed and deployed for maximum impact. 

3. Biometrics

To combat these emerging threats, biometrics is being widely introduced in different sectors and with various aims around the world, while at the same time raising significant challenges for the global security community. Biometrics and next-generation authentication require high volumes of data about an individual, their activity and behaviour. Voices, faces and the slightest details of movement and behavioural traits will need to be stored globally, and this will drive cybercriminals to target and exploit a new generation of personal data. Exploitation will no longer be limited to the theft of people’s credit card number, but will target theft of their being – their fingerprints, voice identification and retinal scans. 

Most experts agree that three-factor authentication is the best available option, and that two-factor authentication is a must. ‘Know’ (password), ‘have’ (token) and ‘are’ (biometrics) are the three factors for authentication, and each one makes this process stronger and more secure. For those charged with defending our digital future, however, understanding an entire ecosystem of biometric software, technology and storage points makes it still harder to defend the rapidly and ever-expanding attack surface.

What next?

Over the past decade, criminals have been able to seize on a low-risk, high-reward landscape in which attribution is rare and significant pressure is placed on the traditional levers and responses to crime. In the next 10 years, the cybersecurity landscape could change significantly, driven by a new generation of transformative technology. To understand how to secure our shared digital future we must first understand how the security community believes the cyberthreat will change and how the consequent risk landscape will be transformed. This critical and urgent analysis must be based on evidence and research, and must leverage the expertise of those in academia, the technical community and policymakers 

around the world. By doing this, the security ecosystem can help build a new generation of cybersecurity defences and partnerships that will enable global prosperity. 






Sunday, November 19, 2017

How a Student Competition Led to a New Cyber Security Approach 11-19




Cybersecurity is a big concern for nearly every industry. But for the banking sector, that concern is paramount and the arms race to stay ahead of digital criminals requires innovative thinking. That’s why the London-based SWIFT Institute, set up by the Society for Worldwide Interbank Financial Telecommunications to enable cross-learning between academics and bankers,  issued a challenge to teams of Canadian university students to come up with new ideas.

The winner, Team Pulse OS, devised a process that allows for reliable early detection by analyzing the unique power-use signatures on mobile devices. Team leader Nataliya Mykhaylova, who is pursuing a doctorate in chemical engineering at the University of Toronto, discussed her project with Knowledge@Wharton following her win at the October 2017 competition. Peter Ware, director of the SWIFT Institute also joined the conversation about cybersecurity.

An edited version of the transcript follows.

Knowledge@Wharton: What prompted the SWIFT Institute to devise this competition?


Peter Ware: We launched the SWIFT Institute Student Challenge last year primarily to engage with students. Part of what the institute does is give research grants to academics. We’ve been dealing with academics for about five years now, so we wanted to go beyond that and try and tap into some young, upcoming, engaging minds.

We linked this specific challenge to a conference that we held in Toronto called Sibos. We thought that we would focus primarily on students at Canadian universities. Before the challenge started, we went to the Canadian banking community and asked, “what is at the forefront of your minds? What is keeping you awake at night that we can try and help you solve?” Unsurprisingly, it was cyber. They helped to find the idea of trying to protect a bank’s channels to its customers from cyber attacks. That’s the challenge that we put to students.

Knowledge@Wharton: Nataliya, why did you want to be a part of this competition?

Nataliya Mykhaylova: I was excited to hear about this competition because cybersecurity was something that is really big on everybody’s mind. A lot of the attacks right now are undetected. I have been kind of researching this field from the hardware side. Doing my Ph.D. at the University of Toronto, I was testing different devices and got lots of ideas about how this could be prevented on a hardware level. I was really excited by this competition and thought I would submit my ideas.

Knowledge@Wharton: Tell us more about your winning idea.

Mykhaylova: You hear on the news all of these companies that have an issue with cybersecurity. What I noticed when looking through those cases is that there is a lot of effort being put into preventing the attacks, which is understandable. But I noticed there is not quite as much attention being spent on detecting those things early. In fact, only 30% of the cyber security attacks are detected in-house. This is a huge problem. There are lots of creative ways in which those attacks happen, and we need better systems to detect them at the edge or before they have a chance to spread.
“There are lots of creative ways in which cyber attacks happen, and we need better systems to detect them at the edge or before they have a chance to spread” –Nataliya Mykhaylova
When I was doing my Ph.D., I was assembling and testing different devices, different sensors. I discovered there is this pattern that you can detect and correct through artificial intelligence models. And you can actually detect the changes in those patterns very early. For example, if the system is compromised even in the early stages, those performance signatures — like heat, CPU, other patterns — change very quickly. You are able to differentiate them from the normal operations of the system. Basically, an attack would leave a series of breadcrumbs as they are compromising the system, so you can detect them before it has really a chance to spread. This was an interesting discovery. This is something that inspired this idea going forward.

Knowledge@Wharton: Do you give consideration to the fact that so much banking is done on mobile devices?

Mykhaylova: Yes. The interesting aspect of the system is that it can work across different types of devices. We are checking up on our accounts on our mobile devices all the time — our  laptops, our desktops. You have to have a system that works effectively throughout interfaces so we can detect things before they have a chance to spread through the banking channels. Part of this system is going down to the very low level, to the hardware level.

With each new version of these devices, they have better and better ICs, the integrated circuits that go into those devices. A lot of them are now able to use features that allow us to run machine-learning models in real time to be able to detect changes in the operation of the systems.

This is a very interesting area, and I feel that it’s been unexplored. This is something that we have been doing, and realizing that there is a lot of opportunity to explore those parts of the system. Because this is something that is much harder for the cyber attackers to fake, they cannot really change the hardware patterns as easily as they would be able to change the software that is running on the system and to hide their traces.

Again, this is something that can be deployed running across the devices, so this makes it very powerful to be able to run the script on your cellphone, on your tablet, on your laptops.

Knowledge@Wharton: Peter, what is the significance of what she is describing?

Ware: It’s something that is very useful, and quite advanced and different from what I think a lot of banks have been looking at. A lot of the ideas that came from other teams in the challenge were all very good ideas. They were dealing with things such as four-factor authentication, voice and facial recognition. But this was a very unique approach from Nataliya, the idea of looking at pattern or usage recognition on our devices. It’s a novel approach. It’s something that, hopefully, banks can take forward and try to implement.

Knowledge@Wharton: Has there already been a reaction from banking institutions to the ideas generated by this contest?

Ware: It was actually the banks that voted on Nataliya to be the winner. We had a panel of four judges, which included some bankers from within Canada and some fintech experts, and we did audience voting online as well. It was the banking community itself that voted on the winner. There was also a lot of engagement among the banks and Nataliya and the other team members. A lot of these ideas are going to be taken forward, I am sure.

Knowledge@Wharton: Is there any possibility that some of those institutions will get involved in developing this idea?

Ware: That is something that would happen directly between the banks and Nataliya, so it is something that we are trying to foster. We are trying to foster that engagement and contact between the banks and the students. What happens next is something that is on a direct relationship between the two of them.

Knowledge@Wharton: Nataliya, can your idea be adapted and applied to sectors beyond banking?

Mykhaylova: I am really interested in potentially scaling this solution. I am passionate about cybersecurity, and I think banking is a great place to start. But I feel like every day we have new channels through which we interact with the world, and we have new devices in our homes through which we interact. We have IoT devices [internet of things], we talk to Alexa and so on. They are really easy channels for attackers to get into our system. I think we can make pretty much any channel more secure.

We have already started conversations with some banks in Canada as well as internationally, so I am very fortunate to have been part of the Sibos competition. But there is a lot of interest I received from the IoT technology sector, which is developing these devices that we all have in our homes now. I am quite excited about the interest and potential scalability of this.

Knowledge@Wharton: The SWIFT Institute will have its 2018 conference in Sydney, Australia. Do you plan to stick with cybersecurity as the theme?
“I am passionate about cybersecurity, and I think banking is a great place to start.” –Nataliya Mykhaylova
Ware: We are going to run the Student Challenge again, but we will come up with a different idea. We’ve gone to the Australian banking community and explained the concept of the challenge to them. There is a great deal of excitement there. They are in the midst of coming up with the idea that is relevant to their community. At this point, we don’t know what the idea is. We have already contacted 43 universities across Australia to explain what Sibos is, what the SWIFT Institute is and the idea behind the challenge. There is a great deal of interest from universities.

Knowledge@Wharton: What are the next steps for you, Nataliya?

Mykhaylova: Our goal right now is to test this system on all of the possible use cases, finalize the models and launch it through a few partner banking institutions to really showcase the benefits that it could provide.

As I mentioned, it can be run on any system, it’s fairly low cost and fast to set up, it’s an easy solution to implement, and it could have a higher return on investments for banks. We are looking to finalize the model and launch it by next year.

Knowledge@Wharton: Banks operate on different systems. Was that a challenge for you in the process of developing this concept?

Mykhaylova: Yes. Banks have all of the infrastructure right now for various types of divisions and for most internal interactions between the employees as well as with the customers. That was one of the biggest aspects that we wanted to incorporate into this solution so that we could deploy a system at scale to detect issues before they have a chance to spread through the network, which I think is one of the biggest concerns with the recent cases of companies being compromised.

Ware: Even within a single bank, they have multiple systems. There are so many different mergers and takeovers that have happened over the decades, and they all have these legacy systems that they try and put together. The idea of Nataliya having something that could be relatively easy to implement is going to be music to the banks’ ears. It’s a great initiative.

Knowledge@Wharton: Do you have to consult with, in this case, the Canadian government for implementation?

Mykhaylova: To some extent. Currently, this system can be operated across a number of different devices and trained on a number of different systems. Right now we are starting kind of small, really validating on very focused case scenarios. But later as it expands, I do feel that it would be important to involve the government because cybersecurity is going to be key for all of our operations. It would be important to think about it on a larger scale.

Knowledge@Wharton: As banks have retreated from some places, a vast number of areas are becoming unbanked, and there is a tremendous increase in financial inclusion with some of the fintechs entering the spaces. Is the cybersecurity solution that Nataliya has proposed relevant to those kinds of entities as well?

Ware: I think it is. You’re absolutely right that the more fintechs open up their systems and create new systems to provide banking services to anyone and everyone around the world, it’s creating more opportunities for cyber attacks. A lot of those smaller fintech companies are not as well regulated, if they’re regulated at all, compared to the banks.

The security they put in place might not be as good as what the banks have in place. Nataliya’s idea could be very relevant to them, and I think it’s absolutely necessary that a lot of those fintech companies try to adopt as stringent security measures as possible.
“The people perpetuating cyberattacks actually operate as a business. They buy and sell information from and to each other.” –Peter Ware
Knowledge@Wharton: Financial institutions may be hesitant to partner with each other, but sharing information would help ensure everyone has a high level of cybersecurity. Do you agree?
Ware: Absolutely. Looking at how banks can share information is something that we have explored from a research perspective. Banks do share cyber-threat information with each other anyway, but we’re always looking for ways on how that can be improved.

The people perpetuating cyber attacks actually operate as a business. They buy and sell information from and to each other. From a protection point of view, the banks are increasingly starting to think along those lines as well. The same would be true for any other industry.

Knowledge@Wharton: Another concern for consumers is the speed in which the information from a breach is relayed to the public. Many within the IT community say time is needed to understand what happened. From that perspective, maybe Nataliya’s solution would speed up this process.

Ware: Exactly. The earlier that those threats can be detected, the more time that banks and anyone else would have to be able to react to it.

Mykhaylova: It takes an average of 98 days to detect an attack, sometimes after years. This is very crazy that we still have to spend so much time detecting those things. Part of the reason is that it is also becoming harder and harder to detect. There are new types of malware, new types of zero-day attacks and other threats that are becoming more and more common. So, it’s important to have systems that don’t need to be signature-based, that can detect those kinds of attacks without any prior knowledge of the threat. This is where our system excels, and it can detect patterns in an unsupervised manner. You don’t need to build up those signature libraries ahead of time.

Knowledge@Wharton: Do you think we will get to a point where potential break-ins are done and figured out in real time?

Mykhaylova: Yes, so that is the goal. Our system runs in real time, continuously tracking things, categorizing them and evaluating how risky they are. I think that is key to be able to do that in real time.

View at the original source

Tuesday, August 15, 2017

Desktop Alert Named Best Mass Notification System by GSN 2017 Airport, Seaport, Border Security Awards 08-16





Desktop Alert, Inc., the patented system owner of less than one minute network-centric emergency mass notification systems (EMNS) to military, government, healthcare, higher education and industrial organizations, today announced that its industry leading mass notification communication platform, Desktop Alert 5.x has garnered three 1st place awards from Government Security News’ (GSN) 2017 Airport, Seaport, Border Security Awards.

Panel 2 of the Summit was moderated by Chuck Brooks, President for Government Relations and Marketing at Sutherland Global Services, who ran the most interactive panel of the day. With all guests being members of DC’s IT Tech elite and the subject of the panel being future threats and new defense technologies, the ballroom was buzzing with questions and discourse. It’s safe to say that this panel ran much like a think-tank, comprised of DC’s greatest tech minds and fueled by the spirit of collaborative learning.

Mr. Brooks has also been cited by Linkedin as one of the top 5 out of 500 million members to follow for emerging technology issues. Linkedin will also be featuring Chuck in their upcoming blogs as a cyber security SME and advisor.

Desktop Alert was named Best Mass Notification System and also a co-winner for Most Notable Implementation of new Technology – Solano Country Implementation of Desktop Alert and Safekey. Desktop Alert subsidiary Metis Secure Solutions also won for Best Alert Beacon System.
"We are honored to have been chosen as a multiple category winner. Our companies numerous years of products and services to the U.S. Army National Guard, U.S. Air National Guard and Northern Command proved pivotal in the award selection process," said Howard Ryan, Founder Desktop Alert Inc.

About Desktop Alert: http://www.desktopalert.net   





Worldwide U.S. Military organizations such as U.S. Northern Command, The United States National Guard, The United States Air Force Academy, The United States Military Academy at West Point, Multi-National Forces in IRAQ and Afghanistan, The U.S. Air Force, The U.S. Army now utilize the Desktop Alert mass notification platform daily for their organizations emergency communication requirements. Desktop Alert can contact thousands of users with desktop alerts and require receipt confirmation of the message. Those not verified can then be listed on a report and/or sent as a "Target Package" to be automatically contacted by other means such as email, SMS, phone calls and other devices.