1.13k likes | 1.22k Views
Required Slide. SESSION CODE: SIA230. Why Security Fixes Won’t Fix Your Security. Pete Calvert sage-work Grad.Dip.Comp.Sc , B.Bus (Marketing / Finance ), MCT , MCITP, MCSE … facebook.com/ pete.calvert | twitter.com/ erucsbo | pete@sage-work.com. g’day. Australia. not Austria. beaches.
E N D
Required Slide SESSION CODE: SIA230 Why Security Fixes Won’t Fix Your Security Pete Calvert sage-work Grad.Dip.Comp.Sc, B.Bus(Marketing / Finance), MCT, MCITP, MCSE … facebook.com/pete.calvert | twitter.com/erucsbo | pete@sage-work.com
Definitions of g’day <strine> Hi Hello Hope you have a good day I’m busy but I’ll acknowledge your existence You don’t look like you’re from England so I’ll say hello I’m not sure what is going on here.Will someone buy me a drink? You look cute. If I buy you a drink will you give me your name and phone number?
Why Security Fixes Won’t Fix Your SecurityAgenda Definitions Models Gaps Options Solution Summary
Definitions of Security Applications? Platforms and Operating Systems? Policies Information Classification? Physical infrastructure? Clearances?
Definitions of Security wedding picture
Definitions of Security house
Definitions of Security job security
Definitions of Security Security guards
Definitions of Security Security guards
Definitions of Security passwords
Definitions of Security Define what we are securing Define what secure means
Models of Security Complex environment that needs to be managed Use models to simplify understanding and hopefully identify gaps Patch / AntiVirus / Firewall Defense in Depth Impossible Triangle
Current malware signature count 7,452,232 http://www.triumfant.com/Signature_Counter.asp
Models of SecuritySecurity Mantra Firewalls Won’t stop legitimate traffic Defined by protocol Content inspection requires the traffic not be encrypted(or is able to be decrypted and re-encrypted between the endpoints) Useful for shutting the gates / traffic isolation
Statistics http://datalossdb.org/statistics
Statistics http://juststolen.net/blog/ Stolen laptops in the US for 2008 & 2009
Statistics • A laptop is stolen every 53 seconds. • More than 12,000 laptops disappear each week from U.S. airports alone. • Only 3% of laptops are ever returned. http://www.propeller.com/story/2008/11/24/interesting-laptop-theft-statistics/
Statistics 0.3% http://www.joe-ks.com/archives_feb2004/Useless_Stats.htm
Statistics http://www.joe-ks.com/archives_feb2004/Useless_Stats.htm
Statistics 90% http://www.joe-ks.com/archives_feb2004/Useless_Stats.htm
Statistics http://www.joe-ks.com/archives_feb2004/Useless_Stats.htm
Statistics http://www.joe-ks.com/archives_feb2004/Useless_Stats.htm
Models of SecuritySecurity Mantra • Secures the platform only and only from known external malicious attacks • Security can still be compromised by • Theft • Inappropriate access controls
Models of SecurityAccess Controls Passwords Something you know Security Tokens Something you have Biometric Something you are