SlideShare uma empresa Scribd logo
1 de 24
(Web) Security
All in the mind(?)
BCS Talk
April 2013
23/04/13 BCS - April 20132
Who, me?
• Clinton Ingrams
• CSC
– Cyber Security Centre, DMU
– Teaching CS since 1986
– Love PHP
23/04/13 BCS - April 20133
• The problems
• What, if anything, can be done?
23/04/13 BCS - April 20134
Famous Hacks
• LinkedIn
• eHarmony
23/04/13 BCS - April 20135
Problem 1 – the Wetware
• Gullible people
– Don't understand/care about security
• Social Engineering
http://www.madsecurity.com/portfolio/social-engineering/
23/04/13 BCS - April 20136
Problems 2 – crappy Web Apps
• Web application issues
– OWASP top 10
• Errors in business logic
– Ebay
– TV news service
– bitcoins
23/04/13 BCS - April 20137
• Web sites are easy to build
• Web applications are also easy
– PHP – very easy to learn
• (could make it harder)
23/04/13 BCS - April 20138
• WAMP or XAMPP make the AMP stack to
install & configure
• Wordpress, Drupal & Joomla make it
easy...
– but reliant on the developers
23/04/13 BCS - April 20139
Common hacks
• SQLi, XSS, Command Line Injection
– SEO attacks
• Clickjacking, CSRFing, Cross-site History
Manipulation
• Hacks are “easy” with automated toolkits
– Backtrack & Samurai
– Metasploit
– SQLMap
23/04/13 BCS - April 201310
Problem 3 – Smart ...
• Buildings
• Towns & Cities
23/04/13 BCS - April 201311
Problem 3 – Smart ...
• Medical
–Pacemakers
–Diagnosic equipment
–Data set manipulation
23/04/13 BCS - April 201312
Problem 3 – Smart ...
• Utilities
–SCADA problems
• Supervisory Control and Data
Acquisition
• Industrial Control Systems
–Stuxnet
23/04/13 BCS - April 201313
Problem 3 – Smart ...
• Transport
–Traffic Control systems
–Hugo Teso
• Hacked aircraft systems with an
Andoid app
23/04/13 BCS - April 201314
Solutions
23/04/13 BCS - April 201315
• Government
• Organisations
– Voluntary
– Business
– News
• Education
23/04/13 BCS - April 201316
Government
• Cyber Security Fusion Cell
• The “Dad's Army” of cyber security
specialists
23/04/13 BCS - April 201317
Vulnerability Assessments
• 4 layers
– Scans
– Automated toolkits
– Penetration tests
– Physical probing
• See Tiger Team videos
23/04/13 BCS - April 201318
Education
(education, education)
• Teaching:
– MSc/BSc in Computer Security & Forensic
Computing
• Training
– Collaborate with commercial trainers
• Research
23/04/13 BCS - April 201319
Teaching Web App
development
• Architecture
• OOP
• Frameworks & CMS
23/04/13 BCS - April 201320
Teaching - security
• Web App Architecture
• Monitoring
– Iptables
– Snort
• Penetration testing
– Toolkits
– Deliberately vulnerable web apps
• DVWA
• Mutillidae
• WebGoat
23/04/13 BCS - April 201321
Research
• Vehicle Forensics
– Cyber MOT
• Collaborations with legal experts, cyber
psychologists, historians & linguists
• Read more at:
http://www.dmu.ac.uk/research/research-
faculties-and-institutes/technology/cyber-
security-centre/research.aspx
23/04/13 BCS - April 201322
TSI
• Trustworthy Software Initiative
“A public-private partnership for enhancing
the overall software and systems culture,
with the objective that all software should
become designed, implemented and
maintained in a trustworthy manner.”
23/04/13 BCS - April 201323
Risks
• Trust disappears as the web becomes a
more dangerous place for business,
education and entertainment
23/04/13 BCS - April 201324
Reading
• http://www.theiet.org/
• http://www.theregister.co.uk/
• https://www.owasp.org/
• http://www.webappsec.org/
• http://samurai.inguardians.com/
• http://plaintextoffenders.com/
• http://www.trutv.com/video/tiger-
team/tiger-team-101-1-of-4.html

Mais conteúdo relacionado

Semelhante a Bcs april 2013

8 nsta tech talk
 8 nsta   tech talk 8 nsta   tech talk
8 nsta tech talk
Ben Smith
 
Advanc ed illinois online network 2013
Advanc ed  illinois online network 2013Advanc ed  illinois online network 2013
Advanc ed illinois online network 2013
Scott Johnson
 

Semelhante a Bcs april 2013 (20)

LTB Demo - Healthcare Evaluation
LTB Demo - Healthcare EvaluationLTB Demo - Healthcare Evaluation
LTB Demo - Healthcare Evaluation
 
8 nsta tech talk
 8 nsta   tech talk 8 nsta   tech talk
8 nsta tech talk
 
Trustworthy Infrastructure for Personal Data Management
Trustworthy Infrastructure for Personal Data ManagementTrustworthy Infrastructure for Personal Data Management
Trustworthy Infrastructure for Personal Data Management
 
Towards online math exams
Towards online math examsTowards online math exams
Towards online math exams
 
Ejrcicio Presentación mapas conceptuales L Liberal
Ejrcicio Presentación mapas conceptuales   L LiberalEjrcicio Presentación mapas conceptuales   L Liberal
Ejrcicio Presentación mapas conceptuales L Liberal
 
Digital inslusion summit 2016
Digital inslusion summit 2016Digital inslusion summit 2016
Digital inslusion summit 2016
 
Technology in Teaching, Research & Admin’: Some Quick Wins & Data Protection
Technology in Teaching, Research & Admin’: Some Quick Wins & Data ProtectionTechnology in Teaching, Research & Admin’: Some Quick Wins & Data Protection
Technology in Teaching, Research & Admin’: Some Quick Wins & Data Protection
 
Advanc ed illinois online network 2013
Advanc ed  illinois online network 2013Advanc ed  illinois online network 2013
Advanc ed illinois online network 2013
 
Iot security amar prusty
Iot security amar prustyIot security amar prusty
Iot security amar prusty
 
Integration data models, Learning Layers project meeting in Bremen
Integration data models, Learning Layers project meeting in BremenIntegration data models, Learning Layers project meeting in Bremen
Integration data models, Learning Layers project meeting in Bremen
 
Emerging Trends in Cybersecurity by Amar Prusty
Emerging Trends in Cybersecurity by Amar PrustyEmerging Trends in Cybersecurity by Amar Prusty
Emerging Trends in Cybersecurity by Amar Prusty
 
Career Guidance on Cybersecurity by Mohammed Adam
Career Guidance on Cybersecurity by Mohammed AdamCareer Guidance on Cybersecurity by Mohammed Adam
Career Guidance on Cybersecurity by Mohammed Adam
 
Package Tracking Systems Are Not Just for Packages Anymore
Package Tracking Systems Are Not Just for Packages Anymore Package Tracking Systems Are Not Just for Packages Anymore
Package Tracking Systems Are Not Just for Packages Anymore
 
SURFconext / OpenConext - De Cloudservice Integrator voor Hoger Onderwijs en ...
SURFconext / OpenConext - De Cloudservice Integrator voor Hoger Onderwijs en ...SURFconext / OpenConext - De Cloudservice Integrator voor Hoger Onderwijs en ...
SURFconext / OpenConext - De Cloudservice Integrator voor Hoger Onderwijs en ...
 
Security in Cyber-Physical Systems
Security in Cyber-Physical SystemsSecurity in Cyber-Physical Systems
Security in Cyber-Physical Systems
 
Bkbiet intro
Bkbiet introBkbiet intro
Bkbiet intro
 
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with trainingASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
 
Privacy. Winter School on “Topics in Digital Trust”. IIT Bombay
Privacy. Winter School on “Topics in Digital Trust”. IIT BombayPrivacy. Winter School on “Topics in Digital Trust”. IIT Bombay
Privacy. Winter School on “Topics in Digital Trust”. IIT Bombay
 
AMARC Summary Description
AMARC Summary Description AMARC Summary Description
AMARC Summary Description
 
Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...
Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...
Iurii Garasym - Cloud Security Alliance Now in Ukraine. Mission, Opportunitie...
 

Último

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Último (20)

Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 

Bcs april 2013

  • 1. (Web) Security All in the mind(?) BCS Talk April 2013
  • 2. 23/04/13 BCS - April 20132 Who, me? • Clinton Ingrams • CSC – Cyber Security Centre, DMU – Teaching CS since 1986 – Love PHP
  • 3. 23/04/13 BCS - April 20133 • The problems • What, if anything, can be done?
  • 4. 23/04/13 BCS - April 20134 Famous Hacks • LinkedIn • eHarmony
  • 5. 23/04/13 BCS - April 20135 Problem 1 – the Wetware • Gullible people – Don't understand/care about security • Social Engineering http://www.madsecurity.com/portfolio/social-engineering/
  • 6. 23/04/13 BCS - April 20136 Problems 2 – crappy Web Apps • Web application issues – OWASP top 10 • Errors in business logic – Ebay – TV news service – bitcoins
  • 7. 23/04/13 BCS - April 20137 • Web sites are easy to build • Web applications are also easy – PHP – very easy to learn • (could make it harder)
  • 8. 23/04/13 BCS - April 20138 • WAMP or XAMPP make the AMP stack to install & configure • Wordpress, Drupal & Joomla make it easy... – but reliant on the developers
  • 9. 23/04/13 BCS - April 20139 Common hacks • SQLi, XSS, Command Line Injection – SEO attacks • Clickjacking, CSRFing, Cross-site History Manipulation • Hacks are “easy” with automated toolkits – Backtrack & Samurai – Metasploit – SQLMap
  • 10. 23/04/13 BCS - April 201310 Problem 3 – Smart ... • Buildings • Towns & Cities
  • 11. 23/04/13 BCS - April 201311 Problem 3 – Smart ... • Medical –Pacemakers –Diagnosic equipment –Data set manipulation
  • 12. 23/04/13 BCS - April 201312 Problem 3 – Smart ... • Utilities –SCADA problems • Supervisory Control and Data Acquisition • Industrial Control Systems –Stuxnet
  • 13. 23/04/13 BCS - April 201313 Problem 3 – Smart ... • Transport –Traffic Control systems –Hugo Teso • Hacked aircraft systems with an Andoid app
  • 14. 23/04/13 BCS - April 201314 Solutions
  • 15. 23/04/13 BCS - April 201315 • Government • Organisations – Voluntary – Business – News • Education
  • 16. 23/04/13 BCS - April 201316 Government • Cyber Security Fusion Cell • The “Dad's Army” of cyber security specialists
  • 17. 23/04/13 BCS - April 201317 Vulnerability Assessments • 4 layers – Scans – Automated toolkits – Penetration tests – Physical probing • See Tiger Team videos
  • 18. 23/04/13 BCS - April 201318 Education (education, education) • Teaching: – MSc/BSc in Computer Security & Forensic Computing • Training – Collaborate with commercial trainers • Research
  • 19. 23/04/13 BCS - April 201319 Teaching Web App development • Architecture • OOP • Frameworks & CMS
  • 20. 23/04/13 BCS - April 201320 Teaching - security • Web App Architecture • Monitoring – Iptables – Snort • Penetration testing – Toolkits – Deliberately vulnerable web apps • DVWA • Mutillidae • WebGoat
  • 21. 23/04/13 BCS - April 201321 Research • Vehicle Forensics – Cyber MOT • Collaborations with legal experts, cyber psychologists, historians & linguists • Read more at: http://www.dmu.ac.uk/research/research- faculties-and-institutes/technology/cyber- security-centre/research.aspx
  • 22. 23/04/13 BCS - April 201322 TSI • Trustworthy Software Initiative “A public-private partnership for enhancing the overall software and systems culture, with the objective that all software should become designed, implemented and maintained in a trustworthy manner.”
  • 23. 23/04/13 BCS - April 201323 Risks • Trust disappears as the web becomes a more dangerous place for business, education and entertainment
  • 24. 23/04/13 BCS - April 201324 Reading • http://www.theiet.org/ • http://www.theregister.co.uk/ • https://www.owasp.org/ • http://www.webappsec.org/ • http://samurai.inguardians.com/ • http://plaintextoffenders.com/ • http://www.trutv.com/video/tiger- team/tiger-team-101-1-of-4.html