SlideShare uma empresa Scribd logo
1 de 54
Baixar para ler offline
Breaking in to Security
2
INFORMATION SECURITY : A SHORT VIEW
“I’d like to get a job in security, how do I
get started?”
6
“What programming language do I need to
learn to be a penetration tester?”
7
“What certification should I get?”
8
Answering these one at a time is
inefficient, biased and time consuming
9
Lets ask the community and get a
definitive answer
10
11
But before we get started...
12
Is this what you want to be?
13
Or maybe this
14
The reality
15
A lot of time in here
16
Meetings
17
Still Interested?
18
For those still here, lets
look at some stats
19
<1year 22 7%
1-3years 64 22%
4-7years 81 27%
7+years 128 43%
Time In Industry
20
Penetrationtester 173 59%
Vulnerabilityauditor 143 49%
Sys-admin 130 45%
IDS/Firewalladmin 102 35%
Policywriter 97 33%
Loganalyst 97 33%
Incidentresponse 74 25%
Other 66 23%
Manager 64 22%
Malwareanalyst 49 17%
ITForensices 48 16%
Reverseengineer 38 13%
Exploitdeveloper 36 12%
Helpdesk 35 12%
PCIauditor 33 11%
Job Types
21
No,butithelps 182 62%
Yes 78 26%
Other 17 6%
Don'tknow 12 4%
No 6 2%
Do you need to be able to program
to be a pen-tester?
22
Python 227 81%
BashScripting 221 79%
Ruby 122 43%
C 116 41%
WindowsPowershell 104 37%
PHP 101 36%
BatchScripting 102 36%
C++ 62 22%
Java 63 22%
Other 51 18%
Perl 46 16%
VB 29 10%
C# 25 9%
Lua 23 8%
What Language?
23
Yes 144 49%
Yes-butonlytogetthroughHR 137 46%
No 14 5%
Are Certifications Useful?
24
SANS/GIAC 189 69%
CISSP 187 68%
OffensiveSecurity(PWB,AWEetc) 111 40%
EC-Council(CEHetc) 64 23%
CompTIA(Security+etc) 63 23%
Vendorspecific 60 22%
Other 55 20%
CHECKTeamLeader(CREST/TigerScheme) 31 11%
CHECKTeamMember(CREST/TigerScheme) 30 11%
Which Certs?
25
Other Certificates Include
•OSSTIM
•ISACA
•Cisco
•Microsoft
•Linux/Unix
•Whatever gets you the job
•Anything management has heard of
•Networking
26
Yes 259 88%
Other 24 8%
No 12 4%
Are Conferences Worth Attending?
27
Which Ones?
All of them got a mention
28
That’s the end of the stats
29
What do you know now that
you wish you'd known when
starting out?
31
People skills, managing management
and clients
“I think it's important to note that information security
is a role in a company that involves dealing with
people. Brush up on your public speaking and
negotiation skills. I'm much better at hacking silicon
than I am hacking carbon, but each is important. Take
time to learn and practice those soft skills.”
32
Business skills
“Business skills are more important than
technical skills.”
33
Report writing skills
“It's all about the report... you can be the
best penetration tester in the world, but if
your report sucks, so does your test!”
34
Networking is important
“Get out there and network, don't be shy
we are a friendly lot”
35
You can't secure everything and can't be
100% secure so live with it
“Security is a balance between risk
mitigation and corporate earnings.
Companies must continue making
money to pay your salary. Ergo, the best
security may not be the right security.”
36
“You will live in hotels”
“Pen testing is not so glamorous as it
appears”
37
“Cons are bad for your liver”
38
What one piece advice would
you give to someone wanting
to start a career in security?
39
Learn, learn and learn some more
“Study hard, do the labs and exercises,
experiment with tools.”
40
You need your own lab
“Set a lab environment up to practice
with, virtualisation makes these easy
these days.”
41
Get an all-round education
“Develop skills in other areas of IT
(system administration, network
management, development, etc.) either
before or in addition to InfoSec.”
42
Make sure you enjoy what you do
“Do it for love of what you do, not to
make money. The money is good, but if
you really enjoy it, it's the best job in the
world.”
“Make sure its something you really want
and can keep up with, not just something
you enjoy on the side.”
43
More about soft skills and business
knowledge
“Be tolerant of the non-techs, teach
them, but don't talk down to them. Be
aware that sometimes, the business
needs trump security best practices.”
44
Repeated from earlier, programming is a
useful skill
“Learn to program (scripting at least).”
45
Get yourself known
“To get involved in different projects and
contribute, there are a lot of open source
projects you can contribute to in different
ways.”
46
“It's all about reputation. Certs are
useful, but if you are unknown you won't
be taken seriously. Get out there, meet
people, and learn from them!”
47
“Start a blog.. not for fame and glory but
more for keeping a record of what you
learn. Doesn't matter if no one reads it,
do it for yourself.”
48
Find your local community - 2600,
hackerspace, DC group
“Find your local community & online
community”
50
Don’t just trust tools
“Learn whats going behind the tools you
are using”
51
“Get in bed with the operations and
finance people (not literally, however this
might also help)”
52
“Work your ass off! Everyone else does
so you better get used to it.”
53
Is it OK to “practice” on sites/
companies without permission
if you don't do any damage?
54
Overwhelming opinion - No, there are
enough resources out there you don’t
need to
55
“Only if you want a new ‘room-mate’
called Bubba......”
56
What I’ve not covered
What do you see as the next up and coming area?
Is there anything you feel you did wrong that you
would advise against?
57
Conclusions
If you aren’t passionate it is just another job
Get stuck in, learn and show your interest
Don’t be afraid to ask questions - but show you’ve
tried to find the answer yourself first
It isn’t all about the tech
60
Big thanks to all who
responded
61
Lets play a game, who
wants a question
answered?
62
Facebook/D3pak
@D3pak
Deepakniit14@gmail.com
about.me/D3pak

Mais conteúdo relacionado

Semelhante a Information Security : A look

Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019Brian Harden
 
So, you wanna be a pen tester
So, you wanna be a pen testerSo, you wanna be a pen tester
So, you wanna be a pen testerAdrien de Beaupre
 
The Security Industry: How to Survive Becoming Management BSIDESLV 2013 Keynote
The Security Industry: How to Survive Becoming Management BSIDESLV 2013 KeynoteThe Security Industry: How to Survive Becoming Management BSIDESLV 2013 Keynote
The Security Industry: How to Survive Becoming Management BSIDESLV 2013 KeynoteVeracode
 
You Can't Buy Security - DerbyCon 2012
You Can't Buy Security - DerbyCon 2012You Can't Buy Security - DerbyCon 2012
You Can't Buy Security - DerbyCon 2012jadedsecurity
 
NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017
NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017
NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017Archersan
 
Banning Whining, Avoiding Cyber Wolves, and Creating Warrior
Banning Whining, Avoiding Cyber Wolves, and Creating WarriorBanning Whining, Avoiding Cyber Wolves, and Creating Warrior
Banning Whining, Avoiding Cyber Wolves, and Creating WarriorSandra (Sandy) Dunn
 
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?Anthony Melfi
 
How To Become an Ethical Hacker?
How To Become an Ethical Hacker?How To Become an Ethical Hacker?
How To Become an Ethical Hacker?Srashti Jain
 
Tech Talk @ Dev Bootcamp Chicago
Tech Talk @ Dev Bootcamp ChicagoTech Talk @ Dev Bootcamp Chicago
Tech Talk @ Dev Bootcamp ChicagoFred Lee
 
HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...
HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...
HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...AdaCore
 
14 things you need to be a successful software developer (v3)
14 things you need to be a successful software developer (v3)14 things you need to be a successful software developer (v3)
14 things you need to be a successful software developer (v3)Robert MacLean
 
Intro to INFOSEC
Intro to INFOSECIntro to INFOSEC
Intro to INFOSECSean Whalen
 
100+ Cyber Security Interview Questions and Answers in 2022
100+ Cyber Security Interview Questions and Answers in 2022100+ Cyber Security Interview Questions and Answers in 2022
100+ Cyber Security Interview Questions and Answers in 2022Temok IT Services
 
apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...
apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...
apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...apidays
 
DIY Education in Cyber Security
DIY Education in Cyber SecurityDIY Education in Cyber Security
DIY Education in Cyber SecurityKelly Shortridge
 
Developing Software with Security in Mind
Developing Software with Security in MindDeveloping Software with Security in Mind
Developing Software with Security in Mindsblom
 
101 ways to fail at security analytics ... and how not to do that - BSidesLV ...
101 ways to fail at security analytics ... and how not to do that - BSidesLV ...101 ways to fail at security analytics ... and how not to do that - BSidesLV ...
101 ways to fail at security analytics ... and how not to do that - BSidesLV ...Jon Hawes
 
Bug Bounties and The Path to Secure Software by 451 Research
Bug Bounties and The Path to Secure Software by 451 ResearchBug Bounties and The Path to Secure Software by 451 Research
Bug Bounties and The Path to Secure Software by 451 ResearchHackerOne
 
A public discussion about privacy careers: Training, certification and experi...
A public discussion about privacy careers: Training, certification and experi...A public discussion about privacy careers: Training, certification and experi...
A public discussion about privacy careers: Training, certification and experi...Infosec
 

Semelhante a Information Security : A look (20)

Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019
 
So, you wanna be a pen tester
So, you wanna be a pen testerSo, you wanna be a pen tester
So, you wanna be a pen tester
 
The Security Industry: How to Survive Becoming Management BSIDESLV 2013 Keynote
The Security Industry: How to Survive Becoming Management BSIDESLV 2013 KeynoteThe Security Industry: How to Survive Becoming Management BSIDESLV 2013 Keynote
The Security Industry: How to Survive Becoming Management BSIDESLV 2013 Keynote
 
HackerRank
HackerRankHackerRank
HackerRank
 
You Can't Buy Security - DerbyCon 2012
You Can't Buy Security - DerbyCon 2012You Can't Buy Security - DerbyCon 2012
You Can't Buy Security - DerbyCon 2012
 
NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017
NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017
NCET Biz Bite | Aaron Boigon, Practical IT management | Sept 2017
 
Banning Whining, Avoiding Cyber Wolves, and Creating Warrior
Banning Whining, Avoiding Cyber Wolves, and Creating WarriorBanning Whining, Avoiding Cyber Wolves, and Creating Warrior
Banning Whining, Avoiding Cyber Wolves, and Creating Warrior
 
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
 
How To Become an Ethical Hacker?
How To Become an Ethical Hacker?How To Become an Ethical Hacker?
How To Become an Ethical Hacker?
 
Tech Talk @ Dev Bootcamp Chicago
Tech Talk @ Dev Bootcamp ChicagoTech Talk @ Dev Bootcamp Chicago
Tech Talk @ Dev Bootcamp Chicago
 
HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...
HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...
HIS 2015: Roderick Chapman - Murphy Vs Satan Why programming secure systems i...
 
14 things you need to be a successful software developer (v3)
14 things you need to be a successful software developer (v3)14 things you need to be a successful software developer (v3)
14 things you need to be a successful software developer (v3)
 
Intro to INFOSEC
Intro to INFOSECIntro to INFOSEC
Intro to INFOSEC
 
100+ Cyber Security Interview Questions and Answers in 2022
100+ Cyber Security Interview Questions and Answers in 2022100+ Cyber Security Interview Questions and Answers in 2022
100+ Cyber Security Interview Questions and Answers in 2022
 
apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...
apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...
apidays Paris 2022 - Let’s not make the diversity mistake in NoCode, Manon Me...
 
DIY Education in Cyber Security
DIY Education in Cyber SecurityDIY Education in Cyber Security
DIY Education in Cyber Security
 
Developing Software with Security in Mind
Developing Software with Security in MindDeveloping Software with Security in Mind
Developing Software with Security in Mind
 
101 ways to fail at security analytics ... and how not to do that - BSidesLV ...
101 ways to fail at security analytics ... and how not to do that - BSidesLV ...101 ways to fail at security analytics ... and how not to do that - BSidesLV ...
101 ways to fail at security analytics ... and how not to do that - BSidesLV ...
 
Bug Bounties and The Path to Secure Software by 451 Research
Bug Bounties and The Path to Secure Software by 451 ResearchBug Bounties and The Path to Secure Software by 451 Research
Bug Bounties and The Path to Secure Software by 451 Research
 
A public discussion about privacy careers: Training, certification and experi...
A public discussion about privacy careers: Training, certification and experi...A public discussion about privacy careers: Training, certification and experi...
A public discussion about privacy careers: Training, certification and experi...
 

Mais de Deepak Kumar (D3) (20)

Dark Web Forensics
Dark Web Forensics Dark Web Forensics
Dark Web Forensics
 
Cyber Threat Intel : Overview
Cyber Threat Intel : OverviewCyber Threat Intel : Overview
Cyber Threat Intel : Overview
 
Cyber of things 2.0
Cyber of things 2.0Cyber of things 2.0
Cyber of things 2.0
 
Cyber Forensics
Cyber Forensics Cyber Forensics
Cyber Forensics
 
Threat Intelligence
Threat IntelligenceThreat Intelligence
Threat Intelligence
 
THINK
THINKTHINK
THINK
 
Cyber Security Tips
Cyber Security TipsCyber Security Tips
Cyber Security Tips
 
CISSP INFORGRAPH MINDMAP
CISSP INFORGRAPH MINDMAPCISSP INFORGRAPH MINDMAP
CISSP INFORGRAPH MINDMAP
 
Cyber Forensics & Challenges
Cyber Forensics & ChallengesCyber Forensics & Challenges
Cyber Forensics & Challenges
 
Cyber Crime Types & Tips
Cyber Crime Types & TipsCyber Crime Types & Tips
Cyber Crime Types & Tips
 
Cyber Security India & Cyber Crime
Cyber Security India & Cyber CrimeCyber Security India & Cyber Crime
Cyber Security India & Cyber Crime
 
21st Century Cyber Forensics
21st Century Cyber Forensics21st Century Cyber Forensics
21st Century Cyber Forensics
 
C3 Cyber
C3 CyberC3 Cyber
C3 Cyber
 
Bitcoin
BitcoinBitcoin
Bitcoin
 
Ransomware
Ransomware Ransomware
Ransomware
 
Success Mantra
Success MantraSuccess Mantra
Success Mantra
 
Facebook Security Tips
Facebook Security TipsFacebook Security Tips
Facebook Security Tips
 
DDOS
DDOS DDOS
DDOS
 
Registry Registrar Registrant
Registry Registrar RegistrantRegistry Registrar Registrant
Registry Registrar Registrant
 
Whatsapp
WhatsappWhatsapp
Whatsapp
 

Último

Scientific Writing :Research Discourse
Scientific  Writing :Research  DiscourseScientific  Writing :Research  Discourse
Scientific Writing :Research DiscourseAnita GoswamiGiri
 
4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptx4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptxmary850239
 
Employablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptxEmployablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptxryandux83rd
 
Indexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdfIndexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdfChristalin Nelson
 
Team Lead Succeed – Helping you and your team achieve high-performance teamwo...
Team Lead Succeed – Helping you and your team achieve high-performance teamwo...Team Lead Succeed – Helping you and your team achieve high-performance teamwo...
Team Lead Succeed – Helping you and your team achieve high-performance teamwo...Association for Project Management
 
An Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERPAn Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERPCeline George
 
The role of Geography in climate education: science and active citizenship
The role of Geography in climate education: science and active citizenshipThe role of Geography in climate education: science and active citizenship
The role of Geography in climate education: science and active citizenshipKarl Donert
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Projectjordimapav
 
6 ways Samsung’s Interactive Display powered by Android changes the classroom
6 ways Samsung’s Interactive Display powered by Android changes the classroom6 ways Samsung’s Interactive Display powered by Android changes the classroom
6 ways Samsung’s Interactive Display powered by Android changes the classroomSamsung Business USA
 
4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptx4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptxmary850239
 
BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...
BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...
BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...Nguyen Thanh Tu Collection
 
Mythology Quiz-4th April 2024, Quiz Club NITW
Mythology Quiz-4th April 2024, Quiz Club NITWMythology Quiz-4th April 2024, Quiz Club NITW
Mythology Quiz-4th April 2024, Quiz Club NITWQuiz Club NITW
 
Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...
Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...
Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...DhatriParmar
 
Objectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptxObjectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptxMadhavi Dharankar
 
Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Celine George
 
DBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdfDBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdfChristalin Nelson
 
Q-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITWQ-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITWQuiz Club NITW
 
DiskStorage_BasicFileStructuresandHashing.pdf
DiskStorage_BasicFileStructuresandHashing.pdfDiskStorage_BasicFileStructuresandHashing.pdf
DiskStorage_BasicFileStructuresandHashing.pdfChristalin Nelson
 

Último (20)

Scientific Writing :Research Discourse
Scientific  Writing :Research  DiscourseScientific  Writing :Research  Discourse
Scientific Writing :Research Discourse
 
4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptx4.11.24 Poverty and Inequality in America.pptx
4.11.24 Poverty and Inequality in America.pptx
 
Employablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptxEmployablity presentation and Future Career Plan.pptx
Employablity presentation and Future Career Plan.pptx
 
Spearman's correlation,Formula,Advantages,
Spearman's correlation,Formula,Advantages,Spearman's correlation,Formula,Advantages,
Spearman's correlation,Formula,Advantages,
 
Indexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdfIndexing Structures in Database Management system.pdf
Indexing Structures in Database Management system.pdf
 
Team Lead Succeed – Helping you and your team achieve high-performance teamwo...
Team Lead Succeed – Helping you and your team achieve high-performance teamwo...Team Lead Succeed – Helping you and your team achieve high-performance teamwo...
Team Lead Succeed – Helping you and your team achieve high-performance teamwo...
 
An Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERPAn Overview of the Calendar App in Odoo 17 ERP
An Overview of the Calendar App in Odoo 17 ERP
 
The role of Geography in climate education: science and active citizenship
The role of Geography in climate education: science and active citizenshipThe role of Geography in climate education: science and active citizenship
The role of Geography in climate education: science and active citizenship
 
ClimART Action | eTwinning Project
ClimART Action    |    eTwinning ProjectClimART Action    |    eTwinning Project
ClimART Action | eTwinning Project
 
6 ways Samsung’s Interactive Display powered by Android changes the classroom
6 ways Samsung’s Interactive Display powered by Android changes the classroom6 ways Samsung’s Interactive Display powered by Android changes the classroom
6 ways Samsung’s Interactive Display powered by Android changes the classroom
 
4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptx4.9.24 School Desegregation in Boston.pptx
4.9.24 School Desegregation in Boston.pptx
 
BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...
BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...
BÀI TẬP BỔ TRỢ TIẾNG ANH 11 THEO ĐƠN VỊ BÀI HỌC - CẢ NĂM - CÓ FILE NGHE (GLOB...
 
Mythology Quiz-4th April 2024, Quiz Club NITW
Mythology Quiz-4th April 2024, Quiz Club NITWMythology Quiz-4th April 2024, Quiz Club NITW
Mythology Quiz-4th April 2024, Quiz Club NITW
 
Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...
Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...
Blowin' in the Wind of Caste_ Bob Dylan's Song as a Catalyst for Social Justi...
 
Objectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptxObjectives n learning outcoms - MD 20240404.pptx
Objectives n learning outcoms - MD 20240404.pptx
 
Introduction to Research ,Need for research, Need for design of Experiments, ...
Introduction to Research ,Need for research, Need for design of Experiments, ...Introduction to Research ,Need for research, Need for design of Experiments, ...
Introduction to Research ,Need for research, Need for design of Experiments, ...
 
Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17Tree View Decoration Attribute in the Odoo 17
Tree View Decoration Attribute in the Odoo 17
 
DBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdfDBMSArchitecture_QueryProcessingandOptimization.pdf
DBMSArchitecture_QueryProcessingandOptimization.pdf
 
Q-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITWQ-Factor General Quiz-7th April 2024, Quiz Club NITW
Q-Factor General Quiz-7th April 2024, Quiz Club NITW
 
DiskStorage_BasicFileStructuresandHashing.pdf
DiskStorage_BasicFileStructuresandHashing.pdfDiskStorage_BasicFileStructuresandHashing.pdf
DiskStorage_BasicFileStructuresandHashing.pdf
 

Information Security : A look

  • 1. Breaking in to Security 2 INFORMATION SECURITY : A SHORT VIEW
  • 2. “I’d like to get a job in security, how do I get started?” 6
  • 3. “What programming language do I need to learn to be a penetration tester?” 7
  • 5. Answering these one at a time is inefficient, biased and time consuming 9
  • 6. Lets ask the community and get a definitive answer 10
  • 7. 11
  • 8. But before we get started... 12
  • 9. Is this what you want to be? 13
  • 12. A lot of time in here 16
  • 15. For those still here, lets look at some stats 19
  • 16. <1year 22 7% 1-3years 64 22% 4-7years 81 27% 7+years 128 43% Time In Industry 20
  • 17. Penetrationtester 173 59% Vulnerabilityauditor 143 49% Sys-admin 130 45% IDS/Firewalladmin 102 35% Policywriter 97 33% Loganalyst 97 33% Incidentresponse 74 25% Other 66 23% Manager 64 22% Malwareanalyst 49 17% ITForensices 48 16% Reverseengineer 38 13% Exploitdeveloper 36 12% Helpdesk 35 12% PCIauditor 33 11% Job Types 21
  • 18. No,butithelps 182 62% Yes 78 26% Other 17 6% Don'tknow 12 4% No 6 2% Do you need to be able to program to be a pen-tester? 22
  • 19. Python 227 81% BashScripting 221 79% Ruby 122 43% C 116 41% WindowsPowershell 104 37% PHP 101 36% BatchScripting 102 36% C++ 62 22% Java 63 22% Other 51 18% Perl 46 16% VB 29 10% C# 25 9% Lua 23 8% What Language? 23
  • 20. Yes 144 49% Yes-butonlytogetthroughHR 137 46% No 14 5% Are Certifications Useful? 24
  • 21. SANS/GIAC 189 69% CISSP 187 68% OffensiveSecurity(PWB,AWEetc) 111 40% EC-Council(CEHetc) 64 23% CompTIA(Security+etc) 63 23% Vendorspecific 60 22% Other 55 20% CHECKTeamLeader(CREST/TigerScheme) 31 11% CHECKTeamMember(CREST/TigerScheme) 30 11% Which Certs? 25
  • 22. Other Certificates Include •OSSTIM •ISACA •Cisco •Microsoft •Linux/Unix •Whatever gets you the job •Anything management has heard of •Networking 26
  • 23. Yes 259 88% Other 24 8% No 12 4% Are Conferences Worth Attending? 27
  • 24. Which Ones? All of them got a mention 28
  • 25. That’s the end of the stats 29
  • 26. What do you know now that you wish you'd known when starting out? 31
  • 27. People skills, managing management and clients “I think it's important to note that information security is a role in a company that involves dealing with people. Brush up on your public speaking and negotiation skills. I'm much better at hacking silicon than I am hacking carbon, but each is important. Take time to learn and practice those soft skills.” 32
  • 28. Business skills “Business skills are more important than technical skills.” 33
  • 29. Report writing skills “It's all about the report... you can be the best penetration tester in the world, but if your report sucks, so does your test!” 34
  • 30. Networking is important “Get out there and network, don't be shy we are a friendly lot” 35
  • 31. You can't secure everything and can't be 100% secure so live with it “Security is a balance between risk mitigation and corporate earnings. Companies must continue making money to pay your salary. Ergo, the best security may not be the right security.” 36
  • 32. “You will live in hotels” “Pen testing is not so glamorous as it appears” 37
  • 33. “Cons are bad for your liver” 38
  • 34. What one piece advice would you give to someone wanting to start a career in security? 39
  • 35. Learn, learn and learn some more “Study hard, do the labs and exercises, experiment with tools.” 40
  • 36. You need your own lab “Set a lab environment up to practice with, virtualisation makes these easy these days.” 41
  • 37. Get an all-round education “Develop skills in other areas of IT (system administration, network management, development, etc.) either before or in addition to InfoSec.” 42
  • 38. Make sure you enjoy what you do “Do it for love of what you do, not to make money. The money is good, but if you really enjoy it, it's the best job in the world.” “Make sure its something you really want and can keep up with, not just something you enjoy on the side.” 43
  • 39. More about soft skills and business knowledge “Be tolerant of the non-techs, teach them, but don't talk down to them. Be aware that sometimes, the business needs trump security best practices.” 44
  • 40. Repeated from earlier, programming is a useful skill “Learn to program (scripting at least).” 45
  • 41. Get yourself known “To get involved in different projects and contribute, there are a lot of open source projects you can contribute to in different ways.” 46
  • 42. “It's all about reputation. Certs are useful, but if you are unknown you won't be taken seriously. Get out there, meet people, and learn from them!” 47
  • 43. “Start a blog.. not for fame and glory but more for keeping a record of what you learn. Doesn't matter if no one reads it, do it for yourself.” 48
  • 44. Find your local community - 2600, hackerspace, DC group “Find your local community & online community” 50
  • 45. Don’t just trust tools “Learn whats going behind the tools you are using” 51
  • 46. “Get in bed with the operations and finance people (not literally, however this might also help)” 52
  • 47. “Work your ass off! Everyone else does so you better get used to it.” 53
  • 48. Is it OK to “practice” on sites/ companies without permission if you don't do any damage? 54
  • 49. Overwhelming opinion - No, there are enough resources out there you don’t need to 55
  • 50. “Only if you want a new ‘room-mate’ called Bubba......” 56
  • 51. What I’ve not covered What do you see as the next up and coming area? Is there anything you feel you did wrong that you would advise against? 57
  • 52. Conclusions If you aren’t passionate it is just another job Get stuck in, learn and show your interest Don’t be afraid to ask questions - but show you’ve tried to find the answer yourself first It isn’t all about the tech 60
  • 53. Big thanks to all who responded 61
  • 54. Lets play a game, who wants a question answered? 62 Facebook/D3pak @D3pak Deepakniit14@gmail.com about.me/D3pak