Securing the Unsecurable

February 29, 2012, RSA Conference, San Francisco—Stuart McClure from McAfee called out the opportunity and challenges for the cloud to develop security over the next 10-15 years. The desire to take control of your own liberties and future runs up against the fact that the bad guys have it easier because they only need one access point.

Information protection has been around for a long time. Soon after writing was developed, the need for ciphers became necessary. Some information has life or death consequences and, even now, all communications are at risk because nothing is unbreakable. Last year was a mess.

Hollywood has known and shown hacking for along time. Some examples are R2D2 hack to add a message, War Games, and many others. The denizens of Hollywood are also likely victims, like Paris Hilton whose Bluetooth phone directory was hacked due to a simple password. We all heard of the News of the World phone hacking incidents. Script writers create scenarios like Mission Impossible-Ghost Protocol.

The opportunities for breaches are increasing, because the number of devices and their vulnerabilities are growing at an exponential rate. To make matters worse, most users make up easy passwords and systems operators have poor setups and escalating privileges. The hackers are getting new motivations for their efforts, and the leading-edge hacking abilities are improving even faster than the proliferation of devices.

The actors now have many sources to attack. Their motivations are to take information and convert it into money, or to cause disturbances. Some of the latest targets are the embedded systems including infrastructure and machinery. The cornucopia of techniques available for the hackers range from simple executables for script kiddies to very sophisticated, long-term attacks like RSA and Lockheed.

The challenges are that as computers evolved from mainframes to PCs to embedded systems, the operating systems have not been secure by design. For example, 483 M people have type I or type II diabetes. This is about 6.4 percent of the population and is the 7th largest killer in the US. Now, insulin delivery systems are wireless and the developers have never considered security.

A demonstration showed how one of these systems can be compromised. Using a laptop as a work platform, they scanned for the pump with a USB radio working in the 900 MHz medical and instrumentation band. When they found the pump, they retrieved pump data and were able to override the default settings and reprogram the pump for any volume of insulin through the laptop.

Everyone needs to evaluate emerging threats and know how to secure your systems. This effort is a change in fundamental thinking about security. First you have to go from a blacklist, post event mentality to a white-grey list. This behavior is much like getting sick, fist you go to se the doctor, get some tests, and then get treatment. Security needs diagnostics and protection, so you need to push protection and diagnostics to the bottom of the stack.

This protection starts with prevention of bios overwrite attacks. Eventually this function will be integrated into silicon, which will be much more secure than software. Security management needs to confirm integrity through a trusted bios and the identity of the user. Privacy and resiliency are moving to hardware-assisted security.

Historically, the early days of computing had no separation of OS and apps. In the ’80’s protected mode in the Intel processors separated the OS from the apps. In the early ’90’s execution control restricted apps to memory. Now, virtualization separates the OS and apps from the core hardware. Next, we will see isolation from other threads and apps.

Control privileges for execution and recovery will help in preventing bad stuff through blacklists and other measures. This move eventually will only allow known apps and data sources to operate in the system. In the next 3-5 years, we need to address the following list of functions.

1 all people and companies are targets. It’s not if, but when
2 botnets and DDoS
3 social networking and media
4 embedded systems
5 mobile and real and virtual currencies
6 cyber terrorism
7 trust landscape. SSL and other technologies are the root of trust
8 insider threats
9 cloud and virtual systems
10 cyber retaliation
11 zero day attacks
12 regulations
13 victimization and incident response
 

Similar Posts