bcc risk advisory irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

23
Vulnerability Management by the numbers and dumb robots!

Upload: eoinkeary

Post on 21-Jun-2015

108 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Vulnerability Management by the numbers and dumb robots!

Page 2: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Rahim Jina• Director BCC Risk Advisory• OWASP Contributor• edgescan.com• Ex-Head of Security of

Fonality• Ex-Big 4 Consultant

• CTO BCC Risk Advisory• OWASP GLOBAL BOARD

MEMBER• Architect edgescan.com

Eoin Keary

Page 3: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

RISK

Page 4: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Automation

+

Page 5: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Automation

Page 6: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Automation

Page 7: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Fraud – Technical Vulns

Page 8: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

“(Cyber crime is the) second cause of economic crime experienced by the financial services sector” – PwC

2012 Cyber Crime• US $20.7 billion in direct losses • Global $110 billion in direct losses• Global $338 billion + downtime

“556 million adults across the world have first-hand experience of cybercrime -- more than the entire population of the European Union.”

Globally, every second, 18 adults become victims of cybercrime- Symantec

“The loss of industrial information and intellectual property through cyber espionage constitutes the greatest transfer of wealth in history” - Keith Alexander

Almost 1 trillion USD was spent in 2012 protecting against cybercrime

“Jimmy, I didn’t click it” – My Grandma

“One hundred BILLION dollars” - Dr Evil

Page 9: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Fraud – Logic Vulns

“40% of applications tested by BCC Risk Advisory in the last 12 months had a critical business logic vulnerability”

Page 10: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 1 – Loan Calculator & Approval

Page 11: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 1 – Loan Calculator & Approval

$20,000

Page 12: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 2 – Coupon Abuse

Stacking Trust the Machine

DISC10

Page 13: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 2 – Coupon Stacking

90%

Page 14: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 3 – Flight Booking

Page 15: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 3 – Flight Booking

Page 16: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 4 – e-Auction

Page 17: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 4 – e-Auction

Page 18: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 5 – e-Dating

Page 19: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Example 5 – e-Dating

Page 20: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

What’s your point?

• Robots don’t understand true love• SIMPLE• COMMON• LEGALITIES

Page 21: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

Really, what’s your point?

• There is no big button• Automation helps but is only part of the

solution• Continuous testing & assessment• Pure blackbox tests are dumb• Onion Approach

SECURE NOW

HACK NOW

Page 22: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

“We need an Onion”

SDL Design reviewThreat ModelingCode review/SAST

Negative use/abuse cases/Fuzzing/DAST

Live/ Continuous/Frequent monitoring / Testing Ongoing Manual Validation

Vulnerability management & PriorityDependency Management ….

Robots are good at detecting known unknownsHumans are good at detecting unknown unknowns

Page 23: Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers and dumb robots!-2

www.bccriskadvisory.com

© BCC Risk Advisory Ltd 2013. All rights reserved.

Thanks for Listening

[email protected]

Some websites were harmed during the making of this presentation