defense in depth is dead, long live depth in defense · defense in depth is dead, long live depth...

36
#RSAC Matt Alderman Defense in Depth is Dead, Long Live Depth in Defense VP, Strategy Tenable Network Security @maldermania

Upload: hoangthuy

Post on 14-Feb-2019

242 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Matt Alderman

Defense in Depth is Dead, Long Live Depth in Defense

VP, StrategyTenable Network Security@maldermania

Page 2: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Eliminate Blind Spots

Page 3: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Prioritize Threats & Weaknesses

Page 4: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Reduce Exposure & Loss

Page 5: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Defense in Depth is Broken

Page 6: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

It’s Time to Transform Security

Page 7: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

• Physical & Virtual Devices• Applications & Databases• Mobile Devices• Cloud Services

• Vulnerability Assessment• Configuration Audit• Malware Detection

• Log Collection• Activity Monitoring• Packet Inspection• Threat Intelligence

• Event Correlation• Anomaly Detection• Behavior Analysis• Dashboards and Reports

• Notification and Alerting• Remediation Workflow• Patch Management

• Patch Installation• Configuration Changes• Port/Service Modification• Device Isolation

Depth in Defense Approach

Action Visibility

Context

Page 8: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Visibility Context Action

Benefits of Depth in Defense

Page 9: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Applying Depth in Defense

Do you have continuous visibility into unknown or shadow assets?

Do you have continuous visibility into the security “state” of your assets?

Do you have critical context to prioritize threats and weaknesses?

Do you have critical context to measure security posture and assurance?

Are you able to take decisive actions to respond to attacks?

Are you able to take decisive actions to protect your assets?

Page 10: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Thank You

Matt [email protected]@maldermania

Page 11: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

John G. O’Leary, CISSP

Garbo, D-Day and Ultimate Social Engineering

O’Leary Management Education

Page 12: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

The Setting

Page 13: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

The Setting

Page 14: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Operation Fortitude Spies -

Page 15: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Juan Pujol Garcia

Graduate of Royal Poultry School

Ran poultry farm outside Barcelona

Cinema proprietor

Cavalry officer

hated chickens

feared horses

terrible businessman

Page 16: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Try and Try Again

Jan 1941 - British in Madrid

“No Thanks”

Juan or Ariceli

British wanted Spain neutral

Plan B - got the Germans to believe he wanted to spy for them

Page 17: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Lisbon to London

Page 18: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Garbo’s “Network”

Page 19: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Garbo’s Influence

Page 20: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Tweaking the Nazis

olbeks

Page 21: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Imaginary Agents, Realistic problems

Girlfriend

Gambling debts

Fear of capture

No appreciation

Fistfights

Page 22: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Finances

$1.4 million from Germans for Double Cross

Funding their own deception

Skimming by middlemen

Page 23: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

D-Day Deception

Start with truth, but little value

Gradually add lies

Still some nuggets of truth

Point away from Normandy

Page 24: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Early 1944, not just reports

Analysis

Drawing conclusions

Aim - not just influence, but replace their intelligence service

D-Day Deception

Page 25: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Post-D-Day – June 9

Stop the Panzers

“It’s just a diversion”

“Patton’s coming with FUSAG”

Page 26: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Awards and Commendations

Page 27: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Aftermath

Pujol effectively disappeared with his Iron CrossDivorced AracelliRemarried – new family in VenezuelaQuiet, relatively anonymous life Still followed trade craft and didn’t trust anyone

Page 28: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Aftermath

D-Day ceremonies in 1970’s

Brought to tears by rows of crosses at Normandy

“I didn’t do enough”Oct 10, 1988

Page 29: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Lessons

Know your audience

Know your “mark”

Don’t be too perfect

Page 30: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Lessons

Complain a lot

Page 31: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Lessons

Emphasize the prime deception point but don’t come right out and say it; let them draw conclusions

Page 32: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Lessons

Strengthen your handTell them about Normandy 3 hours before invasionChastise them for not responding

Page 34: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Lessons

What they think is important

What they do is crucial

Page 35: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

Final Words

Page 36: Defense in Depth is Dead, Long Live Depth in Defense · Defense in Depth is Dead, Long Live Depth in Defense. VP, Strategy. Tenable Network Security. @maldermania. #RSAC Eliminate

#RSAC

John G. O’Leary, CISSP

Garbo, D-Day and Ultimate Social Engineering

O’Leary Management Education