education and research in the area of cybercrime · • police – sharing of knowledge and tools,...

21
Education and research in the area of cybercrime Václav Stupka Czech CyberCrime Centre of Excellence

Upload: others

Post on 29-Oct-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Education andresearch inthe areaof cybercrime

VáclavStupkaCzechCyberCrimeCentreofExcellence

Page 2: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Why it all started?• Demand for research anddevelopment intheareaof cybercrime

• MasarykUniversity– Instituteof law andtechnology&CSIRT-MU– Instituteof computer science– Faculty of Informatics– Faculty of social science– etc.(ad-hoccooperation)

Page 3: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

• Focusontechnologylaw(ICTlaw,dataprotection,intellectualpropertylaw,energylaw,etc.)

• Longtermcooperationwithpublicauthorities• Expertiseintheareaofcybercrime&cybersecurity

• http://cyber.law.muni.cz

Instituteoflawandtechnology

Page 4: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

CSIRT-MU• ComputerSecurityIncidentResponseTeamofMasarykUniversity

• PartoftheInstituteofComputerScience• AccreditedbyTrustedIntroducer• LongtermexperiencewithR&Dinthefieldofnetworksecuritymonitoring

• http://csirt.muni.cz

Page 5: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Howitallstarted?• Cooperation(CSIRT-MU,ILT,RAC&partners)• Growingdemandforexpertadvices• Abilitytofindcommonlanguage• EstablishmentofC4e– ECDGHomeproject(2013)

• https://www.C4e.cz

Page 6: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Whatdowedo?• Cooperation• Research• Education• Development• Consultations

Page 7: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Cooperation• Whattofocuson?• Whatdowe(orsomeoneelse)alreadyknow?• Whatcanweprovide/share?• Howcanwecollaborate?

Page 8: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Internationalcooperation• Europol (EC3)

– taxonomy,– lectures forLEA

• ENISA– taxonomy– sharingofknowledge

• NATO– taxonomy,– studyprograms

• UN– sharingoftoolsandknowledge

• TF-CSIRT– sharingoftools,knowledge,bestpractices,etc.

• Nationalresearchandeducationinstitutions– ad-hoccooperation,researchprojects,sharingofknowledgeandtools

Page 9: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Nationalcooperation• NationalSecurityAuthority

– sharingofknowledgeandtools– trainingandeducation:coursesandexercises(CyberCzech)– attendance atexercises: LockedShields,CyberEurope,EDA

• Police– sharingofknowledgeandtools,consulting– trainingandeducation– cooperationwithPoliceacademy

• ArmyandMinistryofDefense– consulting

• Intelligence services– Consulting

• MinistryofInterior– Researchanddevelopmentprojects(KYPOlatertoday,SABU– sharingofcybersecurityeventsdata)

• Judicialacademy,Publicprosecutorsoffice,Judges– Trainingandeducation,consulting

• Expertboardoncybercrime andcybersecurity– Whattofocuson?

Page 10: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Cooperationwithprivateentities• Attendanceatconferencesandworkshops• Expertopinions• CERITsciencepark

Page 11: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Research• Legal– Substantiveandprocedurallaw– Whatisandshouldberegardedtoasthecybercrime?– Whatproceduresareandshouldbefollowedduringinvestigation?

– Howtoinvestigateit?– Howtohandleevidence?– Howtocooperateinternationally?– Howtocooperatewithprivateandpublicauthorities?

• Focusoftheresearchisdiscussedatthemeetingoftherectorsexpertadvisoryboard.

Page 12: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Education- national• Lecturesandtrainings

– Judicialandpoliceacademy(cybercrimeinvestigation,digitalevidencehandling,intellectualproperty,dataprotection)

– Ad-hoctrainings(forinvestigators,experts,publicprosecutors,etc.)

– KYPOhands-ontrainingandexercises(sysadmins,CSIRTmembers)

• Bachelordegree(ICTsecurity)withUniversityoftechnology

• Mastersdegree(Cybersecurity– interdisciplinaryandlaw)• Doctoralstudyprogramme

Page 13: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Education- international• Jointdoctoraldegree– withUniversityofHaifa

• Mastersstudyprogrames NATO(MultinationalCyberDefenseEducationandTrainingProject)

• Ad-hoccoursesandtrainings– NATO

Page 14: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Education- regularevents• Seminars:– iSysel– Cybercake

• Conferences– Cyberspace– Czechlawandinformationtechnologies

• SummerschoolonICTlaw

Page 15: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Development• Tools,• methodologies,• bestpractices.

Page 16: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Forensictools• Networkandhostforensics– Trafficreconstruction– Automatedfirstsightoverview

• Honeypots• Digitalforensiclaboratoryexaminationandmanagementsystem

• Tutorialsforusers&virtualimagewiththetools

Page 17: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

TaxonomyofCSI• ToolforCERTteamsandLEA• PreparedincooperationwithNSAandPolice,alsopresentedanddiscussedatENISA/Europolmeetings

• Individualtypesofcybersecurity incidents– Isitcrime?(czech lawandCoC)– Whotonotify?– Whatinformationtoshareandwithwhom?– Howtoproceed?– Howtohandleevidence?

Page 18: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Guidebookondigitalevidenceincriminalproceedings

• Generaloverviewofczech procedural lawrelatedtodigitalevidencehandling

• Guidanceforhandlingofspecifictypesofevidence:– Email– Personalprofiledata– Website– Trafficandlocationdata– Interceptionrecords– Mobiledevices– Cybersecurityincidentsdata

Page 19: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

BookonInterceptionanddataretention

• Analysisofthelegislatureandcaselawrelatedtointerceptionofelectroniccommunication

• Comparisonwithforeignapproaches• Liablility ofserviceproviders• ProceduraltoolsforLEA• Proceduraltoolsforinternationalcooperation• PartofstudyfromMaxPlanckInstitute

Page 20: Education and research in the area of cybercrime · • Police – sharing of knowledge and tools, consulting – training and education –cooperation with Police academy • Army

Plansforthefuture?• SENTER– followup projectfocusedon:StrengtheninternationalcooperationofCoEs

• Internationalresearchprojects(H2020)• MasterswithNATO• CyberOlympics– Estonianledinitiativeforhighschool student(participation)

• Doctoralstudies(withpublicauthorities)• Growthofthecenter– morespecializedlabs• Methodologiesbasedonthetaxonomy