fissea 2015 conference, march 24-25 - evaluating …fissea 2015 conference, march 24-25 - evaluating...

22
Evaluating the Security Implications of Innovation: Risk and Risk Reduction in the Internet of Everything UMUC Faculty Presentation to FISSEA 2015 Valorie King, Richard White, Sam Chun

Upload: others

Post on 08-Aug-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Evaluating the Security

Implications of Innovation:

Risk and Risk Reduction in the

Internet of Everything

UMUC Faculty Presentation to FISSEA 2015

Valorie King, Richard White, Sam Chun

Page 2: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Is this the Internet of Everything?

Page 3: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Or, is this how you see the IoE?

Page 4: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

INNOVATIONS

Page 5: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Quantized Self

• Body Sensors (Tattoos, Electro Myographics)– Gestures

– Authentication

– Threat Detection (CBRNE)

• Wearable Computers – Communications & Productivity

– Health & Fitness

– Augmented Reality (input / feedback)

• Implants & Medical Devices – Body Area Networks

– Medication Delivery

– Monitor / Augment internal systems

– Prosthetics

Page 6: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Infrastructures & Technologies

• Smart Homes

• Smart Communities

• Autonomous Vehicles

• Intelligent Transportation Infrastructures

• Utilities Infrastructures & Advanced

Metering

• Banking Sector & Digital Currencies

Page 7: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Enabling Technologies

• Graphene

• Neuromorphic Chips

• Brain-Computer Interfaces

• Physical Unclonable Functions (PUFs)

• Dielectric thin films

• Magneto-electric magnetic sensors

• Nano imprinting

• Nano machines

Page 8: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

TECHNOLOGY REVIEWS

Page 9: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Technology Transfer

• Technology Identification & Maturation

– Identifying promising technologies in R&D phases

– helping technologies emerge from the R&D environment

• Technology Transfer Processes (Universities)

• Technology Transfer Initiatives (DHS, DOE)

• Influence of funding availability & sources, i.e. venture capital, government grants, etc.

Page 10: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Technology Development Life Cycle

Image Source: http://www.atp.nist.gov/eao/gcr02-841/chapt2.htm

Page 11: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Technology Identification &

Evaluation Process

Page 12: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

RISK IDENTIFICATION

Page 13: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Cybersecurity & Emerging Tech

• Incorporating emerging technologies into products and services

– What security features are needed?

– Can we predict how these features will fail?

– Can we identify potential or expected cybersecurity:• Gaps

• Risks

• Vulnerabilities

Page 14: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Evaluation Methodologies

• Analysis of Alternatives

• Case Studies

• Delphi Technique (Expert Panels)

• Experiments

• Gap Analyses

• Meta-Analyses (Published Research)

• Pilot Studies & Implementations

• Product Assurance

• Risk Assessments

Page 15: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Analysis of Alternatives

Page 16: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Experiment-Based Evaluations

Page 17: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

RISK REDUCTION

Page 18: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Two Key Questions

• How can this technology or emerging application of technology be used to improve or support the security of devices and services which comprise the Internet of Everything?

• How can this technology be used by attackers, criminals, terrorists, etc. to achieve their goals and objectives within the context of the Internet of Everything?

Page 19: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

SUMMARY & CONCLUSIONS

Page 20: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Cybersecurity for the IoE:

Built-in or Bolted-on?

Image Source: http://www.atp.nist.gov/eao/gcr02-841/chapt2.htm

Page 21: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Questions?

Page 22: FISSEA 2015 Conference, March 24-25 - Evaluating …FISSEA 2015 Conference, March 24-25 - Evaluating the Security Implications of Innovation, Risk, and Risk Reduction in the Internet

Contact Information

• Valorie King (Course Chair):

[email protected]

• Richard White (Course Chair):

[email protected]

• Samuel Chun (Faculty Member):

[email protected]