how to rob a bank in the 21st century - pki version

55
How To Rob A Bank In The 21 st Century March 2015 Lim Chin Wan

Upload: chin-wan-lim

Post on 16-Jul-2015

82 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: How To Rob A Bank In The 21st Century - PKI Version

How To Rob A Bank In The 21st CenturyMarch 2015

Lim Chin Wan

Page 2: How To Rob A Bank In The 21st Century - PKI Version

Have you ever wanted to rob a bank?

Page 3: How To Rob A Bank In The 21st Century - PKI Version

DOING IT THE OLD SCHOOL WAY?

Page 4: How To Rob A Bank In The 21st Century - PKI Version

Hacking A Bank Is Easy Because We’re

All Humans!

Page 5: How To Rob A Bank In The 21st Century - PKI Version

I think you should meet someone…

Page 6: How To Rob A Bank In The 21st Century - PKI Version

This is Yuri.

In 2012, he and his “anonymous” friends hacked major bank.

In 2013, they hacked credit card company and bought a BMW.

Page 7: How To Rob A Bank In The 21st Century - PKI Version

Last year, Yuri hit a major telco with the secret keys provided by a disgruntled employee.

Then Yuri went on a nice 2 month long vacation in the Caribbean Islands.

Page 8: How To Rob A Bank In The 21st Century - PKI Version

Banks and telcos all used “State of the Art” encryption… yet they

were still hacked!

Page 9: How To Rob A Bank In The 21st Century - PKI Version

So how does Yuri do it?

Page 10: How To Rob A Bank In The 21st Century - PKI Version

“Usually, I just find one disgruntled employee. Just one.”

Page 11: How To Rob A Bank In The 21st Century - PKI Version
Page 12: How To Rob A Bank In The 21st Century - PKI Version

Don’t Believe Me?

Let’s Play A Game…

Page 13: How To Rob A Bank In The 21st Century - PKI Version

Can Anyone Tell Me Who These

People Are?

Page 14: How To Rob A Bank In The 21st Century - PKI Version

Heidi KlumJessica Alba

Page 15: How To Rob A Bank In The 21st Century - PKI Version

Britney Spears

Page 16: How To Rob A Bank In The 21st Century - PKI Version

Christina

Aguilera

Page 17: How To Rob A Bank In The 21st Century - PKI Version

Scarlett Johansson

Kate

Winslet

Page 18: How To Rob A Bank In The 21st Century - PKI Version

Jon Bon Jovi

Page 19: How To Rob A Bank In The 21st Century - PKI Version

RATED TOP 20 MOST DANGEROUS CELEBRITIES IN 2014

BY

McAfee

Page 20: How To Rob A Bank In The 21st Century - PKI Version

18.19%

Page 21: How To Rob A Bank In The 21st Century - PKI Version
Page 22: How To Rob A Bank In The 21st Century - PKI Version

Because your users are your weakest link…

Page 23: How To Rob A Bank In The 21st Century - PKI Version

They are your customers…

They are your Employees...

They are your vendors…

Page 24: How To Rob A Bank In The 21st Century - PKI Version

Regular Training…

Page 25: How To Rob A Bank In The 21st Century - PKI Version

www.securityvitamins.com

Page 26: How To Rob A Bank In The 21st Century - PKI Version
Page 27: How To Rob A Bank In The 21st Century - PKI Version
Page 28: How To Rob A Bank In The 21st Century - PKI Version

How can you as a bank protect your customers and

yourself?

Page 29: How To Rob A Bank In The 21st Century - PKI Version

CENTAGATE (Centralized Authentication Gateway) is an on-demand identification and access management services that enable cloud-based services to adopt strong multi-factor authentication seamlessly. This is a perfect solution for enterprise applications that are now rapidly moving to a secure, cloud-based services.

Next-Gen Adaptive IntelligentAuthentication Platform

Page 30: How To Rob A Bank In The 21st Century - PKI Version

N1.1

N1.2

N1.3 Machine LearningTransaction & Authentication Specific

Hybrid ModelRules Based & Case Based

Openness

Hybrid Adaptive Intelligence Scoring Engine

Page 31: How To Rob A Bank In The 21st Century - PKI Version

Implement Server-to-Server Authentication using PKI

Page 32: How To Rob A Bank In The 21st Century - PKI Version

What is PKI?

Page 33: How To Rob A Bank In The 21st Century - PKI Version

Public Key Infrastructure

Public Key

Private Key

Page 34: How To Rob A Bank In The 21st Century - PKI Version

What is a Certificate Authority?

Page 35: How To Rob A Bank In The 21st Century - PKI Version

SECRET

MARY’SPublic Key

IDEAL WORLD

MESSAGE

+ENCRYPTED MESSAGE

Page 36: How To Rob A Bank In The 21st Century - PKI Version

REAL WORLD

SECRET

Fake MARY’S

Public Key

MESSAGE

+ENCRYPTED MESSAGE

MARY’SPublic Key

MODIFIED ENCRYPTED MESSAGE

+

Page 37: How To Rob A Bank In The 21st Century - PKI Version

HOW TO SOLVE PROBLEM?

SECRET

MESSAGE

+ENCRYPTED MESSAGE

MARY’SPublic Key

Page 38: How To Rob A Bank In The 21st Century - PKI Version

We are

going round

in circle!

Page 39: How To Rob A Bank In The 21st Century - PKI Version

PROBLEM SOLVED

CPS & CP

CERTIFICATE AUTHORITY

Page 40: How To Rob A Bank In The 21st Century - PKI Version

Diffie-Hellman Key Exchange Explained

Page 41: How To Rob A Bank In The 21st Century - PKI Version
Page 42: How To Rob A Bank In The 21st Century - PKI Version

Why banks should use digital certificates?

Page 43: How To Rob A Bank In The 21st Century - PKI Version

Your typical server room scene

How many servers do you have?

Page 44: How To Rob A Bank In The 21st Century - PKI Version

How many servers are talking to each other?

Which server is talking to which server?

How do you take control of your servers?

How many vendors do you have logged onto your servers?

Page 45: How To Rob A Bank In The 21st Century - PKI Version

Assign each server a digital certificate

Page 46: How To Rob A Bank In The 21st Century - PKI Version

Digital Certificates Provides

Identity to each server

Expiry date

Page 47: How To Rob A Bank In The 21st Century - PKI Version

How much does it cost?

Page 48: How To Rob A Bank In The 21st Century - PKI Version
Page 49: How To Rob A Bank In The 21st Century - PKI Version

Wow! So expensive!

Page 50: How To Rob A Bank In The 21st Century - PKI Version

Become my own CA!

Next generation PKI

Page 51: How To Rob A Bank In The 21st Century - PKI Version

51

Why a PKI Appliance?

• Make deployments easier and faster

• Minimize installation/integration efforts

• Lower the TCO with simplified management and maintenance

• Provide one source for Software/Hardware stack

Page 52: How To Rob A Bank In The 21st Century - PKI Version

A PKI Appliance Gives You...

• Overview of all your servers in your data centre

• Better security via Server-to-Server authentication

• Control over who can access your servers

• Easy management of your server access

Page 53: How To Rob A Bank In The 21st Century - PKI Version

?

Page 54: How To Rob A Bank In The 21st Century - PKI Version
Page 55: How To Rob A Bank In The 21st Century - PKI Version

Questions?

SecureMetric Technology Group

Lim Chin Wan

Mobile : +6 016 261 8925Office : +603 8996 [email protected]

Formula for Strong Digital [email protected] www.securemetric.com