usstratcom cyber & space 2011 david white

4
Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04- 94AL85000. 2011-8664 C Managing the Right Risks David White, PhD Senior Manager Sandia National Laboratories November 16, 2011

Upload: afcea-international

Post on 22-Nov-2014

658 views

Category:

Technology


1 download

DESCRIPTION

Session Seven: Panel: Alternative Futures for Cyber and Space - David White

TRANSCRIPT

Page 1: USSTRATCOM Cyber & Space 2011 David White

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL85000. 2011-8664 C  

Managing the Right Risks

David White, PhDSenior Manager

Sandia National Laboratories

November 16, 2011

Page 2: USSTRATCOM Cyber & Space 2011 David White

Full Spectrum Cyber Defense Requires Understanding the Adversary

ClanTech Cyber Special Liaison DeceptionSigintHumanEntry CoverCompany

Full Spectrum of Offensive Methods

SCADA Weapons Network C2 Logistics SwitchesSatellite

CommonPerception

ofCND

Defenses:FirewallSpywareVirusIDS

Cyber

SIPRNET

Targets – Microelectronics and Software Elements

Adversary Determines time, place, combination of methods, and operates in secret

Reality ofCND

Defender must be successful everywhere, continuously, and frequently in the open

Source: J. Gosler – Vaults, Mirrors, Masks: Rediscovering U.S. Counterintelligence

Page 3: USSTRATCOM Cyber & Space 2011 David White

Are we driving the right behavior?

*http://xkcd.com/936

Page 4: USSTRATCOM Cyber & Space 2011 David White

Machine Generated PasswordsTwo Factor

Authentication

Compliance

Spear Phishing

Supply Chain

Attacks

“Pass the hash”