Showing posts with label CyberSecurity. Show all posts
Showing posts with label CyberSecurity. Show all posts

Wednesday, December 13, 2017

Listening In - A MUST Read Cybersecurity Book by Susan Landau


If I had to summarize why I loved working at Sun Microsystems so much, it would be the brilliant people I was able to meet, work with and we became friends.

Susan Landau was a Distinguished Engineer at Sun.  She is an Association for Computing Machinery Fellow, a Cybersecurity Hall of Fame inductee and an American Association for the Advancement of Science Fellow.  Susan is a globally recognized expert in security.

I had the pleasure of meeting Susan while we were both at Sun.  We had a number of very interesting conversations while we were at Sun, as well a number of conversations since Sun was purchased.  The conversations we had and have were always enlightening, interesting and very educational for me.

Susan wrote a book titled Listening In - Cybersecurity in an Insecure Age and sent me a signed copy.  This is an excellent book and a must read whether or not you are a geek like me, a policy maker, someone who has an interest in security or just your average citizen.  Susan's book is extremely well written and well researched.  She is able to educate the reader on Cybersecurity in a clear and compelling fashion.  You do not need a mathematical, computer science or technical background to learn a ton from this book. My hope would be Susan's book would be embraced by policy makers and citizens around the globe as she does an excellent job explaining the proper role and balance of government in providing national security and law enforcement through numerous real life examples.

When I first got the book and looked at the back cover and saw recommendations from Vint Cert, Jonathan Ziltrain, Matt Olsen (former Director NCTC) and Juliette Kayyem (former Assistant Secretary for Homeland Security), I knew this just moved to the top of my reading queue!

Susan did reach out to me to discuss security in the area of manufacturing.  We had a few phone conversations and email discussions.  I was thrilled to see that Susan referenced an article I wrote for Advanced Manufacturing titled, With Machine Monitoring, Instant ROI is Possible and my book, MTConnect: To Measure Is To Know.  Thanks Susan!

Bottom line is that this a GREAT book and a MUST read for everyone.

Saturday, June 24, 2017

Malware on the Electric Grid


  Jim Finkle wrote a very nice article:

Cybersecurity Firms Uncover Malware That Could Cause Power Outages Around The Globe 

The sub-title is: “This could cause wide-scale damage to infrastructure systems that are vital.”

 Mr. Finkle starts off:

"Two cyber security firms have uncovered malicious software that they believe caused a December 2016 Ukraine power outage, they said on Monday, warning the malware could be easily modified to harm critical infrastructure operations around the globe.

ESET, a Slovakian anti-virus software maker, and Dragos Inc, a U.S. critical-infrastructure security firm, released detailed analyzes of the malware, known as Industroyer or Crash Override, and issued private alerts to governments and infrastructure operators to help them defend against the threat."

 It's interesting that I have had these conversations with friends and they conflate Y2K with grid malware and don't believe it is possible.

What is scary, is how easy it can be to use these malware tools as is stated below:

“The malware is really easy to re-purpose and use against other targets. That is definitely alarming,” said ESET malware researcher Robert Lipovsky said in a telephone interview. “This could cause wide-scale damage to infrastructure systems that are vital.”
The Department of Homeland Security corroborated that warning, saying it was working to better understand the threat posed by Crash Override.
“The tactics, techniques and procedures described as part of the Crash Override malware could be modified to target U.S. critical information networks and systems,” the agency said in an alert posted on its website."



Sunday, May 23, 2010

30,000 New CyberSecurity Jobs

There is an ad in today's Washington Post from University of Maryland University College for a BS or MS in CyberSecurity.  UMUC offers both CyberSecurity and CyberSecurity Policy BS and MS degrees.  The ad points out that there will be an estimated 30,000 new jobs in CyberSecurity which I easily believe.

I don't have a clue if this is a quality curriculum or not.  What I do know is that this is sorely needed in the computer industry.  When we have our first major cyber security attack that affects the United States or any other country in a significant fashion, then we will see these CyberSecurity job numbers jump.   This is not something that you take your typical sysadmin and ask them to "worry about security a little more".  I know that many non computer industry individuals were lulled to sleep when we did not see some of the predicted Y2K meltdowns never happened.

I would imagine that some of the nearby government security agencies (hopefully) had a great deal of input to UMUC's new CyberSecurity Programs.   This is where government and industry do need to work together as well as working with other countries.




The Obama administration plan, to some extent, builds on the Bush administration's Comprehensive National Cybersecurity Initiative (CNCI). Among items of interest to the federal workforce, a 12-point CNCI summary calls for:


• Continuation of the Trusted Internet Connections (TIC) initiative, meant to reduce the number of connections between government computers and the Internet.
• Deployment of an intrusion detection system of sensors across the government.
• Coordination of research and development across government.
• Development of a pipeline of skilled cybersecurity employees.
• Coordination and cooperation with the private sector to address security matters of common interest.
That last item, public-private cooperation, has drawn considerable attention. There's wide agreement that the expertise of the private sector ought to be aligned with the security needs of government.
"To secure our country from cyber attacks, we must have shared responsibility between the government and the private sector," Sen. Jay Rockefeller, D-W.Va., told the Business Software Alliance Cybersecurity Forum in April.
At the same time, some in the private sector warn that industry may not be ready to work with government and vice versa.
"There has been no effort in terms of ironing out the legalities," said Pat Clawson, CEO of security and vulnerability technologies firm Lumension.


It will be interesting to see what other universities and colleges will follow the CyberSecurity path in the CS curriculums.