Train Like You Will Fight Reliability First Workshop 1 October 2015 Dr. Joe Adams
Disclaimer 2 The content of this presentation is based on personal and professional experience of the speaker. The content is highly opinionated, personal, and full of behind the scenes stories. This presentation is intended to be thought provoking and provide an insider s view of training and exercises. The content, this presentation, and any of the jokes or comments made by the speaker are his and his alone, and do not represent the official position or opinions of Merit Network, Inc. or anyone else.
Introduction 3 Dr. Joe Adams Vice President of Research and Cyber Security Degrees in Computer Engineering Masters of Strategic Studies, US Army War College 26 years Army Signal Corps Associate Professor at US Military Academy 3 time winner of the NSA s Inter- Service Academy CDX Senior Member IEEE Distinguished Fellow, Ponemon Institute
Agenda 4 Why Defense? Building a Better Defender Elements of an Exercise Types of Exercises Tabletops Force on Force Capture the Flag Putting It All Together
Cyber-Attack Threat Cyber-Attacks Are the Biggest National Security Threat. Leon Panetta My greatest fear is that, rather than having a cyber Pearl Harbor event, we will instead have this death of a thousand cuts. Richard Clarke
The Mythical Air Gap 6
I Can See You 7
The Enemy Are Us 8
Cause First World Problems
Why Defense? Critical Infrastructure 85% owned by the private sector (GAO-07-39) Small Business Industrial Control Systems Enterprise Systems Only as strong as the weakest link
Privately Owned Infrastructure 11
Federal Response 12
Are You Ready? 13
Where Are We Going? 14
Building a Better Defender 15 Hack Back vs. Attribution IT Skills vs. Incident Response Teaching Offense to Learn Better Defense Ethics Play a Big Role
Building a Better Defender 16 Communication is the Key Skill Understanding the Architecture Where do you fit in? 2 nd and 3 rd Order Effects of your actions Maintaining Your Skills Certification Maintenance = CEUs Try New Things
First There is a Plan 17
First There is a Plan 18 What information is the most important to you? Where is it stored? How much of it is stored? Where is it processed? What are the reporting requirements in case of a breach? Who do you call? Who does what?
But then 19
Too Late to Practice 20
Elements of an Exercise 21 Safe Entry/Exit No spillage into the production environment Objective-based Challenges It s about training the Blue Team Defined Assessment Standards Task Condition - Standard
Elements of an Exercise 22 Exercise Directive Scenario Communications Plan Objectives Master Scenario Event List It s about training the Blue Team Keeps everyone engaged Assessment Checklist The unexpected isn t always bad After Action Review Stay positive Structured to avoid emotion
Realistic Exercises
Are You Ready? 24
Crawl Walk - Run 25
Crawl 26 Understand communication links Operating systems Applications Security fundamentals Technical Skills Taught through Structured classes Self-paced labs Experiential learning Basic, consistent training Certificate of completion Continuing education credit Results in
Table Top Exercises 27 Meet the Players Identify and Gather Information Identify Paths of Communication Agree on Taxonomy
Walk 28 Small Group Training Specialization Media Management Work as a team Roles The Message Communication Responsibilities 2 nd & 3 rd order effects Priorities
Capture the Flag 29 Self-Paced Takes the training wheels off Same Tools & Techniques as in class Individual Skill Threads Penetration testing Forensics SCADA PII Database security Scoring engine Encourages competition
Red vs. Blue Exercises 30 Focus on system & service security and continuity Synchronous attack & defend Good to get started working as a team Observe and Review hackers in action
Training Camp 31
Run 32 Collective Training Full Speed Force-onforce Objectivebased Remote Teams Experience out-thinking a live adversary Practice teamwork Relationships & collaboration outside the team
Incident Response Exercises 33 Asynchronous Red team creates havoc Blue team diagnoses and recovers Objectives Communications Teamwork Validating plans and procedures at full speed
Welcome to Alphaville 34
36 A Sense of Place
37 Alphaville Power & Electric
38 Alphaville 3D
Summary 39
40 Make a Plan
Teach Individual Skills 41
Learn how to respond in crisis 42
Be Ready to Go! 43
And Jump 44
Questions? 45
Michigan Cyber Range
47 www.merit.edu/cyberrange 734.527.5700 1000 Oakbrook Drive Suite 200 Ann Arbor, Michigan 48104-6794 Thank You