Showing posts with label Cyber Security Strategy. Show all posts
Showing posts with label Cyber Security Strategy. Show all posts

Wednesday, July 24, 2024

Magic of Cybersecurity

Greetings from a panel on Cyber Security: Exposing the  THE magic involved in product evaluation, at the Australian Computer Society in Canberra. This is timely with Friday's Microsoft Windows/CloudStrike outage. The discussion so far is focused on the Australian Information Security Evaluation Program (AISEP). One topic of interest to me is that the Australian Signals Directorate is looking at training for security certifiers with other countries. Some of my uni students have been interns at companies carrying out government security checks.


The panel has:


Dr Hin Chan, Manager – Australian Certification Authority (ACA), Australian Cyber Security Centre, ASD

Erin Glenn, Director of Product Management, Belkin International, US

Patrick Campbell-Dunn, Securus Consulting Group 

Tuesday, November 1, 2022

Singapore and Cyber Security

Greetings from Predict22: The Intelligence Summit, at Fullerton Hotel in Singapore. The conference organisers were excited to have someone from Canberra as a delegate, but I admitted I was actually here to speak at a uni & EduTech Asia next week. But computer security is a hot topic, so it doesn't hurt to brush up. The current presentation is touching on an attack on India's power grid, and implications for other coutries.

Saturday, October 29, 2016

Cyber Security Researchers Required in Canberra


image
The Australian National University in Canberra has advertised for Cyber Security Lecturer and Associate Professor positions: "The Research School of Computer Science invites applicants to be part of a team developing and delivering education and research programs in the area of cyber security.". Offered are Lecturer, Senior Lecturer, and Associate Professor positions, with salaries from $94,287 to to $145,576 (plus 17% superannuation). A new building is currently under construction at ANU for a joint Cyber Security Innovation Centre, with the Australian Signals Directorate (ASD).
 

Friday, July 22, 2016

Australian Cyber Security Innovation Centre in Canberra


image
The Minister for Defence announced $12M from Australian Signals Directorate (ASD) for a joint facility at ANU (23 June 2016). The height of the planned Computer Science and Mathematics building is being increased by one floor to accommodate joint work on for an Cyber Security Innovation Centre.
The work for the new building is already underway (I can see it out of the window of my office in the existing Computer Science and Information Technology (CIST) building, where the ANU Research School of Computer Science is located.
About a year ago I was walking past the CIST seminar room (the famous N101) on the floor below my office and noticed a group of people I did not recognize. It turned out that they were from the ASD, there to present to students on Careers at ASD, but were having difficulty getting the projector to work (a common occurrence). I helped with the projector and stayed on for the talk.

Afterwards the ASD staff commented on the difficulty they had interacting with universities. I pointed out that CSIRO had solved this problem by moving on campus. CSIRO have one wing of the CIST building at ANU, while the Research School of Computer Science has the other. Between the building's two wings is a shared staff room, to facilitate informal interaction. To meet bureaucratic requirements (and show the architect had a sense of humor), the common room was designed with two doors next to each other: one for ANU and one for CSIRO, opening into the same shared space.

ANU was building a new computer science building, so I suggested ASD could pay for an extra floor to be added. This was an off-the-cuff suggestion and I did not think much more about it. No doubt I was not the only one to suggest it.

Monday, June 27, 2016

Australian Cyber Security Courses

The Australian Government has committed $3.5M over four years for an Academic Centres of Cyber Security Excellence program. Already there are a number of cyber security programs offered by Australian universities. But before looking at courses, how do these fit with professional requirements?

Cyber Security Skills

The Skills Framework for the Information Age (SFIA) is used by the Australian Computer Society to identify the skills IT professionals should have and to accredit suitable university courses. SFIA Version 6 has security related skills definitions:
  • Information security SCTY
  • Information assurance INAS
  • Security administration SCAD
  • Penetration testing PENT
  • Incident management USUP 
There is also the ISACA Model Curriculum for Information Security and EC Council Security Certification .

Australian Cyber Security Programs


Edith Cowan University offer a ECU Master of Cyber Security. This includes units general computer units, plus security related ones, including: Computer Security, Network Security Fundamentals, Wireless Security, Introductory Computer Forensics, Information Security, and most interestingly, Ethical Hacking and Defence. There is also a ECU Graduate Diploma of Cyber Security, and ECU Graduate Certificate of Cyber Security, Bachelor of Science (Cyber Security).

Swinburne University offer a cybersecurity major in Computer Science and Engineering bachelor degrees, with courses in eForensic Fundamentals, Information Systems Risk and Security, IT Security and Network Security & Resilience. There is also a cybersecurity Master of Information and Communication Technologies (Research). Some of the programs include work placements.

UNSW Canberra, at the Defence Force Academy, is offering a new Master's Degree in Cyber Security, Strategy and Diplomacy, as well as a Master of Cyber Security and Master of Cyber Security Operations. UNSW Canberra also offers an extensive range of security courses including: Critical Infrastructure Cyber Security, Cyber Adversary Tradecraft, Intrusion Analysis and Response, Cyber Security Boot Camp, Introduction to Pen Testing, Executive Security Awareness, Computer Network Operation / Network Security Operations, Wireless Security, Reverse Engineering of Malware

Murdoch University offers a Cyber Forensics and Information SecurityBachelor of Science.

Macquarie University offers a Bachelor of Security Studies, and a Master of Information Technology with a specialisation in Internetworking and Cyber Security.
The University of Canberra offers a Graduate Certificate in Cyber Law and Policy, with courses in Cybercrime Investigations, Cyber Security Law, Digital Evidence and Intelligence Management.

The Australian National University offers courses in Cyber-security and Cybercrime, Cyber Warfare Law and Statecraft and national security in cyberspace.

University of South Australia offers a Master of Science (Cyber Security and Forensic Computing).

University of Woolongong offer a BSc with a Major in Cyber Security, with course in System Security, Corporate Network Security, Cryptography and Secure Applications and Ethical Hacking.

Deakin University offer a Bachelor of Cyber Security.

Sub-degree Programs


Box Hill Institute offer a Certificate IV in Information Technology (Specialising in Cyber Security).

Victoria Polytechnic offer an Advanced Diploma of Network Security (ICT60215).

One point to note is that vocational programs are standardized across Australia, so the same cyber security qualifications offered by Box Hill and Victoria Polytechnic could be offered by other TAFEs and by private Registered Training Organizations. These qualifications could also be offered by training units within government agencies and companies, for their own staff. In contrast, the content of university degrees are not standardized in Australia, so degrees at the same level with similar "cyber security" titles, could have very different content.

Open, Online and "Free" Courses

In addition to programs and courses offered directly, Australian universities offer education on cyber security though Open Universities Australia. These include Macquarie University Bachelor of Security Studies, and the Australian Computer Society formation Security Course.
 
Charles Stury University (CSU) offer a free Network Security Administrator Certification short course to help prepare for certification as an EC-Council Network Security Administrator (ENSA)

At the introductory level the Open University run a MOOC on "Introduction to Cyber Security". Also there is a more traditional on-line course "An introduction to information security".


ps: Having a background in defence, my teaching occasionally touches on cyber security. Last semester I was teaching IT ethics using a hypothetical about Cyberwarfare Over the South China Sea.

Wednesday, February 17, 2016

Taming Cyberspace With International Law

Fred CateGreetings from the Australian National University in Canberra, where Professor Fred Cate from Indiana University is speaking on "Taming cyberspace: Applying international law in a new domain" as part of the part of the conference "Securing our Future in Cyberspace". He claimed that on-line systems are not secure. He challenged the audience to name one secure system and no one took up the challenge. The room is full of people from Australian government intelligence agencies, who hopefully have such systems but can't say. ;-)

Professor Cate claimed that 85% to 90% of break-ins to systems are due to human failings, due to phishing or poor passwords, not highly technical attacks. He also claimed that outside banks and a few other categories, there is no legal obligation to secure systems. His conclusion was "We are not taking cyber-security seriously any more", saying US investment in the area is small compared to other security matters. Professor Cate criticized the US Government for only having a "Cybersecurity Coordinator" (currently Michael Daniel).

Professor Cate claimed there were not regulations requiring organizations to have good security. However, he mentioned earlier on "governance". Australia developed the standard "Corporate Governance of Information and Communication Technology" (AS8015), later adopted internationally as ISO/IEC 38500 in 2008. These standards are not mandated by law. However, there are corporate governance laws. I suggest that the standards could be applied though case law, or could be explicitly made mandatory through legislation.

Professor Cate claimed that there was no one in the US Government to shut down a government server which was sending out computer viruses. With the greatest respect to the professor, I do not believe this to be true. Any IT professional with a server under their control has an ethical and legal obligation to shut it down if it is sending out computer viruses (unless of course it is part of an authorized security operation).

Professor Cate asked if any government had a system to deal with a widespread emergency without the Internet. A quick search shows they do. The US military has the Minimum Essential Emergency Communications Network (MEECN) and the Australian Defence Force and state police forces have HF radio networks. There are also Australian outback HF networks.

An interesting comment by Professor Catewas that insurance companies are effectively setting cyber security standards in the USA.

There are an extensive set of papers on Cybersecurity by Professor Cate.

Tuesday, February 16, 2016

Securing our Future in Cyberspace

Greetings from the Australian National University where a research symposium on "Towards a political ecology of cyberspace" is taking place as part of the conference "Securing our Future in Cyberspace". There is a public forum on "Quantum sovereignty: the Westphalian principle and the global governance of cyberspace" tomorrow, "Taming cyberspace: applying international law in a new domain" Wednesday,  "The role of cybersecurity in Chinese foreign policy" Thursday and "Securing our future in cyberspace - next steps" on Friday.
The event has not started well, with the first speaker asking "What is Cyberspace?" and answering their own question with "Well it is really big.". This sounds like a line from the 1995 Steven Seagal  film "Under Siege 2: Dark Territory": a US DoD technician searching for a orbital weapons platform says something like "It called 'space' because it is really big". ;-)

The first presentation on the ontology of cyberspace. The second presentation was on the ethics of cyberwarfare. An interesting aspect is the interaction of IT and military ethics. Perhaps the most insightful comment of the morning was describing cyber-warfare as "a game of rock, paper scissors".

The last session I attended was on Balkanization of the internet". This seemed to have missed the point that "The Internet" (with a capital "I") is an internet (small "i"): that is a network of networks. So the term "Balkanization of the Internet" is a tautology: the Internet is, by design balkanized and this is one of its strengths. The network of networks provides for security and Resistance of the Intent. Balkanization is not an emergent property of the Internet, it is an important part of the design.

The "Towards a political ecology of cyberspace" research symposium was disappointing. It presented some introductory material which would be suitable for a first year introduction lecture. Some of the material was technically incorrect. The work presented was of practical minimal pratical value and not high quality academic research.

Wednesday, February 3, 2016

Security Flaws in Staphones Revealed in Canberra

Dr Leonie Simpson, from QUT, today detailed flaws in the encryption technology in commercial satellite phones. Simpson said that only an ordinary laptop computer would be needed to break the encryption of satphones and "All users of commercial satellite phones are at risk" also that only an ordinary . These phones are used by Australian government officials and the Australian Defence Force on overseas deployments. Simpson was speaking at the Australasian Information Security Conference (AISC 2016).

At the conference exhibition Contact Singapore are providing details of the Singapore Government Cyber Security component of their national development road-map.

ASIC is part of Australasian Computer Science Week (ACSW 2016) at the Australian National University (ANU) in Canberra until Friday. ANU is also hosting the international "Securing our Future in Cyberspace Conference", 15-19 February 2016.

The paper is:

Vishesh Bhartiya and Leonie Simpson. Initialisation Flaws in the A5-GMR-1 Satphone Encryption Algorithm, Australasian Information Security Conference, February 2016

Wednesday, March 5, 2014

International Cybersecurity Research Collaboration

Greetings from the National Security College at the Australian National University in Canberra, where Malcolm Turnbull, Minister for Communications, is speaking at the launch of "Strategy and Statecraft in Cyberspace" research. This research will use techniques of complex systems and natural ecology. The researchers are asking for input from the community and will reach out via blogs and other on-line forms.

Minister  Turnbull started by saying the Internet is the single most powerful driver of innovation in human history (I would nominate the invention of language and writing as greater influences). He included ASD one agency which has a role in cyber security policy. Also he made a reference to "Mr. Snowdens's burglary". Minister  Turnbull pointed out that governments had to protest publicly about being spied on by NSA, because the details were made public.


Minister Turnbull then turned to the digital economy. He emphasised that the Internet was built and is run by the private sector, not governments. I don't agree that this is so significant: most human activities are run by private individuals, non-profit and for-profit organisations (not government). I helped set up the structure used to run the Internet and it was not so different to the structures I help run for other civic activities. However, I agree with his assertion that maintaining a cyberspace not dominated by government is a goal.

 Minister Turnbull asserted that the Internet is run by US based bodies, but not run by the US government. He characterises the way the Internet is governed as ad-hoc, but this is not the case. The Internet was set up with a governance structure carefully designed to prevent government control: this is no accident.

I will post a link, when the text of the speech is available.

Friday, January 24, 2014

Free Online Short Courses to Prepare for Certification

Charles Sturt University (CSU) are offering a Free Short Course: Network Security Administrator Certification. This is run on-line over 5 weeks, with live webinars (and optional recordings) and students expected to do 10-12 hours of study. Several aspects make this different to Massive open Online Courses (MOOCs) being offered by other institutions. Fist of all there is a live component to the course, not just recordings. Also the course is intended to prepare the student for an external certification (ENSA). It is also significant that this  is described as a "short course" with no mention of "MOOC", or the hype surrounding them. As I said at the Inaugural Student Experience Conference, in Sydney, I expect to see the MOOC Bubble burst, with most MOOCs abandoned by the end of 2014.

CSU point out that the short course is based on their Master of Information Systems Security. Clearly the short free course is being used to promote the full for-fee degree program. This would appear to be a viable business model for free courses. A student who completes the short course would be predisposed to enrolling in the degree program.

However, students who undertake the free course to prepare for external certification may not realise the large commitment of time and effort required. Last year I completed two certificates in education, one through regular courses (partly in the classroom and partly on-line) and one by Recognition of Prior Learning (RPL). In theory the RPL should have been easier, as it just required me to collate and present evidence of what I had done previously. But this turned out to be harder than going through a structured course, where you get guidance on what to do and where there are many small milestones on the way to completion.

Also, using a free short course to promote longer for-fee programs might backfire on some universities, presenting a false impression of their programs. Some MOOCs appear to be provided by universities which don' generally offer on-line courses (not the case with CSU who are a leader in on-line education). Also the MOOCs are at a far lower academic standard than regular courses. It will not do a university much good to attract students with one type of course at one level, sign up and pay for a degree program, only to find it is not offered on-line and is far harder.

Friday, November 8, 2013

Formulating National Security in Cyberspace

Greetings from the Australian National University in Canberra, where an international research project on "Political Strategic Ecology in Cyberspace" is being launched.  This research uses techniques of complex systems and natural ecology. The researchers are asking for input from the community and will reach out via blogs and other on-line forms.

Professor Paul Cornish from University of Exeter UK, argued that cyberspace should be treated as a strategic space. Professor Roger Bradbury,  National Security College at ANU expressed concern about the Internet being balkanized with countries such s China separating their national systems from the global network.

One of the audience members commented that the Internet was built by engineers and and that might cause an impediment to security. I found this discussion of balkanization and engineers acting without reference to the public interest troubling. The term "internet" refers to a "Network of Networks", with "The Internet" as the global example of this. Those designing the Internet did not so in isolation from issues of governance, that was key to the system.

I suggest researchers need to first look at how the Internet was created and is now governed. Professor Fred Cate , Director of the Center for Applied Cybersecurity Research at Indiana University, pointed out that most of the Internet is run by non-government organizations. He argued that the law and governance was lagging actual use of the Internet. However, this is not my experience.

When advocating the use of the Internet in Australia in the 1990s, myself and others considered the governance and legal implications. In my day job I had to devise policies for the use of the Internet and the world Wide web by the Department of Defence. This turned out to be relativity easy, identifying existing polices, laws and guidelines and interpreting these where necessary. The general assumption which many people in government and academia made, that public utilities are administered primarily by government turned out not to be true. In practice, most public services are provided by non-government entities following guidelines and standards written by non-government bodies. This approach-was extended to the Internet and proved resilient.

Governments and researchers who want to impose top-down government control of the Internet in order to protect democracy are missing the point.

One student in the audience asked an interesting question about cyber-war, outer-space and conventional warfare in developing nations. One of the panel responded that cyber-war would be an adjunct to use of conventional forces and may make conflicts harder to mange.

I asked the panel how we could get the results of their research to policy makers and practitioners quickly. In the 1990s we used the ANU fellow bar as a forum for formulating public policy, but perhaps something more systematic is needed. 

Strategy and Statecraft in Cyberspace

Join us for a panel discussion and open forum to explore the complexities of cyberspace from a national security perspective – a domain in which states and non-state actors interact with each other in an increasingly contested environment.

This event has been organized by the ANU National Security College (NSC) as it finalises priorities for its new research program on Strategy and Statecraft in Cyberspace. The NSC has brought together leading researchers from Australia, the United States and the United Kingdom for this event which will be facilitated by the ABC’s Michael Brissenden:
  • Professor Roger Bradbury is a complex systems scientist with experience in international cyber issues, and is with the National Security College at ANU.
  • Professor Fred Cate specialises in information privacy and security law issues, and is Director of the Center for Applied Cybersecurity Research at Indiana University, USA.
  • Professor Paul Cornish is an expert in cyber security and cyber war, and Professor of Strategic Studies at the Strategy and Security Institute at the University of Exeter, UK.
  • Dr Jon Lindsay is an expert in international relations at the University of California Institute on Global Conflict and Cooperation at UC San Diego, USA.
Like the traditional domains of land, sea, air and space, states and non-state actors are using the cyberspace domain to pursue their objectives in an increasingly complex world. The panel will discuss the rise of cyberspace, which has created a number of ‘wicked’ policy problems for global security including:









  • the proliferation of cyber weapons to state and non-state actors
  • the systemic vulnerabilities in the infrastructure of globalisation and military power
  • the friction between private sector actors who manage the Internet and the public sector actors who are supposed to defend them
  • the mismatch between the pace of policy formation and the pace of technological change
  • the failure to coordinate among government agencies responsible for national security, law enforcement and industrial policy
  • major disagreements about how the Internet should be managed domestically and internationally.

  • Some authors foresee grave new risks of a ‘digital Pearl Harbor’, while their critics dismiss these warnings as inflating the threat. Technological complexity has amplified political complexity, which in turn has complicated political analysis. Our panel will endeavor to unpick these issues from the perspectives of social policy, security policy and the future of technology. We look forward to welcoming you at this important event focusing on an issue of critical significance.