Top Banner
Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems
12

Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Dec 26, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Antivirus Technology in State Government

Kym PattersonState Chief Cyber Security

OfficerDepartment of Information

Systems

Page 2: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Current World Environment

•25,000 new virus samples submitted daily•Antivirus vendors leaning toward whitelisting•80% of malware is motivated by money•Increasingly hard to detect malware

Page 3: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Bot Activity

•Bots talking to each other in different ways•No command and control servers to identify•Communication between bots through peer to peer mode via encrypted web channels

Page 4: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Current State Network Environment

•SCSO tracks 150 ongoing issues each day•50 new issues identified each day•More than 5,000 DNS resolutions to foreign servers daily

oMost popular DNS server is in Eastern Europe

•Several hundred incident notifications from external organizations each year•At any given time, there are 60 state computers acting as primary nodes on a peer to peer network

oThree of these computers typically generate 500,000 peer to peer sessions daily

Page 5: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Current State Environment

•Purchase antivirus and endpoint protection software from 10+ vendors at several price points•Run 60 versions of these types of software•Some organizations don’t update signature files•Organizations pose a threat to each other on the state network

Page 6: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Future State

Limit number of AV or endpoint protection products in our environment

•Make wise use of state dollars by combining buying power•More bandwidth and computer availability due to low infection rate•Improved productivity resulting in better government service delivery•Improved response time to cyber outbreaks

Page 7: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Advantages of Less Diverse Environment

•Total cost of ownership would be less oSavings could be spent on other security measures

•More organizations likely to buy and be protected oLess threat on the state network

•Better reporting and auditing•Improved compliance with security mandates•Shorter threat period by working with fewer vendors•Manageability and scalability•Increased network reliability and performance

Page 8: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Endpoint protection can include:

•Host-based intrusion prevention system•Firewall•Antivirus•Antispyware•Central management capability•Data Loss Prevention•Encryption

Page 9: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Next Steps

•Gather requirements from agencies and state security working group•Work with Office of State Procurement to identify vendors to provide antivirus and endpoint protection products on state contract•Agencies would determine migration to these products as existing software licenses expire

Page 10: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Possible Antivirus and Endpoint Protection Requirements

•Ease of use

•Update frequency

•Service and support

•Update distribution

•Audit and report capability

•Log

•On demand scanning

•Port control

•Encryption

•Scheduled scans

•Link scanner

•Cross browser

•Webmail protection

•Ability to run on multiple

platforms

•Script protection

•Malware detection capabilities

•Policy management

Page 11: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

SAMPLE

TIMELINE

Page 12: Antivirus Technology in State Government Kym Patterson State Chief Cyber Security Officer Department of Information Systems.

Questions?

Kym PattersonState Chief Cyber Security

OfficerDepartment of Information

Systems