Top Banner
Drs. ing. Elgeline Martis Head CARICERT Cyber Security in the Caribbean
37

Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

May 11, 2018

Download

Documents

doanminh
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Drs. ing. Elgeline MartisHead CARICERT

Cyber Security

in the Caribbean

Page 2: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Cyber Security last week

30 September 2014

Page 3: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Page 4: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Topics

o Introduction

o Status of cyber security in the Caribbean

o Cooperation in the Caribbean

o Roadmap

o Questions

30 September 2014

Page 5: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Caribbean Cyber Emergency Response Team Accredited by FIRST – Full member Recognized by CERT/CC Accredited by Trusted Introducer

Introduction CARICERT

www.caricert.cw

Page 6: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Page 7: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Page 8: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Page 9: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

} 602.3 millions

Page 10: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

2.8% of 602,293,593 =

12,045,872 Internet

users in the Caribbean

Page 11: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Cyber Threats

The Hackers

Hacktivist

Phishers

Spammers

Spyware/malware authors

Insiders

Foreign intelligence services

terrorists30 September 2014

Page 12: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Cyber Threatso Amount of attacks has increasedo Attack Characteristics:

Complexity of attacks has increased; Changing modus operandi of attackers;

Long lasting attacks; Repeating attacks; Slow attacks;

International originated and International effects; Resolution depends on all end users; Incident handling is time consuming and complex. Attack duration possible two/three years before discovering

30 September 2014

Page 13: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Cyber Threats Caribbean ?

SPAM

Page 14: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Caribbean ?????

Reference:

http://resources.infosecinstitute.com/2013-impact-cybercrime/

Page 15: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Cyber Threat Caribbean ?

Reference:

http://resources.infosecinstitute.com/2013-impact-cybercrime/

Page 16: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Cyber Threats Facts & Figures

30 September 2014

TCP ScannersIRC-BotsVirut-BotTor-pig BotHttp BotZeus-BotHermes-BotWorm-Boinberg BotWorm-DorkbotConfickerDos-KhanTdss-botOpenresolversProxySpamMalware URLFeodo

SPAM: 45%

Page 17: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Cyber Threats Caribbean ?

o Lack of structural facts & figures (per country)

o Latin America & Caribbean, but how much is Caribbean?

o Caribbean countries must start collecting and sharing their facts & figures (in working groups)

o Trend Micro, Symantec, and other AV companies collect data per country

Page 18: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Status Cyber Security

In the Caribbean

Page 19: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Page 20: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Name NatCSIRT

Strategy & Policy

Legislation Awareness Info Sharing Cyber Sec degree program

Lack reporting

Financial resources

Antigua &Barbuda

In progress In progress Yes No No No Yes No

Barbados In progress In progress In progress Yes Yes No No Yes

Dominica No In progress In progress No Yes No Yes ?

Dominican Republic

No No yes Yes Yes yes yes ?

Grenada No No yes In progress Unofficial no yes ?

Haiti No No In progress Yes Yes No Yes No

Jamaica In progress In progress Yes No Yes Yes Yes ?

St.Kitts & Nevis

No No No Yes No No No ?

St.Vincent& Grenadine

No No No No No No ? ?

Trinidad & Tobago

In progress Yes In progress Yes In progress no yes ?

Reference: Latin America + Caribbean Cyber Security Trends

OAS and Symantec; June 2014

Page 21: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Name NatCSIRT

Strategy & Policy

Legislation Awareness Info Sharing Cyber Sec degree program

Lack reporting

Financial resources

Antigua &Barbuda

In progress In progress Yes No No No Yes No

Barbados In progress In progress In progress Yes Yes No No Yes

Dominica No In progress In progress No Yes No Yes ?

Dominican Republic

No No yes Yes Yes yes yes ?

Grenada No No yes In progress Unofficial no yes ?

Haiti No No In progress Yes Yes No Yes No

Jamaica In progress In progress Yes No Yes Yes Yes ?

St.Kitts & Nevis

No No No Yes No No No ?

St.Vincent& Grenadine

No No No No No No ? ?

Trinidad & Tobago

In progress Yes In progress Yes In progress no yes ?

30 September 2014

Reference: Latin America + Caribbean Cyber Security Trends

OAS and Symantec; June 2014

Curacao Yes No In progress In progress in progress No Yes Yes

Page 22: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Page 23: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

We can’t keep pace

o No synchronization between the islands

o Security threats and vulnerability landscape changes fast (daily)

o Setting up a Security organization is slow (years)

o Policy making is slow (months)

o Legislation process is slow (years)

o International cooperation is slow (years)

Page 24: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Cooperation in the

Caribbean

Page 25: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Combat Cyber Crime

Share structured Information

Data, measures, methods, training, incident handling

Align security programs, policy and laws

Empower others

Design new training programs

Commitment on all levels

Create regional frameworks (legal)

30 September 2014

Page 26: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Phases / steps

Increase awareness

Cyber Security Strategy

Cyber Security Policy

Cyber Security Legislation

Incident Response Teams (CSIRTs)

Capability building

30 September 2014

Page 27: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Stakeholders

30 September 2014

Internationalo LACNIC

o OAS

o APWG

o ICANN

o CTU

o ECLAC

o Ameripol

Localo Government

o Universities

o ISPs

o CSIRTs

Page 28: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Stakeholders

o Join stakeholders like LACNIC, CaribNog

o Accept assistance from OAS

o Start Caribbean working group for IRT

o Start working groups for Cyber Security Strategy

o Etc.

30 September 2014

WHICH STAKEHOLDER IS DOING WHAT?

Page 29: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

CARICERT cooperation initiatives

o Dutch NCSC (CSIRT)

o CERT.br (CSIRT)

o Curacao ICT Association CICA

o Team Cymru

o Caribbean Cyber Security Center (Barbados)

o DO-CSIRT (Republic Dominican)

o SURCSIRT (Suriname)

o OAS

Page 30: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Roadmap

Page 31: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Reference: www.caribbeancsc.com

Page 32: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Inter-islands

Which island? All islands?

Alignment of Cyber Security Strategies & Policies

Alignment of (international) Legislation

Incident Response Capability

Page 33: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Steering Committee

ConstituencyConstituency

Site Security

Contact

Site Security

Contact

Governmental

CSIRT

Branch CSIRT

National CSIRT

Continental CSIRT

International CSIRT

Steering Committee

Interaction model TRUST

Page 34: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Same programs / same projects

o Start same projects

o Define which information to share

o Centralize data for analysis and correlation

Data collection project support of DO-CSIRT to CARICERT

Page 35: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

TODAYStart a working group for collecting data

Point of contact per country

Page 36: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

30 September 2014

Let's play the same footballIn my country, This is football

Page 37: Cyber Security in the Caribbean - Squarespace · o Status of cyber security in the Caribbean o Cooperation in the Caribbean o Roadmap o Questions 30 September 2014 30 September 2014

Questions

30 September 2014