Top Banner
THREAT INFO SHARING IN PRIVATE SECTOR Nov Matake, GREE Inc.
14
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

THREAT INFO SHARING IN PRIVATE SECTOR

Nov Matake, GREE Inc.

Page 2: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

NOV MATAKE• Security Engineer, GREE Inc.

• Evangelist, OpenID Foundation Japan

• Interested in..

• Digital Identity

• Privacy

• Security

Page 3: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

PASSWORD LEAKS

• Yahoo! JAPAN

• OCN

• Adobe

• LinkedIn

• etc…

Page 4: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

PASSWORD LIST ATTACKS• CyberAgent

• GREE

• DeNA

• mixi

• Nintendo

• etc.

Page 5: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

ONLINE FRAUD ON LINE

Page 6: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

RISK-BASED SECURITY MANAGEMENT

costs $$$..

Page 7: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

–Eric Sachs, Google

“If you’re typing a password into something, unless they have 100+ full-time engineers working on security and abuse and fraud,

you should be nervous.”

Page 8: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

THREAT INFO SHARING

Page 9: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR
Page 10: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

Share information about important security events in order to thwart attackers from leveraging compromised accounts from one Service Provider to gain access to accounts on other Service Providers.

Page 11: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

SECURITY VS. PRIVACY

Page 12: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

– Consumer Privacy Bill of Rights Act of 2015, White House

“The term “personal data” shall not include cyber threat indicators collected, processed, created, used, retained, or disclosed in order to investigate, mitigate,

or otherwise respond to a cybersecurity threat or incident, when processed for those purposes.”

Page 13: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

– Act on the Protection of Personal Information, Japan

“Cases in which the provision of personal data is necessary for the protection of the life, body, or

property of an individual and in which it is difficult to obtain the consent of the person”

Page 14: [International Workshop on Cybersecurity] THREAT INFO SHARING IN PRIVATE SECTOR

CONCLUSION

• Hire 100+ security engineers, or share information !!

• FB & OIDF are going forward with White House backup

• Resolve the conflict between security & privacy

• Cyber Security Basic Act solves it ?