Analysis: Countering Nation-State Attacks in 2020 episode artwork

EPISODE · Jan 3, 2020

Analysis: Countering Nation-State Attacks in 2020

from Info Risk Today Podcast · host InfoRiskToday.com

The latest edition of the ISMG Security Report discusses countering the threat of nation-state cyberattacks in 2020. Also featured: an update on France's experiment with facial recognition technology and sorting out what "zero trust" really means.

Episode metadata supplied by the publisher feed · Published Jan 3, 2020

Embed this episode

NOW PLAYING

Analysis: Countering Nation-State Attacks in 2020

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

The Cyber Axis of evil in 2020 France's facial biometric experiment an expert defines zero trust. These stories and more in this week's Iseng Security Report. Hello, I'm Nick Holland. It's been 18 years since President George W.

Bush used the term axis of evil to describe the trifecta threats from the nation states of Iran, Iraq and North Korea. The countries that make up this axis may have shifted since then, but the threat of nation state attacks is no less pronounced. That's according to Tom Kellerman, former cybersecurity advisor to Obama administration and head cycle strategy for VMware icing. G.

Stonefield spoke with Kevin recently about what his greatest cyber security concerns are going into 2020 and his response is probably not a great surprise. Here he is. Well, the threat actors specifically are the usual suspects and the actions of evil in cyberspace. As you see more robust and organized cyber activity occurring from both China and Russia and from their allies North Korea and Iran, both of which have exemplified true cyber attack capabilities in the organization over the past year, thanks to tech transfer and consultative services being provided by their big brothers.

This is not just a question of disinformation. This is not a question of political affiliation. This is along the strategy, along the lines of information dominance being primary strategy to reassert the hegemonic roles of those empires. So I'm very concerned with the use of rogue nation states in attacking the west as proxies for their allies.

Tommy, been sounding this alarm for several years now, so I want to ask you, take a step back and talk to me about where have we made progress in cyber defense and where do you feel we still lag significantly behind? Well, we're lagging behind because we don't appreciate the evolution of the cognitive attack loop of the adversary. What I mean by that is the cognitive attack loop is a carbon black manifestation as an evolution of the kill chain. The kill chain for too long has been too linear.

It makes the assumption that the adversaries will get in and get out with what they want and then they will leave. Given the dramatic uptake of island hopping 41% of the time that's occurring in investigations where they're actually taking over and commandeering the infrastructure of the victim companies so that they can use that brand to target their constituency. Coupled with counter incident response and dramatic evolutions in lateral movement beyond powershell, we have to appreciate that the adversary isn't leaving. They're never going to leave.

Once they have your infrastructure, they will maintain a footprint on your infrastructure and they will maintain persistence. And so how we react to them, how we defend against them must be along the lines of a focused mission towards intrusion suppression, not just prevention. And we need to just come to Jesus on that and have that awakening that we need to deal with an adversary authority inside of our environment and we need to suppress them in a clandestine fashion so they don't leverage destructive attacks. You're listening to the ISMG Security report on ISMG Radio, ismg, your number one source for information security news.

There's one technology that sets off allwelling alarm bells. It's the government use of facial recognition. While there clearly some significant benefits in using the technology for identity management, the idea of a nation state collecting surveillance information on where you are and who you're with clearly raises hackles, and rightly so. The potential for misuse is significant.

One government that is tentatively dipping its toes in the facial recognition fray is AD France with a project called alicem. Smith's Associate editor Subhana Goswami spoke with Felicien Vallee, the privacy technologist at Kinil, France's data protection authority, about the ALISSEM initiative and asked him what the scope of the project is and how is it being implemented to make sure the technology is being used appropriately. Here's Felicien's response. Facial recognition technologies have already been deployed in France, in the public, for instance for border control and the private sectors.

In France we use also facial recognition to an OCR smartphone to specify identity by comparison of the picture of an ID and selfie or for other usage. However, I think what you refer to is the fact that the French government communicated on two different aspects, stating that it might be interested in using this facial recognition technology further. So the first one is about a project called ALICENT that is currently being developed and the idea is to create a digital identity recognized by the French government. And so the idea is that this process offers a way of creating a digital identity using a mobile app, in a smartphone or a tablet and that can be then used to securely access online administrative services.

That's the first of the French government project and reviewing this project the committee was consulted and the technique stated that if the project was actually legitimate, it could also be improved. In particular regarding the freedom of consent of the concern that subjects the concern of people. The second of this French government project regards the planning of facial recognition experimentation and this is more of a fuzzy thing if I can say it like that. Indeed, Cedric O, France Secretary of State for Digital he stated that facial recognition experiments are necessary for the development of French industries and that democratic debates would only be completed afterwards on this topic.

So the idea is to experiment facial recognition and he expressed his will. So regarding this point, Camille decided to publish a positional paper, some kind of guidelines that express Kil's view on the topic of facial recognition. Because if Kiel can actually understand the necessity in some cases to experiment with facial recognition, it also believes that everything cannot be done for the sole sake of experimentation. So as you said, Camille has come up with certain guidelines on how to manage facial recognition technology.

So what are some key points of that? Well, first of all, the thing is to say that as I pointed out earlier that facial recognition is a very wide topic, covers many things and all these things, they are not necessarily comparable, but not the same. And facial recognition might be very legitimate in some cases. You have to be very cautious with what you are talking about, how you consider things.

That's the first thing. Also the second take is to clearly understand that all cannot and will not be tolerated by the mere regarding facial recognition. Well, that's kind of following what I was previously saying, that that's also linked to what I was talking about, the police decision to ban facial recognition programs in high school. Okay, so essentially what is the standard of the government now that now that as the protection party of the country you have expressed your concerns and what is the stand of the government?

I believe there are still some strong will to go in that direction and I believe experimentation in these regards certainly will be proposed. Then the very idea of publishing this, making public public deal's view was also to say to our end, to our interlocutors, to the people we're talking with, welcome to us. And we can also discuss together helping them to see if actually facial recognition is really the solution to the problem they want to address. And if yes, then try to accompany them to see what organizational technical measures can be put in place so we reduce at the minimum their privacy and protection risks for the concerned people.

Finally, you've probably been under a rock for the entirety of 2019 if you haven't come across the phrase zero trust. It's not a new phrase, but it seems to be truly coming age to describe a more robust stance to validation in today's decentralized cloud based workspace. I spoke with Stanlow Global CSO Zscaler about zero trust coming of age in 2020 and more specifically, how does he define the term? Here's his succinct definition.

So for me, zero trust is really built around four real principles. One is granting access based upon four different criteria and applying policy and access based upon that. One is obviously the identity. What we know about you as an individual, are you an employer, your contractor, your volunteer, whatever.

Two is the device that you find access with, is it managed, is it not managed, is it patched, is it not passed? And then three is the location that you find access. Are you somewhere there's a good country, somewhere, it's a bad country, you're on that off net, whatever. And four is the sensitivity and the criticality of the data that you're trying to access and making a, a policy based decision and applying security policy and access rights based upon those four things.

And it's really. When we talk about, you know, when marketers talk about zero trust and we talk about, you know, from security perspective, zero trust, what we're talking about is granting access to applications and data based upon essentially those four operational criteria. That's it for this week's licensed Security report. Theme music is by Tech Audio.

I'm Nick Collins. Catch you next time.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 3, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!