Posts

Showing posts with the label security

Dealing with the Internet of Insecure Things

Image
I was invited to deliver a presentation to the Institute of Engineering & Technology's EC3 Group on "Dealing with the Internet of Insecure Things".  My talk provided an overview of the security challenges of the Internet of Things and argued that we should adopt human-centric engineering approaches to address these challenges. Abstract:  We are in an age of the ‘Internet of Everything’ where boundaries between citizens, governments, media, and societal organisations are becoming increasingly fuzzy as interconnected digital devices enable the collection and exchange of vast amounts of information across the globe. The availability of data gathered by these devices, coupled with advances in channels of digitally mediated communication, has created a host of new systems that are embedded into a range of human activities, including agriculture, energy, transportation, healthcare, policing, and education – creating the potential for a ‘smarter planet’. However, these cy...

Are we losing the Internet Security battle?

Image
I was recently invited by Heimdal Security to take part in an expert roundup, with the theme of "Is Internet Security a Losing Battle?".   The main thrust of my answer was to question our use of analogies of conflict in the context of Internet Security or cyber security.  As I said in my response: "... in this context the metaphors of conflict, such as ‘war’ and ‘battle’ are unhelpful because they suggest that internet security is the responsibility of the technologists who act our defensive force against attackers.   Instead, as has been argued by technology activists like Cory Doctorow  and others we might have more success by thinking of cyber security using the analogy of public health and communicable diseases.   By using this analogy, we make cyber security issues more relevant to people and spur them to gain a better understanding that, like diseases, any of us can be afflicted by a cyber security attack.  We can also adopt an analogous ap...

Cyber Security Awareness across the Middle-East

Image
Over the past year, I have been working the colleagues at Qatar University's KINDI Centre for Computing Research to adapt the Introduction to Cyber Security course for the Arabic-speaking world. After an initial workshop with a variety of stakeholders across the region, we designed two versions of the course - one aimed at improving workplace cyber security awareness and the other provides a broader overview that aims to help raise awareness among the general public.  Both courses will be made available in Arabic and English, the latter in recognition of the fact that there is a large cadre of expatriates in the Gulf region. The courses are already open for registration, hosted on the Canvas platform, but will be formally launched at Qatar University today.  The video above is one of the publicity trailers produced to promote this project.  For more information, see the KINDI Centre for Computing Research website .

Who's been typing on my keyboard?

Image
Wired magazine reports on some research carried out by Bastille , where attackers can hijack proprietary wireless keyboard (and mouse) dongle from over 100 yards away.  The attack exploits firmware vulnerabilities in a particular radio communications chip used by wireless input devices.   It seems to be a popular piece of hardware, which is integrated into some computer manufacturers' wireless input devices. The report only discusses hijacking the target computer, and it is not clear if the technique can also be used to log the keystrokes of the victim's keyboard.  However, it seems straightforward that an attacker could use the capability to inject the commands for the target computer to download and execute a more significant malware payload.  Of course, the computer would have to be unlocked for this to work, which would mean the attacker could see the victim's screen.  Alternatively, an attacker could simply keep trying to send their commands...

Cyber Security Awareness Month

Image
Introduction to Cyber Security MOOC A few years ago, the US Department for Homeland Security started an initiative to raise awareness of cyber security issues by promoting  October as "National Cyber Security Awareness Month".  Therefore, it is appropriate that the latest presentation of the Open University's MOOC " Introduction to Cyber Security " is due to start next week.  Since we launched the course in October 2014, we've had over 50,000 learners participate and almost 11,000 fully engage with the content. By giving people the basic knowledge and skills to better protect their computer systems, both at home and work, we hope to have made a useful contribution to raising cyber security awareness across the globe.  Of course, there is still a long way to go, as highlighted by Kevin Beaver in a recent blog post on IBM's Security Intelligence site.  Weak passwords, unpatched systems, and improper malware protection are all examples of common sec...

Validation, Verification and Explanation in a Smarter World

Image
View of the Alps from Workshop on "Engineering Adaptive Systems" Ubiquitous computing systems are creating the potential of a smarter but more complex world. One way of managing this complexity is to develop adaptive systems that can react to changes in their operating environment. In such environments security is an important consideration because the assets, threats, attacks and vulnerabilities can all change at runtime.  Adaptive security can help but it is important to have assurances about: Validation:  (Have we built the right system?) Will the system protect the assets from security threats? Verification:  (Have we built the system right?) Has the system been correctly configured to protect the assets from security threats?
; and Explanation:
 Can we understand the behaviour of the adaptive security system? This is the subject of a recent talk I delivered at a workshop on Engineering Adaptive Systems in Bra, Italy.  The photograph above shows a ...

Why can't I do that?: Explaining Adaptive Security

Image
Adaptive security demo, extracted from Collaborative Security video  produced by Amel Bennaceur Our world is increasingly being pervaded by connected digital devices that make up the Internet of Things, making it important to ensure that the security of these devices and the functionality they provide.  We are working on techniques to support adaptive information security, where the security mechanisms used to protect these pervasive computing systems can change as the value of the assets being protected and the threats that arise in the environment change.  A key challenge in any adaptive system is to ensure that users understand why the behaviour of the system is changing at runtime. This is particularly true of security adaptations because in many situations they are likely to prevent users from accessing functionality. In recent work, we have focussed on software engineering techniques that support this through traceability for explaining adaptive security de...

Online Cyber Security Discussion

Image
Ready to start my first Twitter discussion for #FutureLearnAsks As we kick off the next presentation of the Introduction to Cyber Security MOOC , I took part in an online discussion on the topic with Cory Doctorow and Andrew Smith on Twitter.  This was my first time leading one of these "Ask Me Anything" sessions, which was hosted by FutureLearn as part of a new initiative called #FutureLearnAsks.  Although at times I struggled to keep up with the speed of the conversation, it was a lot of fun to engage with a diverse group of people to talk about this important topic. The discussion was seeded by a number of questions, ranging from "Is the state justified to monitor personal digital and telecommunications in the name of security?" to "What one tip would you give to people to better protect their cyber security?"  One key lesson learned about asking open ended questions like this was that if the answer is always going to start with "It depends ...

Cyber security careers

I am working on wrapping up the first presentation of Introduction to Cyber Security and preparing for the next presentation, which is now open for registration and will start on 26 January 2015 .   The popularity of the first presentation demonstrates a recognition of the importance of cyber security.  Hopefully some of the 15,000+ learners who engaged with the course will be inspired to study further and perhaps even pursue a career in the field.  This is an important and exciting discipline to work in, with a variety of career paths depending on people's interests and aptitude. The Open University provides a range of modules and qualifications that can support this journey, and I recently wrote a short article about some of the career options in cyber security which has now been published on OpenLearn.

Reviewing debut run of Introduction to Cyber Security MOOC

Image
Introduction to Cyber Security MOOC The debut presentation of Introduction to Cyber Security MOOC came to an end this week. This 8-week MOOC was developed with the support of the UK National Cyber Security Programme and has been certified as a awareness level cyber security course by the CESG Certified Training programme. Over the next few weeks I will be working with colleagues to review the lessons learned from this first run and making the necessary changes to ensure that the next presentation goes smoothly. Some high-level numbers on the first presentation, as of the end of the Week 8 of the course, are as follows: Registered Learners: 24,245 Returning learners: 15,449 Active Learners: 12,977 (~84%) Fully participated: 3,692 (~24%) The percentages for active and fully participated learners has been calculated based on the number of returning learners rather than the total registrations.  'Active' means that a learner is still progressing through the content a...

Cyber security by the rest of us ...

Image
Breakdown of cyber crime types reported by learners in Week 1 As part of the Introduction to Cyber Security MOOC , we asked learners to review their computer security practices at the start of their learning by completing a simple online survey / self-audit.  Over 9100 learners completed the survey in Week 1 of the course, highlighting some interesting findings. For example, although 84% of respondents had configured their computers to require a password on startup, 30% did not 'lock' their computer so that it required the password to be re-entered if they left it unattended. With regard to password management, 55% of respondents depended on their memory for storing passwords, whereas 26% used software (password manager / web browser) to manage their passwords.  It is noteworthy that 18% reported that they write their passwords down and 59% reuse the same username / password across multiple websites. It was reassuring to note that 90% of learners who completed the...

Stuff people encrypt ....

Image
Rotors from an Enigma Machine This week on the I ntroduction to Cyber Security MOOC (hosted on Futurelearn), the topic is cryptography.  Learners are having fun figuring out how Alice and Bob communicate while keeping their messages secure from Eve - and sharing some funny xkcd.com cartoons in the process.  One of the exercises we set was to use a PGP mail tool ( Mailvelope ) to sign and encrypt an email sent to a mailbox we set up specifically for the MOOC.  I have a mail rule that invokes a simple script to strip out the PGP message text, decrypt it and send it back to the learner in an email. Although many people have successfully completed the task, there is a general consensus that routinely encrypting emails is unlikely to be adopted by most people.  The hurdles identified by people range from the impracticality of getting other people to use crypto in their communications, to the challenge of configuring the crypto tools and their general (lack of) u...

Cyber Security MOOC

Image
Introduction to Cyber Security Over the past few months I have been working with my colleagues at The Open University to produce a MOOC (Massive Open Online Course) that will provide learners with basic knowledge and skills relating to information security.  " Introduction to Cyber Security " is an 8-week course that will be hosted on the Futurelearn platform, with the first presentation scheduled to start on 13 October.  Learners will be guided through the content by Cory Doctorow, who is a visiting professor at the OU. The course was produced with the support of the UK government, as part of the National Cyber Security Programme, with the aim of raising general awareness and interest relating to cyber security.     It is hoped that learners who complete the course - from young people considering careers in computing, to those already in work looking to improve their knowledge and skills, or members of the public looking to protect themselves online - will ga...

Cloud Wedge - geek of the week

Image
CloudWedge: 'Geek of the Week' My colleague Yijun Yu recently wrote a opinion piece for The Conversation about how cloud computing could have made a difference to the search for Malayian Airlines MH370.  Essentially the question he poses is: why, in the age of global internet connectivity (including now onboard planes!), do we depend on the onboard flight data recorder for information about what happens on a plane? Of course there are numerous challenges with this - not least the cost of bandwidth for all the flight data (including cockpit audio) to be uploaded in real time and the security of the data.  Yijun's article addresses some aspects of the latter, and the former is not an insurmountable problem.  For example it should be possible to upload basic flight telemetry (e.g., GPS location, air speed, engine statistics and fuel data) without requiring significant bandwidth.  Indeed aero engine manufacturers such as Rolls-Royce deployed engine monitoring ...

Collaborative Adaptive Security

Image
Collaborative Adaptive Security scenario As part of our work on Adaptive Security and Privacy ( http://asap-project.info ) we are exploring the role of collaboration between different components in a ubiquitous computing environment in order to maximise the satisfaction of security requirements.  The intuition behind this is that the highly dynamic, heterogeneous device ecosystem of ubiquitous computing environments creates the need to satisfy different security requirements depending on the particular context.  The above video presents an early (and very rough!) example of the type of situation we are thinking about.  In this scenario, it is not possible for a single device in the environment to deliver all the required security functionality but if multiple devices collaborate, then the security requirement can be satisfied. Some of our initial ideas of how to engineer a system to exploit a collaborative adaptation for security will be presented at the upcoming...

Unmissable blogs ...

Image
I don't always have a lot of time to keep up with what is going on in the 'Blog-o-sphere', but there are a a few blogs that I try to read whenever possible.  In an effort to increase the frequency of my own blogging I thought it would be a good idea to write a post about my 'unmissable blogs': Prof.so - written by Anthony Finkelstein, provides some excellent insights into software engineering research and academia in general, with some great humour thrown in. Check out some of the excellent '10 Top ...' lists! Geek Prof - written by Ian Sommerville, is a blog I've only recently been introduced to but found to be a really good read.  Wise words about the state of academia and research, as well as insights on a range of topics that range from cybersecurity to software and systems engineering. Crypto-gram - written by Bruce Schneier, the content of which can be accessed in multiple forms, including a podcast and a email newsletter.  This is one ...

Calming those Angry Birds ...

Image
Screenshot of article on The Conversation site The latest revelations from the Snowden files includes evidence that NSA and GCHQ were tapping into some of the application analytics data being gathered by popular mobile applications like Angry Birds.  I was invited by The Conversation platform to contribute to a short article titled, " Angry Birds will have angry users until privacy rules are clear " that discusses this issue and where the responsibility for privacy and security in mobile applications lies.

Adaptive Security and Privacy

Image
My colleague, Prof. Bashar Nuseibeh, has been recently awarded a prestigious ERC Advanced Research grant, as well as a Royal Society-Wolfson Merit Award, to support research in the area of adaptive privacy and security.  As a co-Investigator on some of the previous projects in this area ( PRiMMA and Microsoft Research SEIF ), I am pleased to be part of the research team that will work on this research with Bashar and others.  To find out more about the research agenda, visit the Adaptive Security and Privacy project website .  On a related note, we are also starting a project on Adaptive Information Security for Cloud Computing , funded by the Qatar National Research Fund, which will involve collaborating with a research team based at Qatar University. As result of all this activity, we are soon going to be starting the recruitment process for both post-doctoral researchers and PhD students who have an interest in working in the area of adaptive systems for privacy ...

LinkedIn breach .. the multiplier effect

Image
Last week's high profile theft of password for the business networking site LinkedIn has been a topic of many news articles and blogs in the computing and security area.  There was a particularly interesting discussion of the issue of developers not understanding the security implications of using fast hashing algorithms which are intended for high-speed, on the wire, integrity checking such as SHA, for secure storage of passwords.  The argument here is that password hashes should actually use more computationally demanding (i.e. slower) algorithms.  This would increase the cost to the attacker in conducting a brute force attack to identify the correct plain text to match the encrypted passwords in the stolen file(s). The immediate countermeasure that was publicised through media and through social network 'word of mouth' was that people should change their LinkedIn password.  Of course this created the opportunity for phishing attackers (unrelated to those who...