Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

23
Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler Steve Bongardt The Gyges Group

Transcript of Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Page 1: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

ConceptsofBehavioral&CyberProfiling:My

ExperienceastheFBI’sfirstCyberProfiler

SteveBongardtTheGyges Group

Page 2: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler
Page 3: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

FirstTenetofBehavioralProfilingPeoplewillbelievewhattheywantorneedtobelieveinspiteofallevidenceandinformationtothecontrary

TheGygesGroup,LLC

Page 4: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

SecondTenetofBehavioralProfilingThenumberonepredictoroffuturebehaviorispastbehavior.

TheGygesGroup,LLC

Page 5: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Behavioral&CyberProfilingPurpose&KeyConcepts

Page 6: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler
Page 7: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

SOURCE:MomentumPartners athttp://momentum.partners/docs/Cybersecurity_Market_Review_Q1_2016.pdf

Page 8: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Cyberprofiling

Anassessment(ofanunauthorizedaccesstoaninformationsystem)fromabehavioral,investigativeandforensicperspectivetoassistintheprioritizationofresources,andinanoftenhighlytechnicalinvestigation,provideanindicationthatattemptsatattributionarefocusinginadirectionconsistentwithwhatisknownaboutbehavior(inthecontextoftheunauthorizedaccess).

TheGygesGroup,LLC

Page 9: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

“Traditional”CriminalProfiling– AreasofFocus

VictimologyInitialContactVictimControlContentAnalysisVictimDisposalBehavioralSignature=ModusOperandi+RitualTypologyMixedCrimeScene

TheGygesGroup,LLC

Page 10: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

“Traditional”CriminalProfiling– AreasofFocus

VictimologyInitialContactVictimControlVictimDisposalBehavioralSignature=ModusOperandi+RitualTypologyMixedCrimeScene

ApplyingCyberProfilingProactively:AUniqueWayofAssessingyourSecurityStackand theAttackKillChainatthe

sametime

TheGygesGroup,LLC

Page 11: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

"Despitetheindustry’stwenty-yearfocusonmalwaredetectionandprevention,itturnsoutthatonce

attackersgainaccesstoanetwork,thevastmajorityofactivitymakesuseofbenignprocessesandtools,notmalware.Inresearchingthisreport,weidentified1,109totaluniquetoolsresponsibleforattackbehavior,and

themajorityofthosetoolswerenotmalicious"

Source:Lightcyber.com "CyberWeapons2016Report"availableathttp://lightcyber.com/wp-content/uploads/2016/06/

Page 12: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Typology

Page 13: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Typology

Aconstructdevelopedempiricallyorexperientially,usedintheanalysisofanoffenseorseriesofoffensesofaspecifictype,whichaidsthebehavioralanalysttoevaluatethebehaviormeasuredorobservedwithintheoffense(s)withthegoalofinferringtraitsorcharacteristicsoftheoffender(s)

TheGygesGroup,LLC

Page 14: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

SexualHomicide

Organized vs Disorganized

ChildContactOffenses

Preferential vs Situational/Opportunistic

Page 15: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

CyberAttackTypology

TheGygesGroup,LLC

Page 16: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

MixedBreach/UnauthorizedAccess

Page 17: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

TheGygesGroup,LLC

Page 18: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Training&Education

Page 19: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Application/Hire

Employee

Exit/Termination

InsiderRiskThreat(InsRT)Program

TheGygesGroup,LLC

Page 20: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

Thankyou!

?Questions?SteveBongardtTheGyges Group

[email protected]

Page 21: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

ManandConformity

•PlatonicDialogues• TheRepublic

• BookII,verse359b• Glaucon’s retorttoSocratesonthenatureofinjusticeandman• “Eventhosewhopracticeit(justice)dosounwillingly”

• Tellsthestoryofthe“RingofGyges”

http://mises.org/images4/AthenianSteps.jpg

TheGygesGroup,LLC

Page 22: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

“Traditional”CriminalProfiling– AreasofFocus

VictimologyInitialContactVictimControlVictimDisposalBehavioralSignature=ModusOperandi+RitualTypologyMixedCrimeScene

ApplyingCyberProfilingProactively:AUniqueWayofAssessingyourSecurityStackand theAttackKillChainatthesame

time

TheGygesGroup,LLC

Page 23: Concepts of Behavioral & Cyber Profiling: My Experience as the FBI’s first Cyber Profiler

BehavioralorPsychologicalProfilingTheories

• RetrospectiveProfiling• A“behavioralcomposite”ofpossiblepersonalitytraitsandcharacteristicsofaspecificoffenderbasedonaspecificcrimeorseriesofcrimescanbeconstructed.• “Crime”orspecificbehavior• Thisisalsocalled“HOMOLOGY”(theprimaryororiginaltheoryofprofiling)

• ProspectiveProfiling• Bystudyingpastoffendersofspecifictypesandcategoriesofcrime,wecanpredict,inageneralsense,thetraitsandcharacteristics,behavioralandsocio-demographic,offutureoffendersofthosetypesandcategoriesofcrime.

• BehavioralConsistency• Thereissomeprobabilitythatanindividualwillrepeatedlycommitsimilartypesofoffensesanddosoinsimilarways.• >>>“Linkage”

TheGygesGroup,LLC