CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

11
Asymmetric Defense: Using Your Home Field Advantage May 28, 2014 Brian Wohlwinder

description

This presentation will focus on leveraging knowledge of your own environment to defend yourself. Consciously identifying and building protections around key assets and information that an adversary would target, allows for the most effective protection for the enterprise. We will discuss several attack/defense scenarios, the associated systems and infrastructure involved and key areas to protect. We’ll also show how effort invested to enumerate critical assets can allow the defender to quickly prioritize actions for the greatest effect.

Transcript of CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Page 1: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Asymmetric Defense: Using Your Home Field Advantage

May 28, 2014

Brian Wohlwinder

Page 2: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

ASYMMETRIC DEFENSE

Page 3: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Home Field Advantage

Page 4: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Using your Home Field Advantage

• Understand and define your environment

• Study your opposition

• Proactive Defense

Page 5: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Your Environment

Team– Tactical skills– Strategically focused

Knowledge– System of systems

Plan– Response actions

Page 6: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Event Relativity

White Noise

Informative

Indicative

Page 7: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Who is your opponent?

Threat to target mapping– Depends on what you have…– patient, determined and smart

Focus efforts– Try to protect everything and you protect nothing

Monitor what is leaving your network– Easier said than done

Page 8: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Proactive Defense

Proactive defense– The fun part

Go hunting

Do this smartly

Page 9: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

Using your Home Field Advantage

Understand your environment

Study your opposition

Proactive Defense

Own it

Become a rock star!

…it really is that easy.

Page 10: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”
Page 11: CONFidence 2014: Brian Wohlwinder: Asymmetric Defense “Using your home-field advantage”

THANK YOU.

Brian Wohlwinder

Senior Threat Researcher

[email protected]

General Dynamics Fidelis Cybersecurity Solutions

www.FidelisSecurity.com www.ThreatGeek.com