Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First...

273
Network Defender First Principles Rick Howard - CSO

Transcript of Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First...

Page 1: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender First Principles

Rick Howard - CSO

Page 2: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 3: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Page 4: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Page 5: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Page 6: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Page 7: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Y-Axis: Hope

Page 8: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

X-Axis: Time

Page 9: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Page 10: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Non-Geeks – The Beautiful People

Page 11: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Non-Geeks – The Beautiful People

Page 12: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Non-Geeks – The Beautiful People

I’ll just wait a bit; maybe it will come back

Page 13: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Hmmm … this is taking too long

Geek Non-Geek

Non-Geeks – The Beautiful People

Page 14: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Hmmm … this is taking too long

Geek Non-Geek

Non-Geeks – The Beautiful People

Page 15: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Non-Geeks – The Beautiful People

Call the ISP

Page 16: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Non-Geeks – The Beautiful People

Call the ISP

They Are Always so Helpful

Page 17: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Call the ISP

Non-Geeks – The Beautiful People

Page 18: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Non-Geeks – The Beautiful People

Call the ISP

Page 19: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

Page 20: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

Reload

Page 21: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Page 22: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site

Page 23: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Page 24: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Page 25: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

Page 26: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

Page 27: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

!@#^!@&^

Page 28: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

!@#^!@&^

pingifconfig

rebootdmesgtraceroute

iptables

Page 29: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

!@#^!@&^

pingifconfig

rebootdmesgtraceroute

iptables

Page 30: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

!@#^!@&^

pingifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Page 31: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

!@#^!@&^

pingifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Call the ISP

Page 32: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

!@#^!@&^

pingifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Call the ISP

They Are Always so Helpful

Page 33: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

Geek Non-Geek

Geeks – My Peeps

ReloadReload

Try Another Site Reload

Check network settings

Switch WiFiOn/Off

That will fix everything

!@#^!@&^

pingifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Call the ISP

Page 34: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

ReloadReload

Try Another Site Reload

Check network settings

That will fix everything

Switch WiFiOn/Off

ping

!@#^!@&^

ifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Hmmm … this is taking too long

Call the ISPCall the ISP

Geek Non-Geek

Page 35: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

ReloadReload

Try Another Site Reload

Check network settings

That will fix everything

Switch WiFiOn/Off

ping

!@#^!@&^

ifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Hmmm … this is taking too long

Call the ISPCall the ISP

Geek Non-Geek

Page 36: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

ReloadReload

Try Another Site Reload

Check network settings

That will fix everything

Switch WiFiOn/Off

ping

!@#^!@&^

ifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Hmmm … this is taking too long

Call the ISPCall the ISP

Geek Non-Geek

Page 37: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Time

Hope

Source: Bruno Oliveira

Geeks vs Non-Geeks: Reaction to flaky internet connection

ReloadReload

Try Another Site Reload

Check network settings

That will fix everything

Switch WiFiOn/Off

ping

!@#^!@&^

ifconfig

rebootdmesgtraceroute

iptables

I’ll just wait a bit; maybe it will come back

Hmmm … this is taking too long

Call the ISPCall the ISP

Geek Non-Geek

Page 38: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

AUTHORITY: FEAR UNCERTAINTY AND DOUBT COMMITTEE

STATE OF CALIFORNIA

Page 39: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

AUTHORITY: FEAR UNCERTAINTY AND DOUBT COMMITTEE

STATE OF CALIFORNIA

Page 40: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender First Principles

Page 41: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ElonMusk

Page 42: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ElonMusk

Page 43: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ElonMusk

Page 44: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ElonMusk

Page 45: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ElonMusk

Page 46: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ElonMusk

Page 47: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a First Principle?

Principia Mathematicapublished in 1913

Page 48: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a First Principle?

Principia Mathematicapublished in 1913

Page 49: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Principia Mathematicapublished in 1913

What is a First Principle?

Page 50: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Analogy vs First Principle

Page 51: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Analogy vs First Principle

Page 52: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Analogy vs First Principle

Page 53: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Leap Ahead

Analogy vs First Principle

Page 54: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Leap Ahead

Analogy vs First Principle

Page 55: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Leap Ahead

Analogy vs First Principle

Page 56: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Semantic Tree

Page 57: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Semantic Tree

Page 58: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Semantic Tree

Page 59: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Limbs

Semantic Tree

Page 60: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

LeavesSemantic Tree

Page 61: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a First Principle?

Page 62: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

What is a First Principle?

Page 63: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

SelfEvident

What is a First Principle?

Page 64: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

SelfEvident

ExpertsAgree

What is a First Principle?

Page 65: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

SelfEvident

ExpertsAgree

Atomic

What is a First Principle?

Page 66: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

SelfEvident

ExpertsAgree

Atomic

What is a First Principle?

Page 67: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

SelfEvident

ExpertsAgree

Atomic

New

What is a First Principle?

Page 68: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

SelfEvident

ExpertsAgree

Atomic

New

FirstPrinciples

What is a First Principle?

Page 69: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a First Principle?

1+1=2

Page 70: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

1+1=2

*Note:Mightbeusefultoknow

What is a First Principle?

Page 71: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Problem SpaceTh

ird In

nova

tion

1994

First Intrusion Detection System

1985 1987 2004 2007 2010 2014

Page 72: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2007 2010 2014

Network Defender Problem Space

Page 73: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2007 2010 2014

Network Defender Problem Space

Page 74: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987

First Detection System

2004 2007 2010 2014

Network Defender Problem Space

Page 75: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2006 2010 2014

First Data Loss Protection Systems

Network Defender Problem Space

First Detection System

Page 76: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004

First Data Loss Protection Systems

2006 2010 2014

Network Defender Problem Space

First Detection System

Page 77: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2007 2010 2014

First Data Loss Protection Systems

Network Defender Problem Space

First Detection System

Page 78: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2007 2010 2014

First Data Loss Protection Systems

Network Defender Problem Space

First Detection System

Page 79: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2007 2010 2014

First Data Loss Protection Systems

Network Defender Problem Space

First Detection System

Page 80: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2007 2010 2014

Leap Ahead

First Data Loss Protection Systems

Network Defender Problem Space

First Detection System

Page 81: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987 2004 2007 2010 2014

First Data Loss Protection Systems

Network Defender Problem Space

First Detection System

Page 82: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 83: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 84: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 85: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 86: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 87: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 88: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 89: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Page 90: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Victim

Prefatory First Principle Statements

Page 91: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Prefatory First Principle Statements

Victim

Page 92: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Threats

Wow! That’s a lot!

?

Prefatory First Principle Statements

Page 93: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Risk Matrix

Prefatory First Principle Statements

Page 94: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

X-Axis: Likelihood

Prefatory First Principle Statements

Risk Matrix

Page 95: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Y-Axis: Impact

Prefatory First Principle Statements

Risk Matrix

Page 96: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a Network Defender First Principle?

Page 97: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a Network Defender First Principle?

Page 98: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a Network Defender First Principle?

Page 99: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a Network Defender First Principle?

Page 100: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a Network Defender First Principle?

Page 101: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a Network Defender First Principle?

Page 102: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

What is a Network Defender First Principle?

Page 103: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Whatisit?

What is a Network Defender First Principle?

Page 104: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Whatisit?

Whatshoulditbe?

What is a Network Defender First Principle?

Page 105: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Whatisit?

Whatshoulditbe?

Whatdoweagreethatitshoulditbe?

What is a Network Defender First Principle?

Page 106: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

“Wemustidentifythetrunkandthebigbranchesfirstsothatwhenwediscovertheleaveslater,wewillhavesomethingtohangthemon.”

What is a Network Defender First Principle?

Page 107: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree

Page 108: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

1Trunk

Network Defender Semantic Tree

Page 109: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

5Limbs

Network Defender Semantic Tree

Page 110: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Leaves

Network Defender Semantic Tree

Page 111: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The Trunk

Page 112: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: The Trunk

Page 113: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: The Trunk

Page 114: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 115: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

PreventHighRiskMaterialImpactTrunk

Network Defender Semantic Tree: The Trunk

Page 116: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 117: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 118: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 119: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 120: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 121: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 122: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trunk

Network Defender Semantic Tree: The Trunk

Page 123: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

High ProbabilityTrunk

Network Defender Semantic Tree: The Trunk

Page 124: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

High damage

TrunkHigh Probability

Network Defender Semantic Tree: The Trunk

Page 125: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

PreventHighRiskMaterialImpact

Network Defender Semantic Tree: The Trunk

Page 126: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The First Limb

Page 127: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

EstablishaRobustThreatPreventionprogram

Limb

Page 128: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 129: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 130: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

NEW

Network Defender Semantic Tree: First Limb

Page 131: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

NEW

Network Defender Semantic Tree: First Limb

Page 132: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

NEW

Network Defender Semantic Tree: First Limb

Page 133: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 134: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 135: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Victim

Network Defender Semantic Tree: First Limb

Page 136: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Victim

Network Defender Semantic Tree: First Limb

Page 137: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

IndicatorsofCompromise areforensicartifactsthatdescribeanadversary’smethodology;digitalcluesleftbehindbytheadversarygroupasitworksitswaythroughthephasesoftheattacklifecycle.

Network Defender Semantic Tree: First Limb

Page 138: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

IndicatorsofCompromise areforensicartifactsthatdescribeanadversary’smethodology;digitalcluesleftbehindbytheadversarygroupasitworksitswaythroughthephasesoftheattacklifecycle.

Network Defender Semantic Tree: First Limb

Page 139: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

IndicatorsofCompromise areforensicartifactsthatdescribeanadversary’smethodology;digitalcluesleftbehindbytheadversarygroupasitworksitswaythroughthephasesoftheattacklifecycle.

Network Defender Semantic Tree: First Limb

Page 140: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Theattacklifecycle isaphasedmodelthatdescribesthetasksanadversarygroupmustaccomplishinordertocompletetheirmission

Network Defender Semantic Tree: First Limb

Page 141: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Theattacklifecycle isaphasedmodelthatdescribesthetasksanadversarygroupmustaccomplishinordertocompletetheirmission

Network Defender Semantic Tree: First Limb

Page 142: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Theattacklifecycle isaphasedmodelthatdescribesthetasksanadversarygroupmustaccomplishinordertocompletetheirmission

Network Defender Semantic Tree: First Limb

Page 143: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Theattacklifecycle isaphasedmodelthatdescribesthetasksanadversarygroupmustaccomplishinordertocompletetheirmission

Network Defender Semantic Tree: First Limb

Page 144: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Theattacklifecycle isaphasedmodelthatdescribesthetasksanadversarygroupmustaccomplishinordertocompletetheirmission

Network Defender Semantic Tree: First Limb

Page 145: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Theattacklifecycle isaphasedmodelthatdescribesthetasksanadversarygroupmustaccomplishinordertocompletetheirmission

Network Defender Semantic Tree: First Limb

Page 146: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Theattacklifecycle isaphasedmodelthatdescribesthetasksanadversarygroupmustaccomplishinordertocompletetheirmission

Network Defender Semantic Tree: First Limb

Page 147: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 148: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 149: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 150: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 151: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 152: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 153: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 154: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

MOST

Network Defender Semantic Tree: First Limb

Page 155: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

MOST

Network Defender Semantic Tree: First Limb

Page 156: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ThreatPrevention istheactofturningknownindicatorsofcompromiseintooneormoredeployedpreventioncontrols.

Network Defender Semantic Tree: First Limb

Page 157: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

ThreatPrevention istheactofturningknownindicatorsofcompromiseintooneormoredeployedpreventioncontrols.

Network Defender Semantic Tree: First Limb

Page 158: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 159: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 160: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Precision

Network Defender Semantic Tree: First Limb

Page 161: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 162: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 163: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

99% Guarantee

Network Defender Semantic Tree: First Limb

Page 164: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

99% Guarantee

Network Defender Semantic Tree: First Limb

Page 165: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: First Limb

Page 166: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatPreventionprogram

1st Limb

Network Defender Semantic Tree: First Limb

Page 167: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The Second Limb

Page 168: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatDetectionProgram

Limb

Network Defender Semantic Tree: 2d Limb

Page 169: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 170: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 171: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 172: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 173: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 174: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 175: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 176: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 177: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 178: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

178

Page 179: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

179

Page 180: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 181: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 182: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 183: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 184: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 185: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 186: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 187: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 188: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 2d Limb

Page 189: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatDetectionProgram

2nd Limb

Network Defender Semantic Tree: 2d Limb

Page 190: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The Third Limb

Page 191: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatEradicationProgram

3rd Limb

Network Defender Semantic Tree: 3rd Limb

Page 192: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 193: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 194: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 195: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 196: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Threateradication istheactofminimizing theeffectivenessofnewlydiscoveredadversarycampaignactivitybyblocking futureactivitythroughtheThreatPreventionprogram,analyzingthepurposeofthisnewcampaign,andinstallingadditionalcountermeasuresthatwilllikelythwarttheaccomplishmentofthecampaignobjectives.

Network Defender Semantic Tree: 3rd Limb

Page 197: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Threateradication istheactofminimizingtheeffectivenessofnewlydiscoveredadversarycampaignactivitybyblockingfutureactivitythroughtheThreatPreventionprogram,analyzingthepurposeofthisnewcampaign,andinstallingadditionalcountermeasuresthatwilllikelythwarttheaccomplishmentofthecampaignobjectives.

Impact Mitigation

Network Defender Semantic Tree: 3rd Limb

Page 198: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 199: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 200: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 201: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 3rd Limb

Page 202: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatEradicationProgram

3rd Limb

Network Defender Semantic Tree: 3rd Limb

Page 203: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The Fourth Limb

Page 204: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

CreatetheNetworkDefender’sTrinity.

4th Limb

Network Defender Semantic Tree: 4th Limb

Page 205: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 4th Limb

Page 206: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 4th Limb

Page 207: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Inextricablylinked

Network Defender Semantic Tree: 4th Limb

Page 208: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Inextricablylinked

Network Defender Semantic Tree: 4th Limb

Page 209: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Inextricablylinked

Network Defender Semantic Tree: 4th Limb

Page 210: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Trinity

Network Defender Semantic Tree: 4th Limb

Page 211: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

CreatetheNetworkDefender’sTrinity.

4thLimb

Network Defender Semantic Tree: 4th Limb

Page 212: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The Last Limb

Page 213: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Embracecybersecurityintelligencecollectionandubiquitoussharing

5thLimb

Network Defender Semantic Tree: 5th Limb

Page 214: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 215: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 216: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Collected

Network Defender Semantic Tree: 5th Limb

Page 217: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Collected

Sorted

Network Defender Semantic Tree: 5th Limb

Page 218: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Collected

Sorted

Evaluated

Network Defender Semantic Tree: 5th Limb

Page 219: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Collected

Sorted

Evaluated

Prioritized

Network Defender Semantic Tree: 5th Limb

Page 220: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Intelligencecollection istheactofgatheringIndicatorsofCompromise fromnetworkandendpointsystemsthroughouttheenterpriseanddiscoveringanysupplementalinformationfrominternalandexternalsourcesthatcanaddcontextaboutwhattheadversarygroupisabout.

Network Defender Semantic Tree: 5th Limb

Page 221: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Intelligencecollection istheactofgatheringIndicatorsofCompromise fromnetworkandendpointsystemsthroughouttheenterpriseanddiscoveringanysupplementalinformationfrominternalandexternalsourcesthatcanaddcontextaboutwhattheadversarygroupisabout.

Page 222: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 223: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 224: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 225: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Maximize

Page 226: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Maximize

Network Defender Semantic Tree: 5th Limb

Page 227: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 228: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 229: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 230: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 231: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 232: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 233: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Page 234: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

BenefitsAll

Network Defender Semantic Tree: 5th Limb

Page 235: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender Semantic Tree: 5th Limb

Benefits

Page 236: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Embracecybersecurityintelligencecollectionandubiquitoussharing

Limb

Network Defender Semantic Tree: 5th Limb

Page 237: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The Cyber Threat Alliance

Page 238: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Founding CEOs

Mark McLaughlin Michael Brown Ken Xie Chris Young

Page 239: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Founding Members:

Purpose: The Cyber Threat Alliance is a group of cyber security practitioners that have chosen to share threat information with each other for the purpose of improving defenses against advanced cyber adversaries across member organizations and their customers.

Page 240: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Rick Howard Vishaal Hariprasad Derek MankyJoe Chen Jeannette JarvisVincent Weafer

Working Committee

Page 241: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

2 Initial Issues

Build Trust

Build Infrastructure

Rick Howard Vishaal Hariprasad Derek MankyJoe Chen Jeannette JarvisVincent Weafer

Page 242: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

New Contributing Members:

Membership: Open to any organization that can share a minimum volume of threat intelligence designed by the Alliance.

Page 243: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

New Contributing Members:

Membership: Open to any organization that can share a minimum volume of threat intelligence designed by the Alliance.

White House Summit on Cybersecurity and Consumer Protection held at Stanford University

Page 244: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Two Unique Organizing Principles:

• Must Contribute.

• Whatever is shared goes directly into the product line.

Result: Automatic Prevention Controls.

Page 245: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Mark McLaughlin Michael Brown Ken Xie Chris Young

Founding CEOs

Page 246: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Founding CEOs

Mark McLaughlin Michael Brown Ken Xie Chris Young

Page 247: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Mark McLaughlin Michael Brown Ken Xie Chris Young

Page 248: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Mark McLaughlin Michael Brown Ken Xie Chris Young

Page 249: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 250: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 251: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 252: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 253: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 254: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 255: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 256: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 257: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System
Page 258: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

The only smart thing for the network defender to do is to share everything; crowd source threat intelligence so that only the advanced adversary can keep up.K

ey T

ake-

Aw

ay:

Shar

e Ev

eryt

hing

Where We Need to Go

Page 259: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Conclusion

Page 260: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

1994

First Firewall

First Intrusion Detection System

1985

First Anti-Virus System

1987

First Detection System

2004 2007 2010 2014

First Data Loss Protection Systems

25 Years of Incremental Improvement

Page 261: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Rethink the Network Defender Problem Space

Leap Ahead

Page 262: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Third

Inno

vatio

n

ElonMusk

Rethink the Network Defender Problem Space

Page 263: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Fundamental

SelfEvident

ExpertsAgree

AtomicFirstPrinciples

Rethink the Network Defender Problem Space

Page 264: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Semantic Tree

Limbs

Trunk

Page 265: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Network Defender First Principles

PreventHighRiskMaterialImpact

Page 266: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatPreventionprogram

1st Limb

Network Defender First Principles

Page 267: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatDetectionProgram

2nd Limb

Network Defender First Principles

Page 268: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

EstablishaRobustThreatEradicationProgram

3rd Limb

Network Defender First Principles

Page 269: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

TheNetworkDefender’strinityisinextricablylinked,atomic,andirreducible

4th Limb

Network Defender First Principles

Page 270: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Embracecybersecurityintelligencecollectionandubiquitoussharing

5th Limb

Network Defender First Principles

Page 271: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

More Information

Page 272: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

Rick Howard: CSO Palo Alto NetworksEmail: [email protected]: @raceBannon99

https://paloaltonetworks.com/threat-research.html

https://paloaltonetworks.com/threat-research/cybercanon.html

http://cyberthreatalliance.org/

Con

tact

Info

rmat

ion

Call to Action

First Principle White Paper:http://researchcenter.paloaltonetworks.com/2016/03/first-principles-for-network-defenders-a-unified-theory-for-security-practitioners/

Page 273: Network Defender First Principles · 2016. 11. 17. · Network Defender Problem Space First Detection System. Third Innovation 1994 First Firewall First Intrusion Detection System

End