52
Anonymous 20*20

Anonymous 20*20

  • Upload
    masao

  • View
    38

  • Download
    0

Embed Size (px)

DESCRIPTION

Anonymous 20*20. Joshua Corman. Jericho. Chief Curmudgeon for attrition.org President/COO of Open Security Foundation (OSF) Director of Non-profit Activity at Risk Based Security Industry Experience - PowerPoint PPT Presentation

Citation preview

Page 1: Anonymous 20*20

Anonymous 20*20

Page 2: Anonymous 20*20

Director of Security Intelligence for Akamai Technologies

Former Research Director, Enterprise Security [The 451 Group]

Former Principal Security Strategist [IBM ISS]

Industry Experience Faculty: The Institute for Applied

Network Security (IANS) 2012 Vanity Fair Hero Co-Founder of “Rugged Software”

www.ruggedsoftware.org

Things I’ve been researching Compliance vs Security Disruptive Security for Disruptive

Innovations Chaotic Actors Espionage Security Metrics

2

Chief Curmudgeon for attrition.org President/COO of Open Security Foundation (OSF) Director of Non-profit Activity at Risk Based Security

Industry ExperienceFaculty: Honorary Professor @

University of Dayton School of Law 2000-2001, CyberCrime Curriculum

2000 Vanity Fair VillainPresident / COO of Open Security

Foundation (OSF)

Things I’ve been researchingThe Myth of Compliance & Certification Disruptive Rants and Twitter RepliesInfoSec Industry ErrataSquirrelsVulnerability Databases & Metrics

JerichoJoshua Corman

Page 3: Anonymous 20*20

Consequences: Replaceability

3

http://blog.cognitivedissidents.com/2011/10/24/a-replaceability-continuum/

Page 4: Anonymous 20*20

Anon

“Good Guys”

Analysts

Civilians LEO

Page 5: Anonymous 20*20

=

Page 6: Anonymous 20*20
Page 7: Anonymous 20*20
Page 8: Anonymous 20*20
Page 9: Anonymous 20*20
Page 10: Anonymous 20*20

Endgame Ethics

Page 11: Anonymous 20*20

Chaotic Actor

Page 12: Anonymous 20*20

12

Page 13: Anonymous 20*20

Lots & Lots of Anonymous Sects

13

Page 14: Anonymous 20*20

“Anonymous is God’s gift to the Chinese” – Government Agency CISO

False Flag: Criminal & State Actors

Page 15: Anonymous 20*20

Cyber-Neo-McCarthyism

Page 16: Anonymous 20*20
Page 17: Anonymous 20*20

Mastercard / Visa – Denying payments to Wikileaks

PayPal – Suspended Wikileaks account

Sony – Lawsuit against PlayStation 3 hacker George Hotz

HBGary – Threat of outing Anonymous leaders

Retaliation

Page 18: Anonymous 20*20

Operation Payback

Page 19: Anonymous 20*20

Beyond Operation Payback

Page 20: Anonymous 20*20

Data on Anonymous

Page 21: Anonymous 20*20

Name: Anonymous Hacktivism

Denial of ServiceDefacements

Use of Iconography Decentralized Group

What is really new?

Page 22: Anonymous 20*20

A Mirror to Our Neglect…

Page 23: Anonymous 20*20
Page 24: Anonymous 20*20

Modern Pantheon of Adversary Classes

TargetsCredit Card

#s

Web Presence

Connectivity

Intellectual Property

PII / Identity

Cyber Infrastruct

ure

Core Business Processes

Impacts

Reputational Personal Confidentiality Integrity Availability

Motivations

Financial Industrial Military Ideological Political Prestige

Actors

States Competitors

Organized Crime

Script Kiddies Terrorists Hacktivis

ts Insiders Auditors

Page 25: Anonymous 20*20
Page 26: Anonymous 20*20
Page 27: Anonymous 20*20

Anonymous & the Law

Page 28: Anonymous 20*20

Anonymous Activity

Page 29: Anonymous 20*20

Law Enforcement Activity

Page 30: Anonymous 20*20

The Face of Anonymous*

Page 31: Anonymous 20*20

The Unknowns of Anonymous

~270

Page 32: Anonymous 20*20
Page 33: Anonymous 20*20

Crossroads

Page 34: Anonymous 20*20
Page 35: Anonymous 20*20
Page 36: Anonymous 20*20

Chaotic Good

Legislation

Watchdog

Chaotic Good

Free Speech

Chaotic Good

Moral Outrage

Anonymous Identity/Meme“General Population”

MalSec?

ChaoticGood? or

Evil?

Leave

LulzSec

ChaoticEvil

Page 37: Anonymous 20*20

“If you believe something…”

Page 38: Anonymous 20*20
Page 39: Anonymous 20*20

Finger on the Pulse

Page 40: Anonymous 20*20

Vigilantism?

Page 41: Anonymous 20*20

Predictions about Anonymous are [interesting|amusing|ridiculous]

“Will this mean the end of Anonymous? No. It will mean the end of LulzSec, but Anonymous existed before LulzSec and will continue existing. However we probably won't see any more hacks as the ones LulzSec had been perpetrating, and Anonymous will only use their known childish tactic of DDoS using their LOIC tool.” -- Luis Corrons, Panda Security.

Page 42: Anonymous 20*20

Anonymous as an Industry

Page 43: Anonymous 20*20
Page 44: Anonymous 20*20

Control and Chaos”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

Page 45: Anonymous 20*20

Does not one cause the other?”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

“It’s a Trap” on shirt.woot.com

Page 46: Anonymous 20*20

1914

Page 47: Anonymous 20*20

With Great Power?

"When you don't have centralized leadership, it doesn't matter what most will do, it matters what one

of them will do," Corman said.

Page 48: Anonymous 20*20

Back to Anonymous 2020

Page 49: Anonymous 20*20

The Future of Anonymous

Page 50: Anonymous 20*20
Page 51: Anonymous 20*20

Thank You & Contact Mar @ sudux.com @krypt3ia “anonymous” contributors “unspecified” contributors

@attritionorg @JoshCorman

http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/

Page 52: Anonymous 20*20