Search for Cybersecurity's Unit of Work
AI Attack Slop: Cybersecurity's Newest Script Kiddies
The Haystack and the Needles: Why Lossless Cybersecurity Analytics Require Deterministic Pipelines
Which Detective Would You Hire? The Case for Deterministic Cybersecurity
Podcast: Adventures of Alice & Bob
Three Prompts That Turn Your Data Lake Into an Empathetic Processor
Blaster, Mythos, and the Patching Tempo We're About to Need
Why the Fork: Addressing the Objections
The Nuclear Code Fork
Dragon 305: AI Lessons from the Flight Deck
GrrCON 2024 - Birthing Perjury-free AI
Abstract
Cybersecurity analysis leading to deterrence of cybercrime requires processing thousands to billions of digital signals per second. Those signals must be accurately comprehended, forensically preserved then used to detect and investigate potential cybercrime. The work products must not only assist the investigators but must be translated into language that non-technical lay audiences including judges, lawyers and jurors can understand.
This presentation explores how generative artificial intelligence (GenAI), natural language processing (NLP), graph-theory and artificial narrow intelligence (ANI) can play a role in delivering these outcomes.
The session includes demonstrations of opensource toolkits, datasets and models designed to assist in this work.
TechnoWest 2024 - Birthing Perjury-free AI
ChiBrrCon Talk 2: Birthing Perjury-free AI
Abstract
While believability of an AI (Turing test) is important in many applications, the need for forensic truth is paramount in cybersecurity application. In this session, we will evaluate methods for training and tuning models that meet requirements of evidence handling, business analysis and legal and martial response.
ChiBrrCon Talk 1: SECOPS Driving Criminal Prosecution
DarkRhiino Podcast - 7 Unstable Conversations
Machine Learning Driven Social Engineering
GrrCON 2023 - Deterring Cybercrime via a Global CyberGrid
Abstract
Detecting, catching and successfully prosecuting cybercrime requires collaboration across private sector, law enforcement, insurance companies and national security agencies. In this session, approaches to collect, analyze, store and share digital evidence will be examined. Methods of safely transmitting data between private sector and law enforcement will be discussed. Demonstration of workflows between investigators, law enforcement, prosecutors and insurance adjusters will be covered.
I also reference this 2021 DarkReading Article: Handcuffs over AI.
Big Data in Cybersecurity
An updated deck for my talk on Big Data in Cybersecurity can be downloaded here.
Salving Vendor Fatigue with AI
Artificial Narrow Intelligence (ANI) in Cybersecurity
BSidesSPFD - SECOPS Driving Prosecution via a Global CyberGrid
In a 2021 DarkReading article titled Handcuffs over AI, I describe the importance focusing on the outcome of increasing deterence in cybercrime. The presentation can be downloaded here.
Profit and Loss (PNL) of Cyber Security
The purpose of a CISO and a cyber program is to reduce the costs associated with cybersecurity. I said this to colleagues at a social mixer this week and their heads almost exploded. “Shouldn’t we be trying to stop and mitigate risk?” “We need to spend more money on cyber, not less.” “I can’t believe you, of all people, think we need to be doing less!”
Audacious Proposal
“Do you want to give up and let the bad guys win?” I want businesses to understand that cybercrime is a part of business in the exact same (not metaphorical) way as shoplifting, employees stealing office supplies, customers slipping on the floor, vandalism, executives abusing power against employees, hurricanes, power failures, earthquakes, flooding and taxes.
The goal in all risk management is to reduce the costs associated with the mishaps not to make them impossible.
Log4J/LogShell IOC search
Log4J/LogShell (CVE-2021-44228) exploit IOC have been published by Cisco Talos (see: https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html). These IOC have been packaged as a WitFoo Actor definition and have been pushed to all production instances of WitFoo Precinct and Precinct Cloud. The definitions were automatically applied at 1404 Eastern Standard time on December 14, 2021. Detections are both forward looking and retrospective across the entire Precinct big-data archive.
Actor functionality has been pushed early (ahead of 6.2 GA release) to allow data to be searched. A quick overview of the functionality can be viewed below.
Emergency Update for CVE-2021-44228 (log4j / Log4Shell)
CVE-2021-44228 (https://nvd.nist.gov/vuln/detail/CVE-2021-44228) was released on December 10, 2021 outlining a vulnerability in Apache Foundation project Log4j (https://logging.apache.org/log4j/2.x/index.html). This vulnerability can be used by a remote attacker to execute code without authentication. This vulnerability is also known as Log4Shell.
WitFoo Precinct 6.x utilizes log4j in the WitFoo Streamer & Apache Kafka Docker containers that manage the message processing pipeline. Other custom WitFoo containers (including Cassandra 4.01) do not utilize log4j.
As of 0940 Eastern Standard time on Saturday, December 11, 2021, WitFoo has completed the following mitigation steps: