How Can Cybersecurity Keep Pace With Change?

4.0K views
•
November 16, 2017
by
RSAC Cybersecurity
YouTube video player
How Can Cybersecurity Keep Pace With Change?

TL;DR

Cybersecurity must move beyond linear, reactive point solutions because hacking, malware, and social engineering are increasing exponentially. Blockchain, post-quantum cryptography, and artificial intelligence offer more abundant approaches by enabling non-repudiable transactions, preparing encryption for quantum threats, and using growing stores of data and computing power to learn from network activity.

Transcript

Salaam Alaikum. Good morning, everyone. Uh, thank you, Your Excellencies, for being here this morning. Thank you all of you for being here. Today, I'm gonna talk to you about how we're living in exponential times. Uh, this is not going to be a, a typical vendor presentation. I'm gonna give you some retrospective on what's going on in cybersecurity ... Read More

Key Insights

  • Exponential change is growth that advances by doubling or faster than doubling, rather than moving one step at a time. The presentation identifies this pattern across transistor counts, storage availability relative to price, network backbones, genome sequencing, computing power, and several successive waves of technology.
  • Personal computing may appear to have reached the flatter portion of its adoption curve, but computing power has not stopped growing exponentially. Greater capacity can support more advanced cybersecurity methods, particularly systems that must process large datasets and learn from previous observations and mistakes.
  • Mobility extends beyond widespread smartphone adoption into machine-to-machine communication and the Internet of Things. A cited conservative estimate projected 31 billion devices by 2020, creating a much larger environment in which vulnerabilities, attacks, and defensive requirements could emerge.
  • Cybersecurity attacks are increasing exponentially through hacking, malware, and social engineering, while many defensive approaches remain linear. Point solutions typically respond to observed attacker behavior after the fact, leaving the profession struggling to match the speed and scale of adversarial activity.
  • Internet of Things security research demonstrates that collections of connected devices can be hacked, but findings do not always become public immediately. Some vulnerabilities are disclosed at conferences such as DEF CON, while other problems may remain unseen for weeks, months, or years.
  • Blockchain is presented as a potential foundation for trustless and non-repudiable transactions. By combining qualities associated with public key infrastructure and peer-to-peer networking, it could support financial, military, real estate, wedding, e-government, smart-city, and other transaction records.
  • Quantum computing could undermine current blockchain designs by breaking public key encryption. Peter Shor's algorithm is described as a method for finding prime factors associated with a large integer, raising the possibility that information encrypted during the previous 30 years could become visible.
  • Artificial intelligence benefits from exponentially increasing computing power and decreasing storage costs. These conditions allow organizations to retain large amounts of data that an AI can analyze, use to identify mistakes, and learn from so that its subsequent decisions or responses improve.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why must cybersecurity move beyond linear defenses?

Cybersecurity must move beyond linear defenses because hacking, malware, social engineering, and other adversarial activities are increasing exponentially. Much of the security industry still responds with isolated point solutions after observing what attackers have done. That step-by-step model cannot effectively match threats that grow by doubling or faster, especially as computing, mobility, and connected-device environments continue expanding.

Q: What does exponential change mean for cybersecurity?

Exponential change means that technological capabilities and security problems advance by doubling or faster than doubling instead of progressing one step at a time. Computing power, storage, networks, mobility, and connected devices illustrate this pattern. For cybersecurity, the consequence is a growing mismatch between rapidly expanding attack opportunities and defensive practices that often remain reactive, fragmented, and linear.

Q: How does the Internet of Things increase cyber risk?

The Internet of Things increases cyber risk by extending connectivity beyond smartphones into machine-to-machine communications and large collections of devices. The presentation cites a conservative estimate of 31 billion devices by 2020. Security researchers have demonstrated ways to hack connected products, while some discoveries are published at conferences and others remain unknown publicly for weeks, months, or years.

Q: How could blockchain improve cybersecurity?

Blockchain could improve cybersecurity by supporting a trustless, non-repudiable environment in which many kinds of transactions can be recorded and trusted over time. The presentation connects this capability with the value of public key infrastructure and peer-to-peer networking. Potential applications include financial activity, military transactions, real estate, weddings, e-government, smart cities, and other security-sensitive processes.

Q: What cybersecurity risks does blockchain create?

Blockchain introduces risks when implementations contain mistakes, are insufficiently tested, or depend on cryptography that later becomes vulnerable. The presentation also notes that excessive control of blockchain computing power can create risk. Quantum computing presents a further concern because it could potentially break the public key encryption used by current blockchain approaches, weakening the security of recorded transactions.

Q: Why is quantum computing a threat to encryption?

Quantum computing is a threat to current encryption because it could be used with approaches such as Peter Shor's algorithm to find the prime factors associated with a large integer. The presentation warns that this capability could break public key encryption and potentially expose information encrypted over the previous 30 years, including data protected through existing blockchain designs.

Q: How should cybersecurity prepare for quantum computing?

Cybersecurity should prepare for quantum computing by treating it as an opportunity to create stronger defenses, not solely as a scarcity-driven threat. The recommended direction is to develop post-quantum cryptography that addresses the possibility of current public key encryption being broken. Security professionals should also consider how quantum capabilities might help solve other problems while validating new technologies carefully.

Q: Why is artificial intelligence becoming useful for cybersecurity?

Artificial intelligence is becoming useful because computing power is increasing exponentially while storage costs are decreasing exponentially. Organizations can therefore collect large quantities of data and avoid deleting it. That data becomes the material an AI uses to recognize patterns, analyze mistakes, learn from observed events, and improve its next response, including responses to cybersecurity problems on a network.

Summary & Key Takeaways

  • Technological capacity is growing exponentially across computing power, storage, networks, genome sequencing, mobility, and connected devices. Yet cybersecurity still relies heavily on linear responses and isolated point solutions. This mismatch leaves defenders reacting to rapidly expanding malware, hacking, social engineering, mobile threats, and emerging Internet of Things vulnerabilities.

  • Blockchain could support cybersecurity by combining properties associated with public key infrastructure, peer-to-peer computing, and a trustless, non-repudiable record of transactions. Its potential extends beyond cryptocurrency to e-government, smart cities, military activity, real estate, and other transactions, although implementations must be tested and validated carefully.

  • Quantum computing could threaten existing public key encryption and blockchain approaches, potentially exposing encrypted information. The productive response is to develop post-quantum cryptography instead of treating quantum computing only as a threat. Artificial intelligence provides another opportunity because expanding computing power and falling storage costs support continuous learning from large security datasets.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚