Christian Johnson on Interdisciplinary Cybersecurity

100 views
February 22, 2017
by
RSAC Cybersecurity
YouTube video player
Christian Johnson on Interdisciplinary Cybersecurity

TL;DR

Cybersecurity problems require more than technical expertise, so effective education should include perspectives from computing, engineering, social sciences, economics, and other disciplines. Christian Johnson also argues that machine learning, serverless architectures, and software-defined infrastructure could help enterprise networks respond to rapidly changing malware by transforming their topology, mitigating attacks, or isolating harmful activity.

Transcript

Hey, welcome back to RSAC TV, RSA Conference Television here at the Moscone Center West, downtown San Francisco. I'm your host Paul Roberts, and I'm the editor in chief at the Security Ledger. I'm here all week talking with some of the luminaries from the RSA Conference and some of the folks who are coming here to present, to take part. We're doing... Read More

Key Insights

  • Cybersecurity is an interdisciplinary problem because technical knowledge alone does not address all of its modern challenges. The ACES program therefore includes students from computing, engineering, mathematics, anthropology, criminal science, political science, economics, and other academic areas.
  • The ACES program is a four-year undergraduate honors college in cybersecurity at the University of Maryland. It typically includes about 70 students in each cohort and sponsored one student, Christian Johnson, to attend the 2017 RSA Conference as a Security Scholar.
  • The Security Scholars experience is valuable for building connections among students from different universities. Johnson found that meeting peers with varied research projects and academic approaches helped him look beyond the potentially narrow perspective of his own institution and program.
  • Graduate researchers can provide inspiration and practical insight to undergraduates. Johnson valued speaking with master’s and doctoral students about their advanced projects, including students preparing to defend dissertations, because their depth of knowledge demonstrated possible directions for his own scholarly development.
  • RSA Conference combines enterprise participation, vendor exhibits, learning tracks, technical talks, and hands-on labs. Johnson used this variety to alternate between attending presentations, writing scripts or actively programming on his laptop, and exploring the perspectives presented across the expo floor.
  • Johnson’s research focuses on the intersection of machine learning and cybersecurity. His path began with data science, continued into information security, and led him to investigate how combining those areas could support automated technologies capable of responding to rapidly changing cybercrime.
  • Malware changes faster than many network infrastructures and topologies can adapt. Johnson says new malware and attack variations appear so quickly that defensive systems need automation capable of keeping pace instead of relying on comparatively static network designs.
  • Software-defined and serverless architectures could enable networks to respond directly to machine learning signals. Johnson envisions enterprise topologies transforming within moments to mitigate an attack or place harmful activity into a sandbox, making classification useful as an immediate defensive action.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why does cybersecurity require an interdisciplinary approach?

Cybersecurity requires an interdisciplinary approach because its problems are not exclusively technical. Johnson points to the ACES program’s inclusion of students from computer science, computer engineering, mathematics, engineering, anthropology, criminal science, political science, and economics. These perspectives can help address the human, organizational, political, and economic elements surrounding technical security challenges that computing expertise alone may not resolve.

Q: What is the University of Maryland ACES program?

ACES stands for Advanced Cybersecurity Experience for Students. Johnson describes it as the first four-year undergraduate honors college in cybersecurity in the United States. Located at the University of Maryland, it typically has about 70 students per cohort and deliberately accepts students from a broad range of majors. The program sponsored one student to attend RSA Conference, selecting Johnson through that process.

Q: How did the Security Scholars program benefit Christian Johnson?

The Security Scholars program gave Johnson an immersive opportunity to meet students from universities across the country and quickly build a network and community. It also provided access to cryptology founders and influential industry stakeholders. Discussing research with other scholars helped him understand how universities approach cybersecurity differently and exposed him to advanced work by master’s and doctoral students.

Q: What did Christian Johnson find valuable about RSA Conference?

Johnson valued the conference’s combination of enterprise participation, vendor exhibits, educational tracks, technical talks, and practical labs. As someone who prefers hands-on learning, he attended labs where he could write scripts and actively program. He could move from a presentation to coding and then to the expo, creating a varied learning experience suited to his interests.

Q: What cybersecurity topics does Christian Johnson research?

Johnson researches the intersection of machine learning and cybersecurity through the software engineering institute at Maryland and the university’s Department of Computer Science. After moving from data science into information security, he became interested in their combined potential. His central question is how automated technologies can keep pace with cybercrime and convert analytical signals into rapid defensive changes across enterprise networks.

Q: Why does cybersecurity defense need greater automation?

Cybersecurity defense needs greater automation because malware samples and attack variations emerge faster than many network infrastructures can change. Johnson observes that new malware appears every minute across the internet, while network topologies often remain comparatively static. Automated systems could narrow that gap by interpreting threats and rapidly changing the network to mitigate an attack or contain its effects.

Q: How could machine learning help defend enterprise networks?

Machine learning could classify suspicious activity and produce a signal that triggers an immediate defensive response. Johnson considers classification useful, but he is more interested in what happens next. He wants that signal to enable an enterprise network topology to transform within moments, either mitigating the attack directly or sandboxing the activity so its effects remain contained.

Q: What role could software-defined and serverless systems play in cybersecurity?

Software-defined and serverless systems could make network defenses more adaptable by reducing dependence on fixed physical hardware and centralized controller models. Johnson expects virtual and decentralized appliances to become increasingly important. In his research vision, these architectures would let an enterprise rapidly reconfigure its topology after receiving a machine learning signal, helping mitigate or isolate an attack.

Summary & Key Takeaways

  • Christian Johnson attended the 2017 RSA Conference as a Security Scholar representing the University of Maryland’s Advanced Cybersecurity Experience for Students program. He valued meeting students from across the country, building a professional community, and gaining access to cryptology founders and other influential participants whom he would not ordinarily encounter alone.

  • The ACES program brings together students from computer science, engineering, mathematics, anthropology, criminal science, political science, economics, and other fields. Johnson says this breadth reflects the nature of modern cybersecurity, whose problems include technical and nontechnical dimensions. His cybersecurity minor therefore complements his computer science studies in unexpectedly interdisciplinary ways.

  • Johnson researches the intersection of machine learning and cybersecurity through the University of Maryland’s software engineering institute and computer science department. He wants automated defenses to match the rapid evolution of malware, using serverless and software-defined architectures so networks can quickly transform, mitigate attacks, or place harmful activity into isolated environments.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚