How Can We Build the Next Generation of Security?

8.4K views
•
April 23, 2015
by
RSAC Cybersecurity
YouTube video player
How Can We Build the Next Generation of Security?

TL;DR

Building a safer digital future requires security to be designed into software and connected devices, not added after deployment. As malware, shared-code vulnerabilities, diverse threat actors, and Internet-connected products expand the attack surface, the security community must move beyond describing failures and invest in education, awareness, and the next generation of practitioners.

Transcript

Thank you. That was a really incredible inspirational, uh, talk by Diana, and it sort of ties very well in with the messages that we're gonna talk about today. And that song you just heard, that very iconic song from The Who, uh, Talking About My Generation, uh, means a lot to me given the time I grew up, and it means a lot to this talk because if ... Read More

Key Insights

  • Cybersecurity remains an adolescent industry because practitioners and the wider world often misunderstand one another, while public discussions frequently emphasize failure. Progress requires shifting attention from repeatedly framing problems toward developing practical solutions for a safer and more secure future.
  • Self-reproducing code has theoretical roots in John von Neumann's 1949 paper, The Theory of Self-Reproducing Automata. The paper explored how code and machinery could replicate and create themselves on top of an existing base, providing an early foundation for computer virology.
  • Early self-replicating programs were not always designed to cause harm. Examples including Creeper and Animal demonstrated replication, displayed messages, or consumed processing resources, while later developments increasingly crossed into malicious behavior and produced consequences their creators did not necessarily anticipate.
  • Malware evolved alongside computing platforms and programming environments. The progression included Apple II and IBM PC viruses, the Morris worm, language-specific and macro viruses, widespread worms, targeted malicious software, and ransomware, reflecting accelerating malicious intent and increasingly varied objectives.
  • Internet-scale monoculture vulnerabilities arise when widely reused code bases contain weaknesses affecting large portions of the Internet. Heartbleed, POODLE, and Shellshock illustrate how shared technological foundations can expose tens of thousands, hundreds of thousands, or potentially millions of endpoints at once.
  • Modern cyber risk combines increasing threat velocity and volume with an expanding technology landscape and evolving threat actors. A study cited for 2014 reported twelve million new malware variants per month, alongside growing attention to dark-web markets, Bitcoin, and nation-state attacks on critical infrastructure.
  • Connected devices create security and privacy consequences far beyond traditional computers. Phones can report locations, speakers and televisions can listen, refrigerators can send spam, light bulbs can expose Wi-Fi passwords, baby monitors can enable spying, and infected cameras can become Bitcoin miners.
  • Security must be built into software and connected products rather than treated as a feature added afterward. The software supply chain becomes especially important when convenience encourages rapid adoption of applications, sensors, health devices, and other products without sufficient attention to their security properties.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can organizations build the next generation of cybersecurity?

Organizations can build the next generation of cybersecurity by focusing on solutions, designing security into software and devices, and paying serious attention to the security supply chain. Protection should be considered during creation rather than attached after deployment. Investment in education and awareness, including programs for children and parents, can also develop people capable of understanding and addressing complex security challenges.

Q: Why should security be built into products instead of added later?

Security should be built into products because connected devices can expose sensitive information or produce unexpected harmful behavior after deployment. The transcript describes televisions, refrigerators, light bulbs, baby monitors, cameras, and personal health sensors as potential sources of risk. Treating security as part of software design and the supply chain provides a stronger foundation than relying on protection added afterward.

Q: How did self-reproducing code lead to modern malware?

The development began with John von Neumann's 1949 theory of self-reproducing automata, which described how code and machinery could replicate on an existing base. Later programs such as Creeper and Animal applied the replication concept without necessarily intending serious harm. Subsequent viruses, worms, macro viruses, targeted code, and ransomware increasingly incorporated malicious objectives and expanded their effects across connected systems.

Q: What are Internet-scale monoculture vulnerabilities?

Internet-scale monoculture vulnerabilities are weaknesses in code bases reused across very large numbers of systems. When many endpoints depend on the same underlying software, one flaw can affect tens of thousands, hundreds of thousands, or potentially millions of endpoints. Heartbleed, POODLE, and Shellshock are presented as examples of vulnerabilities whose reach reflected the widespread reuse of common technological components.

Q: Why has modern cybersecurity become more difficult?

Modern cybersecurity has become more difficult because threat velocity and volume are increasing while the technology landscape and population of threat actors continue to expand. The transcript cites twelve million new malware variants per month during 2014. It also identifies dark-web markets, Bitcoin, nation-state targeting of critical infrastructure, abundant malicious code, and widely shared software vulnerabilities as compounding factors.

Q: What security risks come from Internet-connected devices?

Internet-connected devices can collect private information, reveal credentials, or be repurposed for unintended activity. Examples in the transcript include phones reporting locations, speakers and televisions listening, refrigerators sending spam, light bulbs exposing Wi-Fi passwords, baby monitors spying on children, and closed-circuit televisions becoming Bitcoin miners. Embedded medical and health sensors could create even more consequential risks if accessed improperly.

Q: How does convenience affect security and privacy decisions?

Convenience can override good judgment when people rapidly adopt applications and connected products without examining their security or privacy properties. Phones can run hundreds of applications that provide capabilities previously unavailable, but the software inside those devices creates supply-chain concerns. The transcript argues that people sometimes exchange security and privacy for convenience, making deliberate secure design increasingly necessary.

Q: Why is cybersecurity education important for children?

Cybersecurity education is important for children because even a nine-year-old can understand complex security challenges and recognize techniques such as tricking someone into clicking a link. Reuben Paul is presented as the leader and organizer of a cybersecurity awareness organization for children and their parents. His example supports investing in younger generations as active participants in building a safer digital future.

Summary & Key Takeaways

  • Cybersecurity developed from early theories of self-reproducing automata into an industry confronting deliberately malicious code. Experiments such as Creeper were followed by boot-sector viruses, worms, macro viruses, ransomware, and increasingly sophisticated attacks. This progression changed both the scale of threats and the ways defenders must approach security.

  • Present risks combine abundant malicious code with vulnerabilities in widely reused software. Heartbleed, POODLE, and Shellshock illustrate how shared code can expose enormous numbers of systems. Expanding connectivity, growing malware volume, dark-web markets, alternative currencies, and nation-state targeting further increase the difficulty of protecting modern infrastructure and information.

  • Future security depends on designing protection into software, devices, and their supply chains from the beginning. Connected televisions, refrigerators, light bulbs, cameras, baby monitors, and medical sensors create risks that convenience can obscure. Cybersecurity education for children and parents demonstrates that younger generations can understand complex challenges and help build safer systems.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚