《从设计阶段保障安全并提升现有生态系统.pdf》由会员分享,可在线阅读,更多相关《从设计阶段保障安全并提升现有生态系统.pdf(12页珍藏版)》请在三个皮匠报告上搜索。
1、Matthew RogersMay 29,2025C I S A|C Y B E R S E C U R I T Y A N D I N F R A S T R U C T U R E S E C U R I T Y A G E N C YSECURE BY DESIGN AND TRANSITIONING OFF LEGACY SYSTEMS1Matthew RogersMay 29,2025C Y B E R S E C U R I T Y A N D I N F R A S T R U C T U R E S E C U R I T Y A G E N C YMatthew Rogers
2、May 29,20255Legacy&Operational ChallengesPriorities based on threats,security gaps,resilienceSecure by Design for OTMatthew RogersMay 29,20256Protection of DataSecure by DefaultConfigurationManagementLogging in theBaseline ProductThreatModelingStrongAuthenticationVulnerabilityHandlingUpgrade&PatchTo
3、olingOpen StandardsOwnershipSecure CommunicationsSecure ControlsMatthew RogersMay 29,2025Leaping to a Secure Foundation7Secure CommunicationsSecure Controls Linking Cyber-Informed Engineering and Secure by Design How do you make Secure Comms usable for non-cyber experts?StrongAuthenticationMatthew R
4、ogersMay 29,20251983Interconnectivity and Shaky Foundations82013Matthew RogersMay 29,2025Secure Controls Example:Securing Aircraft9MIL-STD-1553:No Authentication Mode-Codes that disable avionics computersGeneric Approach:Monitor for anomalous timings Monitor for normal data in the wrong context Moni
5、tor for anomalous dataSecurity Assumptions in ICSCant modify a PLCCant add operator frictionCant rearchitect anythingMatthew RogersMay 29,2025Secure Control Example:Secure by Design10The same security model:-Adding an IF statement to the Bus ControllerOptions:Spend a few million+labor on something t
6、hat will produce false positives and require skilled analysts to parse or Design around a malicious actorMatthew RogersMay 29,2025Apply Human Centered Design to Comms11Alerting on bad configsWell Lit Paths Usable Security Designed for the e