
who here likes free Wi-Fi hands up now
that’s reasonable we all like something
free interestingly though I don’t think
that I love a free Wi-Fi is necessarily
translated through to this morning and
this afternoon earlier before we came in
here my colleagues and I and I came in
we set up a Wi-Fi access point we built
a landing page to look like TEDx
and we asked you to enter in email
addresses and enter in a password we’ve
done this with malicious intent if
anyone recognizes their email address up
there yeah for the next 15 minutes or so
you’re my victim now if you look at a
couple of the email addresses at the
bottom I think people perhaps on to our
little trick and in the circumstance of
what we’ve done this morning
perhaps that’s actually a good thing my
name is Sven Ross and I’m here to talk
to you today about the modern cyber
threat the modern cyber problem I think
it’s worth exploring this because as we
enter into as we are now in the digital
age and as we step forward into a future
and with the future blueprint we use
technology almost pervasively throughout
our lives and I think we need to
understand the risk that it poses and
for every advantage that we take of
Technology perhaps there’s something or
someone out there using it to their
advantage as well but what is a cyber
threat what is hacking now I won’t ask
for any contribution from the audience
so I just like to give I guess my own
interpretation of what this is I broadly
set hacking is the manipulation of
technology or process or both in order
to deliver effect that was that wasn’t
intended by the originator of that
technology or process and with malicious
intent it can come in many forms it can
come in a simplistic form such as a
social engineering attack that we
engineered this morning against you guys
it can be brutal and chunky such as a
brute-force attempt against your
password trying to crack your password
or it can be a touch more elegant and
sophisticated such as placing a little
bit of malicious software on your laptop
so that when you enter your banking
credentials it captures it as you’re
entering the keystrokes and sends it off
to a sense
service or someone can log into your
bank account and steal your money now I
think we’re a little misled by the media
when it comes to somewhat the cyber
threat is and this is the crux of my
talk this morning and I think we’re
mislead because we see photos like this
we see images where the focus is 100% on
the code on the technology on the ones
of zeroes and sometimes we see things
like this where it’s definitely the code
that’s coming to attack us but it’s not
and that’s what I’d like to cover this
morning this afternoon but first I
haven’t always want to suit a little bit
about me how many ways one suit so I
haven’t always worn pink shirts I
haven’t always been a normal person for
the greater part of my adult life I
spent in the military specifically the
army and serving in Special Forces
regiments now when I tell people this
they’d have images again perhaps a
little misleading they’d see things like
this in their head sexy Brad Pitt
jumping out of helicopters um I didn’t
do that I did things more like this and
now I’m not talking about the very
good-looking man holding the radio
handset I’m talking about the short
dumpy man who you can’t see carrying the
radio when he’s back I did a little bit
of that I did a lot of looking at
computer networks staring at satellite
networks and otherwise looking at the
ones and zeros run around and run run
around running around the ether lots of
lots of diagrams like that very boring
stuff I spent pretty much all my adult
life using technology to make sure that
people could communicate but I guess
being in the army I also spent a lot of
my adult life making sure or using
technology to make sure that other
people couldn’t communicate and so
whilst it’s not the sexy Hollywood image
of what Special Operations does I think
it’s what lends me the credibility to
stand up in front of this afternoon and
talk about what constitutes the modern
cyber threat but before we do I just
want to tell a little story a little
history lesson
it’s 1960 a gentleman named Colonel John
Boyd a veteran US Air Force fighter
pilot who served in the Korean War
was working on a program in the Pentagon
to develop a new fighter jet and he
developed a theory of aircraft
maneuverability called the energy
manoeuvrability theory now I’m about as
far from an aeronautical engineer as you
can get so I’m going to be very high
level on this and Colonel John Boyd
forgive me
the theory postulated that the thrust to
weight ratio and the wing orientation of
a fighter jet was what lent it it’s is
what gave it an advantage in air combat
maneuvers not necessarily its speed or
its ability to dive I’ll leave that
there anyway as he developed this theory
and thrown a lot of numbers through a
lot of very big computers sitting under
the Pentagon he was saying yes this is
exactly what’s diskant this is this is
what describes the air superiority this
is what describes a better fighter jet
as he applied this theory to his combat
experience from the Korean War
he flew f-86 sabres he couldn’t really
understand the dot what the data of his
theory and then what the results and
kill ratio between the American aircraft
and the North Korean Soviet and Chinese
aircraft was telling him the American
aircraft significantly outperformed or
the Americans significantly outperformed
their communist counterparts the f-86
and previous iterations of American
aircraft shot down a lot more Mickey
fifteens
now according to Boyd’s e/m theory this
shouldn’t make sense the MIG was in fact
faster it was seeking weakening more
maneuverable its wing orientation was
superior to previous iterations the
Sabre had by this stage of the war
caught up with the mixed design but the
numbers were skewed he didn’t understand
why was this and it wasn’t until he was
looking at a picture but possibly not
dissimilar to what I’ve got behind me
and what you’re looking at and he
noticed something really imperceptible a
detail that would otherwise be missed
and if you can see it it’s at the rear
of the canopy of the meet 15 is slightly
more armoured and then the perspex of
the canopy itself was ever so slightly
thicker the designers of the MEK had
opted for higher protection and a high
degree of safety for the pilot this was
easier Rico moment John Boyd knew as a
fighter pilot fighter pilot himself the
prices he went through during air combat
maneuvers
and the advantage that 300 180 270
degrees of visibility provided him and
that imperceptibly small piece of armor
to his rear during a combat maneuvers as
you’re flipping planes over and looking
all around you was significant and at
that point he realized there’s two
factors yes it’s the aircraft but it’s
also the speed at which you make
decisions particularly in an adversarial
contest and particularly in a contest
done at significant speed that affords
you victory he developed a second theory
clever fella he developed a theory
called the OODA loop and that is
observation orientation decision and
action
and he postulated that all intelligent
beings go through this loop as we make
decisions as we react to the world
around us and as we choose to engage
with the problem in front of us he said
it’s true of individuals and he says
it’s true of organizations as well but
what does that have to do in a modern
cyber problem what does human decision
cycles have to do with being hacked
remember at the start I said that it’s
not the technique the focus is on
technology and I believe this to be a
little misleading it’s misleading
because cyber threats are human
it’s not the ones and zeros that attack
you it’s not a piece of malware that
sits on your laptop and it’s not the
phishing email somewhere someone has
made a decision to use technology to
attack you to take something from you to
take malicious action using technology
using process and act against you that
could be a confronting thought certainly
is for me and I’ve spent a long time in
the army a long time in the military
knowing that I have an enemy somewhere
so for those of us in everyday life the
thought that somewhere someone is trying
to act against us I agree it can be
confronting but as we step into not to
step into as we now live in a digital
age and everything we do is increasingly
leveraged and reliant upon technology I
think it’s interesting to note and
important to note that for every
advantage technology brings us there’s a
darker side to it and that someone can
use this technology
to act against us so because the cyber
threat is human it’s complex and it’s
adaptive it’s complex because it
leverages technology and it’s adaptive
because it’s human it has its own
decision cycle so at the start of every
cyberattack there has been a human who
has gone through their own odor loop and
their action is to attack you now being
coming from the military we’ve had a bit
of experience now I’ve had experience in
engaging with a complex and adaptive
enemy spent a little bit of my life in
Afghanistan probably too long and the
enemy we fought over there was complex
and adaptive and we learned some very
tough lessons but we learned some quick
lessons about how to deal with this and
it was about defeating their Ruta loop
getting inside the enemy’s OODA loop
because at the moment I think in the
world today we are all very much in
sorry the the adversary the cyber threat
is inside our odor loop they’re able to
observe orient decide and act against us
with a lot more speed than we are and
certainly Afghanistan it led us to
changing our methodology of operations
we moved to intelligence-led operations
rather than coming up with a plan
allocating resources and monolithically
following that plan and this was a not
quite a revolution but certainly an
evolution in in the way we conducted our
business and really all that meant was
we need to speed up our decision-making
we need our decision cycle to be faster
than the enemy’s we need to be able to
disrupt his decision cycle I think we’ve
all been in situations where bid Nova
serial contact context or otherwise
where we feel reactive we feel like
we’re on the back foot we feel like
decisions are being made around us and
we can only react to it our opponents
OODA loop is faster than ours and I
think we’ve been in situations where we
feel around the front foot we’re making
decisions faster than the adversary and
this in this is the crux of Boyd’s
theory is those able to observe orient
decide and act faster than the other or
win the engagement I know you’re
thinking spin what does this have to do
with with me
what does I have to do with my place in
the world and how I engage with
technology
well I’d like to offer I guess a little
vignette a little analogy of how I think
we can all disrupt the adversaries Oh de
loop I’d like to think about passwords
now hopefully those people had actually
logged into our little are a little
trick this morning didn’t actually enter
your real password that you’ve used
elsewhere but I’ll tell you what some
people probably did you know what you
see on they up the board behind me is
examples of bad passwords now we know a
lot about passwords these days because
every major breach that occurs every
huge dump of credentials on the Internet
is available for researchers such as us
and also bad card researchers we now
know a lot about how humans construct
passwords when you use bad passwords
like this you leave yourself vulnerable
why is that you say spen but there’s
clever people who write clever
technology and clever mathematicians who
encrypt my password and that’s true
typically as you enter a password into
any legitimate site it goes through
what’s called a hash algorithm and that
means the string of text or numbers that
you’ve put in results in an enormous
string that’s completely reversible so
you can’t actually reverse engineer that
hash back into the password you entered
but because we know so much about the
way humans construct passwords because
we have because we and the adversary has
advantage to high compute we can
somewhat cheat that process we can use
our knowledge of the way humans
construct passwords to defeat that hash
and essentially recreate it and
therefore learn the passwords because
they’re so simple so when you all use
passwords in the internet if you use
passwords of their short if you use
passwords that are not random and if you
use passwords that are not complex
you’re giving the adversary the
advantage you’re speeding up his
decision cycle by being lazy his ability
to observe simple password use or in
himself to your situation in your
context make a decision to act against
that password and then actually enact
that cracking or enact that guessing
process it is made very simply
this is what I’d like to leave you with
today that the pervasiveness of
technology today tomorrow and the day
after that means that we all have a role
to play in disrupting the modern cyber
threat the modern cyber problem and it
could be as simple as using long complex
and random passwords thank you very much
[Applause]
that’s reasonable we all like something
free interestingly though I don’t think
that I love a free Wi-Fi is necessarily
translated through to this morning and
this afternoon earlier before we came in
here my colleagues and I and I came in
we set up a Wi-Fi access point we built
a landing page to look like TEDx
and we asked you to enter in email
addresses and enter in a password we’ve
done this with malicious intent if
anyone recognizes their email address up
there yeah for the next 15 minutes or so
you’re my victim now if you look at a
couple of the email addresses at the
bottom I think people perhaps on to our
little trick and in the circumstance of
what we’ve done this morning
perhaps that’s actually a good thing my
name is Sven Ross and I’m here to talk
to you today about the modern cyber
threat the modern cyber problem I think
it’s worth exploring this because as we
enter into as we are now in the digital
age and as we step forward into a future
and with the future blueprint we use
technology almost pervasively throughout
our lives and I think we need to
understand the risk that it poses and
for every advantage that we take of
Technology perhaps there’s something or
someone out there using it to their
advantage as well but what is a cyber
threat what is hacking now I won’t ask
for any contribution from the audience
so I just like to give I guess my own
interpretation of what this is I broadly
set hacking is the manipulation of
technology or process or both in order
to deliver effect that was that wasn’t
intended by the originator of that
technology or process and with malicious
intent it can come in many forms it can
come in a simplistic form such as a
social engineering attack that we
engineered this morning against you guys
it can be brutal and chunky such as a
brute-force attempt against your
password trying to crack your password
or it can be a touch more elegant and
sophisticated such as placing a little
bit of malicious software on your laptop
so that when you enter your banking
credentials it captures it as you’re
entering the keystrokes and sends it off
to a sense
service or someone can log into your
bank account and steal your money now I
think we’re a little misled by the media
when it comes to somewhat the cyber
threat is and this is the crux of my
talk this morning and I think we’re
mislead because we see photos like this
we see images where the focus is 100% on
the code on the technology on the ones
of zeroes and sometimes we see things
like this where it’s definitely the code
that’s coming to attack us but it’s not
and that’s what I’d like to cover this
morning this afternoon but first I
haven’t always want to suit a little bit
about me how many ways one suit so I
haven’t always worn pink shirts I
haven’t always been a normal person for
the greater part of my adult life I
spent in the military specifically the
army and serving in Special Forces
regiments now when I tell people this
they’d have images again perhaps a
little misleading they’d see things like
this in their head sexy Brad Pitt
jumping out of helicopters um I didn’t
do that I did things more like this and
now I’m not talking about the very
good-looking man holding the radio
handset I’m talking about the short
dumpy man who you can’t see carrying the
radio when he’s back I did a little bit
of that I did a lot of looking at
computer networks staring at satellite
networks and otherwise looking at the
ones and zeros run around and run run
around running around the ether lots of
lots of diagrams like that very boring
stuff I spent pretty much all my adult
life using technology to make sure that
people could communicate but I guess
being in the army I also spent a lot of
my adult life making sure or using
technology to make sure that other
people couldn’t communicate and so
whilst it’s not the sexy Hollywood image
of what Special Operations does I think
it’s what lends me the credibility to
stand up in front of this afternoon and
talk about what constitutes the modern
cyber threat but before we do I just
want to tell a little story a little
history lesson
it’s 1960 a gentleman named Colonel John
Boyd a veteran US Air Force fighter
pilot who served in the Korean War
was working on a program in the Pentagon
to develop a new fighter jet and he
developed a theory of aircraft
maneuverability called the energy
manoeuvrability theory now I’m about as
far from an aeronautical engineer as you
can get so I’m going to be very high
level on this and Colonel John Boyd
forgive me
the theory postulated that the thrust to
weight ratio and the wing orientation of
a fighter jet was what lent it it’s is
what gave it an advantage in air combat
maneuvers not necessarily its speed or
its ability to dive I’ll leave that
there anyway as he developed this theory
and thrown a lot of numbers through a
lot of very big computers sitting under
the Pentagon he was saying yes this is
exactly what’s diskant this is this is
what describes the air superiority this
is what describes a better fighter jet
as he applied this theory to his combat
experience from the Korean War
he flew f-86 sabres he couldn’t really
understand the dot what the data of his
theory and then what the results and
kill ratio between the American aircraft
and the North Korean Soviet and Chinese
aircraft was telling him the American
aircraft significantly outperformed or
the Americans significantly outperformed
their communist counterparts the f-86
and previous iterations of American
aircraft shot down a lot more Mickey
fifteens
now according to Boyd’s e/m theory this
shouldn’t make sense the MIG was in fact
faster it was seeking weakening more
maneuverable its wing orientation was
superior to previous iterations the
Sabre had by this stage of the war
caught up with the mixed design but the
numbers were skewed he didn’t understand
why was this and it wasn’t until he was
looking at a picture but possibly not
dissimilar to what I’ve got behind me
and what you’re looking at and he
noticed something really imperceptible a
detail that would otherwise be missed
and if you can see it it’s at the rear
of the canopy of the meet 15 is slightly
more armoured and then the perspex of
the canopy itself was ever so slightly
thicker the designers of the MEK had
opted for higher protection and a high
degree of safety for the pilot this was
easier Rico moment John Boyd knew as a
fighter pilot fighter pilot himself the
prices he went through during air combat
maneuvers
and the advantage that 300 180 270
degrees of visibility provided him and
that imperceptibly small piece of armor
to his rear during a combat maneuvers as
you’re flipping planes over and looking
all around you was significant and at
that point he realized there’s two
factors yes it’s the aircraft but it’s
also the speed at which you make
decisions particularly in an adversarial
contest and particularly in a contest
done at significant speed that affords
you victory he developed a second theory
clever fella he developed a theory
called the OODA loop and that is
observation orientation decision and
action
and he postulated that all intelligent
beings go through this loop as we make
decisions as we react to the world
around us and as we choose to engage
with the problem in front of us he said
it’s true of individuals and he says
it’s true of organizations as well but
what does that have to do in a modern
cyber problem what does human decision
cycles have to do with being hacked
remember at the start I said that it’s
not the technique the focus is on
technology and I believe this to be a
little misleading it’s misleading
because cyber threats are human
it’s not the ones and zeros that attack
you it’s not a piece of malware that
sits on your laptop and it’s not the
phishing email somewhere someone has
made a decision to use technology to
attack you to take something from you to
take malicious action using technology
using process and act against you that
could be a confronting thought certainly
is for me and I’ve spent a long time in
the army a long time in the military
knowing that I have an enemy somewhere
so for those of us in everyday life the
thought that somewhere someone is trying
to act against us I agree it can be
confronting but as we step into not to
step into as we now live in a digital
age and everything we do is increasingly
leveraged and reliant upon technology I
think it’s interesting to note and
important to note that for every
advantage technology brings us there’s a
darker side to it and that someone can
use this technology
to act against us so because the cyber
threat is human it’s complex and it’s
adaptive it’s complex because it
leverages technology and it’s adaptive
because it’s human it has its own
decision cycle so at the start of every
cyberattack there has been a human who
has gone through their own odor loop and
their action is to attack you now being
coming from the military we’ve had a bit
of experience now I’ve had experience in
engaging with a complex and adaptive
enemy spent a little bit of my life in
Afghanistan probably too long and the
enemy we fought over there was complex
and adaptive and we learned some very
tough lessons but we learned some quick
lessons about how to deal with this and
it was about defeating their Ruta loop
getting inside the enemy’s OODA loop
because at the moment I think in the
world today we are all very much in
sorry the the adversary the cyber threat
is inside our odor loop they’re able to
observe orient decide and act against us
with a lot more speed than we are and
certainly Afghanistan it led us to
changing our methodology of operations
we moved to intelligence-led operations
rather than coming up with a plan
allocating resources and monolithically
following that plan and this was a not
quite a revolution but certainly an
evolution in in the way we conducted our
business and really all that meant was
we need to speed up our decision-making
we need our decision cycle to be faster
than the enemy’s we need to be able to
disrupt his decision cycle I think we’ve
all been in situations where bid Nova
serial contact context or otherwise
where we feel reactive we feel like
we’re on the back foot we feel like
decisions are being made around us and
we can only react to it our opponents
OODA loop is faster than ours and I
think we’ve been in situations where we
feel around the front foot we’re making
decisions faster than the adversary and
this in this is the crux of Boyd’s
theory is those able to observe orient
decide and act faster than the other or
win the engagement I know you’re
thinking spin what does this have to do
with with me
what does I have to do with my place in
the world and how I engage with
technology
well I’d like to offer I guess a little
vignette a little analogy of how I think
we can all disrupt the adversaries Oh de
loop I’d like to think about passwords
now hopefully those people had actually
logged into our little are a little
trick this morning didn’t actually enter
your real password that you’ve used
elsewhere but I’ll tell you what some
people probably did you know what you
see on they up the board behind me is
examples of bad passwords now we know a
lot about passwords these days because
every major breach that occurs every
huge dump of credentials on the Internet
is available for researchers such as us
and also bad card researchers we now
know a lot about how humans construct
passwords when you use bad passwords
like this you leave yourself vulnerable
why is that you say spen but there’s
clever people who write clever
technology and clever mathematicians who
encrypt my password and that’s true
typically as you enter a password into
any legitimate site it goes through
what’s called a hash algorithm and that
means the string of text or numbers that
you’ve put in results in an enormous
string that’s completely reversible so
you can’t actually reverse engineer that
hash back into the password you entered
but because we know so much about the
way humans construct passwords because
we have because we and the adversary has
advantage to high compute we can
somewhat cheat that process we can use
our knowledge of the way humans
construct passwords to defeat that hash
and essentially recreate it and
therefore learn the passwords because
they’re so simple so when you all use
passwords in the internet if you use
passwords of their short if you use
passwords that are not random and if you
use passwords that are not complex
you’re giving the adversary the
advantage you’re speeding up his
decision cycle by being lazy his ability
to observe simple password use or in
himself to your situation in your
context make a decision to act against
that password and then actually enact
that cracking or enact that guessing
process it is made very simply
this is what I’d like to leave you with
today that the pervasiveness of
technology today tomorrow and the day
after that means that we all have a role
to play in disrupting the modern cyber
threat the modern cyber problem and it
could be as simple as using long complex
and random passwords thank you very much
[Applause]
Please follow and like us: