Presentation is loading. Please wait.

Presentation is loading. Please wait.

1 What is the Game in Cyber Security? Ravi Sandhu Executive Director and Endowed Professor February 2011

Similar presentations


Presentation on theme: "1 What is the Game in Cyber Security? Ravi Sandhu Executive Director and Endowed Professor February 2011"— Presentation transcript:

1 1 What is the Game in Cyber Security? Ravi Sandhu Executive Director and Endowed Professor February 2011 ravi.sandhu@utsa.edu, www.profsandhu.com, www.ics.utsa.edu © Ravi Sandhu World-Leading Research with Real-World Impact! Institute for Cyber Security

2  Multiple games at multiple levels  More than 2 players or teams  defenders, attackers, technology innovators, …  Many ways to change the game  Biggest challenges  we don’t get to set the rules  we don’t get to pick the adversary  asymmetric: defense is harder than offense  Most important recommendation  cyber security needs to be a proactive rather than reactive discipline © Ravi Sandhu 2 World-Leading Research with Real-World Impact! What is the Game?

3 3 Microsec vs Macrosec From Wikipedia, the free encyclopedia: Microeconomics (from Greek prefix micro- meaning "small" + "economics") is a branch of economics that studies how the individual parts of the economy, the household and the firms, make decisions to allocate limited resources, typically in markets where goods or services are being bought and sold. Microeconomics examines how these decisions and behaviors affect the supply and demand for goods and services, which determines prices, and how prices, in turn, determine the supply and demand of goods and services. This is a contrast to macroeconomics, which involves the "sum total of economic activity, dealing with the issues of growth, inflation, and unemployment. Microeconomics also deals with the effects of national economic policies (such as changing taxation levels) on the before mentioned aspects of the economy. © Ravi Sandhu World-Leading Research with Real-World Impact!

4  Most cyber security thinking is microsec  Most big cyber security threats are macrosec  Microsec  Retail attacks vs Targeted attacks  99% of the attacks are thwarted by basic hygiene and some luck  1% of the attacks are difficult and expensive, even impossible, to defend or detect  Rational microsec behavior can result in highly vulnerable macrosec © Ravi Sandhu 4 World-Leading Research with Real-World Impact! Microsec vs Macrosec

5 Technology Innovation © Ravi Sandhu 5 World-Leading Research with Real-World Impact! Old attacks New attacks Old technologiesNew technologies

6 Productivity-Security  Cyber Security is all about tradeoffs © Ravi Sandhu 6 World-Leading Research with Real-World Impact! ProductivitySecurity Let’s build it Cash out the benefits Next generation can secure it Let’s not build it Let’s bake in super-security to make it unusable/unaffordable Let’s sell unproven solutions There is a middle ground We don’t know how to predictably find it

7 Cyber Security as a Discipline © Ravi Sandhu 7 World-Leading Research with Real-World Impact! Computer Science Cyber Security

8 Cyber Security as a Discipline © Ravi Sandhu 8 World-Leading Research with Real-World Impact! Computer Science Cyber Security


Download ppt "1 What is the Game in Cyber Security? Ravi Sandhu Executive Director and Endowed Professor February 2011"

Similar presentations


Ads by Google