UMUC Team contact info:
Patrick Gill: pat@patrickgill.me
Morning Session:
On March 26-27, a DiploHack event was hosted in Washington DC. Six teams competed in a challenge. In the University of Maryland University College won. They will now give a talk on the case they solved for the challenge:
Learning about the "Scenario" - fictitious country of Zambonia is facing a cyber attack! OH NO! Who will help us??
Look! It's the University of Maryland Cyber Team to the resuce!
A bit more on the scenario: attacks on commercial banks resulted in personal data of millions of Zambonians was published on social media websites.
How do you respond? You're dealing with government entities rather than who is impacted: a citizen
- there is the problem of people dont have access to accounts, and trying to recover that information/data
- what's happening on a public level?
- how much info to share with theme
- need to craft an immediate response, to reduce the fear level, letting citizens know things are under control
BIG QUESTION: how can you keep people informed and reassured, but still have the time to respond to the problem?
There's about 7-10 days of downtime during data recovery, which is a substantial loss when looking at the number of transactions happening at microseconds.
the way the fictitious people found about this security attack is through social media this is more typical and more realistic as social media does not filter news
BIG QUESTION: As a country with a low GDP, relying on international donors, where will the funds come from for this? Would it be a change in the policies or the kingdom?
Cyber security - protection of information voluntarily given.
Many of the technical vulnerabilities are due to outdated software/systems.
Try to make management in companies/governments see that protecting their cyber-infrastructure is something extremely important which should not be dealt with by rushing from fire to fire, but by taking enough measures upfront.
Sharing of hacks, using open-source tools and sharing information between organizations requires a culture change on many levels, but they could result in better handling of cyberthreats.
Yesterday, the Global Forum for Cyber Expertise (GFCE) was launched at the GCCS. 42 countries participate in this organization which will help developing countries improve their cybersecurity.
This is a top-down approach though, which might bring its difficulties. Is it also possible to do this bottoms-up, e.g., via an NGO?
There are two methods to protect users (around the globe):
- People should only use locked-down devices (e.g., iPads) and use cloud services which are automatically secured for them
- Let people fix their own security, but this requires education, where people know how patch their systems and even switch Operating Systems once their OS is outdated (e.g., Windows XP usage in developing countries)
If we focus on method 2, then there are two big questions:
- How to get kids educated on cyber(security)
- How to get users cyber(security) aware
Afternoon Session:
There are no NGOs which help with cybersecurtiy. How would such an NGO function? E.g., can cybersecurity be agnostic? How do socio-cultural factors affect this?
- Threats for countries with lower cybersecurity: take over of computers to facilitate cyberattacks.
- Why should countries worry about cyber security when they do not have money for food or water?
- These are important issues. Still, people are connecting to the internet. E.g., cell phone banking is big in some countries and there are real risks if nothing is done about safety/cybersecurity.
- NGOs might be the best solution to spread safety/cybersecurity in Africa.
- FOSSFA (The Free Software and Open Source Foundation for Africa) wants to empower digital tools for education of the youth. http://www.fossfa.net/
http://umuc.edu/visitors/president/
16:15 Session
CYBERSECURITY LOCALIZATION
What are the challenges when trying to adapt cybersecurity help to specific developing countries?
Language barrier.