Re: [Smart] When we say 'cyber'...

Olaf Kolkman <> Fri, 19 October 2018 11:59 UTC

From: Olaf Kolkman <>
To: Mark O <>
CC: "" <>
Date: Fri, 19 Oct 2018 11:58:56 +0000
Archived-At: <>
Subject: Re: [Smart] When we say 'cyber'...
Hello all,

I am normally lurking on this list but I would personally stay somewhat at arms length from ‘cyber defence’. There is a delta in understanding between how technologists, policy makers, and diplomates use and understand the term _cyber security_ and in my experience the delta may be bigger for the words _cyber defence_.

—Olaf Kolkman

On 4 Oct 2018, at 17:44, Mark O wrote:

> There's been some discussion on the list about what to call the main topic of our research. We settled on the name 'SMART' - Stopping Malware And Researching Threats - for the list because it covered a couple of our major aims and made for a handy acronym. But it's not the whole of our ambition.
> When we first mooted the possibility of a research group at the SAAG open meeting in Montreal, we referred to 'Cyber Defence'. That's [part of] what we do at the National Cyber Security Centre - we have an Active Cyber Defence<> programme, aimed at improving the resistance of UK infrastructure to cyber attacks. So the word 'cyber' trips easily off our tongues. It's not just us - large parts of industry and academia refer to 'cyber security' and 'cyber attacks', as do the media.. But we're also aware that 'cyber' means different things to different people, it's a buzzword, it's generic, and it can raise hackles in some. Earlier versions of the draft charter referred to 'cyber security', 'cyber defence', 'security operations', and the current version refers to the rather plain 'attack defence'. Hopefully without getting side-tracked - what speaks best to most people?
> Ultimately, we don't have a strong view on what phrase is used - the important point is that it's clear and obvious what type of threats we're trying to defend against (without being prescriptive). So it's probably more helpful to try and build a list of the kind of threats we're meaning.
> As a general theme, the threats we're considering:
>   *   have malicious intent - as opposed to accidental threats (e.g. hardware failure causing data loss);
>   *   involve active interference with data, users or the network - as opposed to passive wiretapping and offline attacks; and
>   *   result in harm.
> We probably will need to reference a taxonomy of threats, and we needn't reinvent the wheel here - that work has been done before. ENISA has produced one such threat taxonomy<> which I've used to construct the list below. This is just a starting point - there will be some things I've missed off, and I certainly can't promise that we'll be able to address all of them:
>   *   Unsolicited e-mail - spam and infected e-mails; links to malicious websites
>   *   Identity theft - stealing credentials
>   *   Denial of service - DDoS, network and application layer, amplification attacks
>   *   Malware, worms, trojans, rootkits, injection attacks, viruses, exploits
>   *   Spyware, scareware, ransomware
>   *   Social engineering - phishing, spear-phishing
>   *   Fake certificates, MITM, signed malware
>   *   Manipulation of hardware and software
>   *   Manipulation of information - hijacking, routing table manipulation, DNS poisoning
>   *   Misuse of audit tools to discover security weaknesses
>   *   Unauthorised access, network intrusion
>   *   Unauthorised installation of software, web/browser-based attacks, drive-by downloads
>   *   Data breach
>   *   Remote execution, botnets
>   *   Advanced Persistent Threats
> Note that 'cyber' doesn't appear in the list once - and that's OK.
> Is that what everyone's expecting? This is still up for grabs and we'd like everyone to have the same, clear view of what we're trying to achieve.
> -- Mark
