Can we ever be one step ahead of the hackers

cyber crime industry

is way bigger than the cyber security

industry

let me explain cyber security industry

is a 180 billion dollar industry

whereas the cyber crime industry is more

than six trillion

this is equivalent to the gdp of

australia canada brazil and south korea

all put together or the equivalent work

of google amazon facebook and apple

the one guarding the internet the good

guys white hats

on the other side the bad guys black

hats

the hackers this shows that people are

not assets

only good people are assets the world of

hacker consists of people who write and

sell exploits in the dark web

for as less as 50 dollars and all these

transactions

are also very anonymous because of

bitcoin

in fact there a very popular hacker joke

where did the hackers go

i don’t know they ran somewhere

every single day half a million malware

is written in the dark web

in fact most of the darkweb forums have

become the alibaba and amazon of the

cyber crime industry

to fight big wars you need to have deep

pockets

with all these statistics you clearly

know who’s winning

but i feel intellectual capital will

always term financial capital

let me explain if you see the top three

nations

in terms of cyber attack traffic lb

united states

china and russia the cyber investment by

all these nations

is enormous but still they get hacked

every single day not only nations

even corporations see some of the top

hacks

2013 yahoo attack where 3 billion user

accounts were compromised

2016 mirai iot botnet attack

which was ddos based 2017

wannacry ransomware attack if you see

all these attack patterns you’ll

understand that

defending all the time is not easy there

has to be a better strategy

before we get into the solution zone

let’s try to understand what this

world of hackers look like this how they

look like

christopher warren hassell the world’s

youngest hacker

at the age of five he broke into

microsoft xbox security

ruben paul at the age of nine

he had his own cyber security firm

but i wonder if kids can do this what

about the experts

and two more stats see the world average

of hacker

it’s 25 years old and most patents

awarded to people

are below 26 years common denominator

youth a child grows to curiosity

and so does hacker and curiosity is a

never-ending game

be finding the depth of ocean or

reaching mars

what starts off as a computer hobby

turns into unethical hacking

and that’s where the problem begins even

if you see the world’s most

famous hacker kevin mitnick in his

childhood days he was drawn by the world

of magic

again common denominator curiosity

i think there are only three reasons why

hackers do what they do

money fame activism

if you see some of the hacker lifestyle

swanky cars multi-million mansion

would want to give it up at a very young

age

some hacker groups hack into rival

hacking groups and pose their

credentials in the dark web

gives them fame in their hacker

community

for few money is not a motivation

ideologies this activist group

hack into government websites and post

their credentials

and messages all over in public or

they give access to citizens to

government-censored websites

anonymous is one of the hacktivist group

known

i think the world needs a technology

where even if a slight

evil idea comes into anyone’s mind

the keyboards should get locked and the

screen

should get blacked out well sharing some

startup ideas

well now that we understand the cyprus

world

can we ever be one step ahead of this

hackers game

well there are no silver bullets but

definitely a solution approach

i propose a three-prong approach

software coders

government schools universities and

social awareness

let’s start with software programmers

software coders

are the heart of every application that

is built today

software coders build the code but don’t

imagine how it can be misused

so the question is can every code be

trusted

because even a bad code can function

hence i propose a campaign that should

be run in mnc’s government institution

schools

it says secure everything you build

coders need to write defect-free

software

and this depends on the quality of

professors it depends on the

quality of schooling system

and this vicious cycle needs to be fixed

first

see if you are an atheist you need to

know what is religion right

so if you want to be a good hacker you

need to know how a bad hacker thinks

because even a bad hacker thinks like a

coder first

you know one can argue that the bad

hackers keep you at check

because that will help you get a good

software code

i met vitalik buterin in may 2017

in india who’s the inventor of open

source blockchain ethereum

who brought in the concept of smart

contracts we had some deep conversation

about the future of blockchain

he said every new version of software

that comes in

disrupts the earlier version to bring a

better product

this is how evolution will happen made

me think

why don’t all the software coders open

source their

product in the world and tell everyone

to break their code this will bring in

good coding practice

not just coding see

software will become smarter and

the day they become self learning will

be very difficult to control them

so the focus should be on upscaling the

resources

in cyber security alone 4 million jobs

are still vacant

because of lack of quality resource

the second pillar government university

schools

i think the real education happens once

you leave university design school

and the problem is when you leave

schools and university and join the

corporate world

you’re bound by policy regulations

and you end up doing only ethical

penetration testing

on the other side hackers are

independent free and available as

hackers

for higher program in the dark web most

of them

also offer 24x7 support can you believe

that

so the question is why in schools

ethical hacking is not taught

schools should focus on difference

between cyber legal and illegal

schools should teach students critical

thinking

and logical reasoning this will help

them identify vulnerabilities when they

reach the corporate world

establishments should penalize as well

as incentivize

for effective measures three

initiatives can be done we need more of

bug bounty programs and hackathons

this is the best economic incentive that

can be offered

this can drive two purpose okay at least

make sure the good ones

don’t join the bad hacker and since the

bulk bounty programs are lucrative

least it can entice the bad hackers to

come on this side

some of the bug bounty programs offer a

million dollar in reward

programs like tesla and facebook bounty

programs are

quite popular we need more of

ethical hacking schools in the world

this is the best educational incentive

that can be offered to students who want

to

take cyber security as an elective

why not have something called as cyber

credit rating in the world

citizens can be rewarded for good cyber

behavior in the internet

we need to also penalize for

accountability sake

and this can be done through regulations

see jurisdiction of cyber attack is very

difficult to find

because hackers operating multiple

countries keep hopping in different

regions

laws can fix this successful laws like

gdpr in the european union has shown

that

you know regulations can be outcome

driven

we need more of these regulations we

need more

replications of models of estonia and

israel

if you see models like israel they’re

far ahead in cyber security

some of the initiatives like after

school cyber program

is superb see i’ve spent a lot

of time in cyber security space in

various continents

and i still see most of the critical

government institutions

using outdated softwares

there is an immediate need to modernize

infrastructure and also plan to

de-risk the core business

15 years back i did a course on

cryptography

and network security under professor

bernard meneses

and those days is to calculate the

number of years it will take to crack

algorithms like rsa aes

two years back i met professor again he

was so happy to tell me that

he and his team has cracked the aes

algorithm

such a proud moment for me made me think

quantum computing will disrupt

encryption

and when it gets commercialized and it

falls into the wrong hands

it will be very difficult to control the

hacker’s world

the question is can we write better

quantum encryption

the third pillar social awareness

i think people need to understand that

surveillance is the business model of

the internet

this will help them accept the risk way

before

they go to the internet social media

manipulation

to influence buying behavior and

influence election

is well known you know case of cambridge

and aldegar

most of the mobile games and defect apps

might have malware in it so be very sure

of what you download

from the internet see cyber security is

taken as a very

complicated subject so why not bring in

gamification into the space

to add a little bit of fun element so

that

awareness spreads in the masses

see by 2030 50 billion devices would be

connected through iot

in terms of things in fact internet of

things

will be way bigger than the oil economy

and when the whole world gets connected

it’d be very difficult to digitize

trust i met bruce scheiner

the technology expert

of cyber security i met him in

paris in november 2013

for the isf world congress

i asked him is iot the real threat to

the world

and mind you this was way before the

mirai iot attack

it will mean when the world is connected

through devices

two things will happen the world will

change both economically

as well as socially made me think

imagine this you get up in the morning

and your fridge tells you

transfer 500 if you want to unlock me

or the car that you’re driving is

controlled by ai bot

and accidents happen and someone dies

see there will be elements of hacking in

every part of your life

in coming years the only proactive

strategy

is to have a security mindset security

should be in your dna

this is the only way to deal with

hackers

and hence i propose this cyber movement

which propagates this idea of proactive

security strategy the

benefits of this initiative is far

utilitarian

because imagine if you run this campaign

in schools

due to students the parents get educated

and hence mother and we all know once

women do better

economies do better and forget about my

mother clicking into

certain email phishing links even

corporate employees do it

so this problem is absolutely deep

rooted

we need to tell everyone that you know

never trust

always verify do you really want to

connect to any free public wi-fi

think about it i hope this three-prong

approach

is debated and celebrated and discussed

everywhere in the society

because it about debating and

celebrating differences

of all my experience in the cyber

security world

i’ve realized that cyber security is a

shared responsibility

private public partnership along with

responsible institutions like itu

and icann all coming together can fight

this evil

else they will keep controlling you for

the rest of your life

see today 60 percent of the world is

internet

when the remaining 40 percent comes in

the internet and the world becomes

completely digital

only a good hacker can save the world

see you don’t need to manufacture

missiles if there are no wars

so if no war is influenced don’t need to

sell the machinery

because guns don’t hurt people people

hurt people

well i think we all need to think

like a hacker to be one step ahead of

the game

we need to think counterintuitive

only by thinking like a hacker you can

not only be a good programmer

but you can also have a good security

mindset to change humanity

and think like a hacker is like playing

chess

you have to anticipate the opponent’s

move way before

because if you’re predictable you can be

defeated

lastly we are debating quantum computing

today

tomorrow there will be some other

technology which will disrupt quantum

computing

so there is no winning this

technological war

the only way to beat this is by having a

strong

security mindset because hackers

hack people of technology

thank you

网络犯罪

行业比网络安全行业大得多

让我解释一下网络安全行业

是一个价值 1800 亿美元的行业,

而网络犯罪行业

超过 6 万亿,

这相当于

澳大利亚、加拿大、巴西和韩国的 GDP

总和或

谷歌亚马逊 Facebook 和苹果

的等效工作 一个守卫互联网

好人白帽子

在另一边 坏人黑

帽子 黑客 这表明人

不是资产

只有好人才是资产 黑客的世界

由以下人组成

在暗网上

以低至 50 美元的价格编写和出售漏洞,所有这些

交易

也是非常匿名的,因为

比特

币实际上有一个非常流行的黑客笑话

,黑客去了哪里,

我不知道他们每天都跑到某个地方

一百万个恶意软件

被写入暗

网事实上大多数暗网论坛已

成为

网络犯罪行业

的阿里巴巴和亚马逊 打大战 你需要有足够的

财力

拥有所有这些统计数据 你清楚地

知道谁在赢,

但我觉得智力资本

永远是金融资本

让我解释一下,如果你看到网络攻击流量排名前三的

国家

lb 美国

中国和俄罗斯 所有这些国家的网络投资

都是巨大的,但他们仍然每天都受到黑客攻击,

不仅国家

甚至公司都看到了一些顶级

黑客攻击

2013 雅虎攻击,其中 30 亿用户

帐户遭到入侵

2016 mirai iot 僵尸网络攻击

,这是基于 ddos 的

2017wannacry 勒索软件 攻击 如果你看到

所有这些攻击模式,你就会

明白,一直

防守并不容易,

在我们进入解决方案区之前必须有一个更好的策略

让我们试着了解这个

黑客的世界是什么样子他们是

什么样子的

克里斯托弗·沃伦·哈塞尔 5 岁时世界上

最年轻的黑客

,他闯入了

微软的 xbox 安全

ruben paul at t 他 9 岁,

他有自己的网络安全公司,

但我想知道孩子们能不能做到这一点?

专家

和另外两个统计数据看看世界

黑客的平均年龄是 25 岁,大多数

授予人们的专利

都在 26 岁以下的共同点

青年 一个孩子成长

为好奇心,黑客也是如此

著名黑客 kevin mitnick 在他的

童年时代 他再次被魔法世界所吸引

共同点 好奇心

我认为

黑客做他们所做的事情只有三个原因

会想在很小的时候就放弃它

一些黑客组织侵入了竞争对手的

黑客组织并

在暗网中

提供了他们的凭据,这使他们在黑客中声名鹊起

少数钱的社区不是一种动机

意识形态这个激进组织

侵入政府网站并在公共场合发布

他们的凭据

和消息,或者

他们允许公民访问

政府审查的网站

匿名是

我认为世界需要的已知黑客组织之一 一种技术

,即使

任何人的脑海中出现了一个轻微的邪恶想法

,键盘也应该被锁定,

屏幕

应该被很好地黑屏 很好地分享一些

创业

点子 既然我们了解了塞浦路斯世界,

我们能否在这场

黑客游戏

中领先一步 没有灵丹妙药,但

绝对是一种解决方法

我提出三管齐下的方法

软件编码器

政府学校 大学和

社会意识

让我们从软件程序员开始

软件编码

器是当今构建的每个应用程序的核心

软件编码器构建代码但不要

无法想象它是如何被滥用的,

所以问题是每个代码都可以被

信任吗

因为即使是糟糕的代码也能发挥作用,

因此我

建议在跨国公司的政府机构

学校开展一项活动 系统

和这个恶性循环需要首先解决

你是否是一个无神论者你需要

知道什么是正确的宗教

所以如果你想成为一个好的黑客你

需要知道一个坏的黑客是如何思考的

因为即使是一个坏的黑客也会像一个

coder first

你知道有人会争辩说坏

黑客会让你

受到控制,因为这将帮助你获得一个好的

软件代码

我于 2017 年 5 月在印度遇到了vitalik buterin,

他是

开源区块链以太坊的发明者,

他引入了智能合约的概念

我们就

区块链的未来进行了一些深入的对话,

他说每一个新版本的

软件都会

破坏早期版本以带来

更好的产品

这就是 进化将会发生让

我思考

为什么不是所有的软件编码人员

都在世界上开源他们的产品并告诉每个

人破解他们的代码这将带来

良好的编码实践

而不仅仅是编码看到

软件将变得更智能并且

他们成为自学的那一天

将很难控制它们,

因此重点应放在提升

网络安全资源上 400 万个工作岗位

仍然空缺,

因为缺乏优质

资源 第二支柱公立大学

学校

我认为真正的教育发生在

你离开大学设计学院后

问题是,当您离开

学校和大学并加入

企业界时,

您会受到政策法规的约束,

并且最终只能在另一端进行道德

渗透测试

他们中的大多数人

还提供 24x7 全天候支持你能相信吗

所以问题是为什么在学校里有

道德 hacki 不教 ng

学校应该关注

网络合法和非法之间的区别

学校应该教学生批判性

思维

和逻辑推理 这将帮助

他们在进入企业界时识别漏洞

机构应该惩罚和

激励有效措施 三项

举措可以完成 我们需要更多的

漏洞赏金计划和黑客马拉松

这是可以提供的最好的经济激励措施

这可以驱动两个目的 好吧 至少

确保好人

不会加入坏黑客,而且由于

大量赏金计划是有利可图的,

至少它可以 诱使坏黑客站

出来

一些漏洞赏金计划提供一

百万美元的奖励

计划,例如特斯拉和 facebook 赏金

计划

非常受欢迎 我们需要

世界上更多的道德黑客学校

这是最好的教育

激励 提供给想要

将网络安全作为选修课的学生,

为什么不选修一些东西? ng

在世界上被称为网络信用评级

公民可以因在互联网上的良好网络行为而获得奖励,

我们也需要为

问责制而受到惩罚

,这可以通过

法规来完成,因为很难找到网络攻击的管辖权,

因为黑客在多个

国家/地区运营 在不同地区不断跳跃

法律可以解决这个成功的法律,比如

欧盟的 gdpr 已经表明

您知道法规可以以结果为

导向

我们需要更多这些法规 如果您看到像以色列这样的模型,我们

需要更多地

复制爱沙尼亚和

以色列的

模型 '

在网络安全方面遥遥领先

一些举措,如

放学后网络

计划非常棒,我

在各大洲的网络安全领域花了很多时间

,我仍然看到大多数关键的

政府机构都在

使用过时的

软件 迫切需要对基础设施进行现代化改造

,并计划在 15 年前

降低核心业务的风险

Bernard meneses 教授的

密码学

和网络安全课程,

当时是计算

破解

像 rsa aes 这样的算法所需的

年数 两年前我再次见到教授,他

很高兴告诉我

他和他的团队已经 破解 aes

算法

对我来说如此自豪的时刻让我认为

量子计算将破坏

加密

,当它商业化并

落入坏人之手

时,将很难控制

黑客的

世界问题是我们能否编写更好的

量子

加密 第三支柱社会意识

我认为人们需要了解

监视是互联网的商业模式

这将帮助他们在上网之前接受风险方式

社交媒体

操纵

以影响购买行为和

影响选举

是众所周知的 cambridge

and aldegar

大多数手机游戏和有缺陷的应用程序都

可能包含恶意软件,所以要非常确定

是什么 您

从互联网上下载看到网络安全被

视为一个非常

复杂的主题,所以为什么不将

游戏化引入空间

以添加一点有趣的元素,以便

在大众中传播意识,到

2030 年将有 500 亿台设备

通过物联网连接

就物而言,事实上

物联网

将比石油经济大得多

,当整个世界连接

起来时,将很难将信任数字化

我遇到了网络安全技术专家布鲁斯·谢纳

于 11 月在巴黎遇到了他 2013

年 ISF 世界大会,

我问他物联网是对世界的真正威胁

,请注意,这是在 mirai 物联网攻击之前的方式,

这意味着当世界通过设备连接时,

将会发生两件事,世界也会

在经济

上发生变化 社交让我

想像这样,你早上起床

,你的冰箱告诉你

转移 500,如果你想解锁我

或者你驾驶的汽车是

可控的 d by ai bot

,事故发生,有人死亡

黑客

,因此我提出了

这种传播主动安全策略理念的网络运动,该

计划的

好处是非常

实用的,

因为想象一下,如果您在学校开展这项运动

因为学生父母受过教育

,因此母亲和我们都知道一旦

女性这样做 更好的

经济做得更好,忘记我

母亲点击

某些电子邮件网络钓鱼链接,甚至

公司员工也会这样做,

所以这个问题绝对是

根深蒂固的,

我们需要告诉每个人,你知道

永远不要信任,

永远验证你是否真的想

连接到任何免费的公共无线网络 -fi

想一想,我希望这种三管齐下的

方法

在社会上到处都能得到辩论、庆祝和讨论,

因为它 关于辩论和

庆祝

我在网络安全领域的所有经验的差异

我已经意识到网络安全是一种

共同责任的

私人公共伙伴关系,与

ITU 和 icann 等负责任的机构

一起团结起来可以对抗

这种邪恶,

否则他们将继续控制你

你的余生

今天看到 60% 的世界是

互联网

当剩下的 40%

进入互联网时,世界变得

完全数字化

只有优秀的黑客才能拯救世界

如果没有,你不需要制造导弹 战争,

所以如果没有战争受到影响,就不需要

出售机器,

因为枪支不会伤害人,人们

很好地伤害人我认为我们都需要

像黑客一样思考才能领先一步

通过像黑客一样思考,您

不仅可以成为一名优秀的程序员,

而且您还可以拥有良好的安全

心态来改变人类

并像黑客一样思考 下

国际象棋,

你必须提前预测对手的

移动方式,

因为如果你是可预测的,你最终可能会被

击败,

我们今天讨论量子计算

明天将会有其他一些

技术将破坏量子

计算,

所以没有赢得这场

技术战争

的唯一 解决这个问题的方法是拥有

强大的

安全意识,因为

黑客会攻击技术人员,

谢谢