Welcome!

Cloud Security Authors: Pat Romanski, Zakia Bouachraoui, Elizabeth White, Yeshim Deniz, Liz McMillan

Related Topics: @CloudExpo, Cloud Security, @ThingsExpo

@CloudExpo: Blog Post

Part 2: What ‘Mr. Robot’ Can Teach Us About Incident Response | @CloudExpo #IoT #Cloud #Security

It is not often that movies and television shows give viewers the opportunity to explore the world of hacking & digital security

We continue with the second part of our two-part series. If you missed the first part, we are discussing what security professionals can learn from the hit series, "Mr. Robot." The series explores the world of organized hacking as well as the security measures being used to stop the hackers.

Vulnerabilities Abound in the Internet of Things
During the two seasons that the show has aired, viewers have seen examples of how hackers can exploit connected devices. One of the most extreme examples was when hackers took over the attorney's smart home, generating a nightmare of constantly changing sounds and lights and leading the attorney to run from her own home. Another example touching on IoT security was Dominique's use of a digital assistant to discuss topics of an intimate nature. Should a hacker manage to gain access to the records, the possibilities for blackmail or additional attacks seem likely.

Mobile Devices Require Protection
In the series, several people with Android phones were victimized and, interestingly enough, real vulnerabilities in the Android such as Stagefright were allegedly exploited by the hackers. They also used a malicious femtocell to intercept FBI communications and gather information without the agents even noticing. In this age of BYOD, how can you be sure that users install the latest patches and updates? Are mobile users introducing malware into the network? What is your plan to ensure a safe, effective mobile policy is implemented and maintained?

CDs and Flash Drives Are Potential Sources of Attacks
Despite warnings that they should never insert a stick or disc with an unknown source, employees seem to forget all about the risks on a much-too-frequent basis. On the series, a malware-infected CD was given to an employee by a hacker who claimed that he was an aspiring performer and that it was a demo. The employee loaded the CD, allowing the hacker to assume control of his computer for nefarious purposes. In another episode, the disc contained a data file that was used as incriminating evidence against the corporation's CTO.

Hackers Are Seldom Lone Wolves
As depicted on the show, large-scale hacking is done by organized groups, state-sponsored departments or crime syndicates, which is a much more realistic portrayal of how hacking is handled in today's world. The image of the loner huddled in his mother's basement and hacking into government agencies, major corporations and international banks does not compute. It has been a popular image for Hollywood to depict, but today, you are up against well-funded, well-trained, skilled, talented, organized teams of hackers. They may spend weeks or even months to research, analyze, execute and cover up a hack. Counteract their patience through proactive hunting on your own network.

With a DDoS Attack, Response Time Is Critical
In the show's first episode, the DDoS attack has been praised as one of the best portrayals of a hack. When the hacktivists launched a DDoS attack against E Corp, the fictional corporation's critical applications were effectively crippled. Even with a private jet to transport Elliot and the team directly to the data center, it took several hours to end the attack. This may sound like a relatively short period, but the results of a 2015 survey revealed that critical application failure costs hundreds of thousands of dollars every hour, so immediate response is important. If your organization has a well-prepared response plan and a well-trained response team, the recovery time depicted in the show is actually realistic.

Encryption Works Wonders
Too many users still believe that encryption is too complex and is not really necessary. However, encryption is a good practice that can protect data even if the situation is quite complex. In an episode of "Mr. Robot," the hackers "liberate" an attorney's devices, which they then examine to gather information that they can use to blackmail her into silence. If the attorney had encrypted her files, the hackers' plan would have failed.

More Stories By Rishi Bhargava

Rishi Bhargava is Co-founder and VP, Marketing for Demisto, a cyber security startup with the mission to make security operations - “faster, leaner and smarter.” Prior to founding Demisto, he was Vice President and General Manager of the Software Defined Datacenter Group at Intel Security. A visionary and technology enthusiast, he was responsible for delivering Intel integrated Security Solutions for datacenters.

Before Intel, he was Vice President of Product Management for Datacenter and Server security products at McAfee, now part of Intel Security. As an intrapreneur at McAfee, he launched multiple products to establish McAfee leadership in risk & compliance, virtualization, and cloud security. He joined McAfee by way of acquisition in 2009 (Solidcore, Enterprise Security Startup). At Solidcore, he was responsible for Product Management and Strategy. As one of the early employees and member of the leadership team, he was instrumental in defining the company's product strategy and growing the business.

Rishi has over a dozen patents in the area of Computer Security. He holds a BS in Computer Science from Indian Institute of Technology, New Delhi and a Masters in Computer Science from University of Southern California, Los Angeles. He is passionate about new technologies and industry trends and serves as an active advisor to multiple startups in silicon valley and India.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
@DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22nd international CloudEXPO | first international DXWorldEXPO and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time t...
CloudEXPO New York 2018, colocated with DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City and will bring together Cloud Computing, FinTech and Blockchain, Digital Transformation, Big Data, Internet of Things, DevOps, AI, Machine Learning and WebRTC to one location.
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
Machine Learning helps make complex systems more efficient. By applying advanced Machine Learning techniques such as Cognitive Fingerprinting, wind project operators can utilize these tools to learn from collected data, detect regular patterns, and optimize their own operations. In his session at 18th Cloud Expo, Stuart Gillen, Director of Business Development at SparkCognition, discussed how research has demonstrated the value of Machine Learning in delivering next generation analytics to impr...
The challenges of aggregating data from consumer-oriented devices, such as wearable technologies and smart thermostats, are fairly well-understood. However, there are a new set of challenges for IoT devices that generate megabytes or gigabytes of data per second. Certainly, the infrastructure will have to change, as those volumes of data will likely overwhelm the available bandwidth for aggregating the data into a central repository. Ochandarena discusses a whole new way to think about your next...
The hierarchical architecture that distributes "compute" within the network specially at the edge can enable new services by harnessing emerging technologies. But Edge-Compute comes at increased cost that needs to be managed and potentially augmented by creative architecture solutions as there will always a catching-up with the capacity demands. Processing power in smartphones has enhanced YoY and there is increasingly spare compute capacity that can be potentially pooled. Uber has successfully ...
Chris Matthieu is the President & CEO of Computes, inc. He brings 30 years of experience in development and launches of disruptive technologies to create new market opportunities as well as enhance enterprise product portfolios with emerging technologies. His most recent venture was Octoblu, a cross-protocol Internet of Things (IoT) mesh network platform, acquired by Citrix. Prior to co-founding Octoblu, Chris was founder of Nodester, an open-source Node.JS PaaS which was acquired by AppFog and ...
The deluge of IoT sensor data collected from connected devices and the powerful AI required to make that data actionable are giving rise to a hybrid ecosystem in which cloud, on-prem and edge processes become interweaved. Attendees will learn how emerging composable infrastructure solutions deliver the adaptive architecture needed to manage this new data reality. Machine learning algorithms can better anticipate data storms and automate resources to support surges, including fully scalable GPU-c...
Predicting the future has never been more challenging - not because of the lack of data but because of the flood of ungoverned and risk laden information. Microsoft states that 2.5 exabytes of data are created every day. Expectations and reliance on data are being pushed to the limits, as demands around hybrid options continue to grow.
JETRO showcased Japan Digital Transformation Pavilion at SYS-CON's 21st International Cloud Expo® at the Santa Clara Convention Center in Santa Clara, CA. The Japan External Trade Organization (JETRO) is a non-profit organization that provides business support services to companies expanding to Japan. With the support of JETRO's dedicated staff, clients can incorporate their business; receive visa, immigration, and HR support; find dedicated office space; identify local government subsidies; get...