Cybersecurity Trends and Insights
Cybersecurity Trends and Insights
Roshan Chandra Gupta whom I have known for a very long time as one of the leading
uh software cyber security experts in the country and as you know uh this subject
is about emerging trends uh the the new things that are happening and things that
you should be aware of and even spend some time learning about And there's no
better person than Roshan to talk to you about cyber security. He has been uh at uh
at the government places. He has been at the priv private sector. He has been
lecturer. He has been a spokesperson for a sensor in charge of the cyber security
for the government and a very active person. So you are guys are very lucky to be
able to hear to Roshan today on what is happening with the cyber security. This is
one of the most important areas nowadays with this developments happening in the uh
in the world on AI on on on on uh communication the OG 5G uh the security is
becoming an extremely important area and a very uh lucrative job opportunities as
well in uh those who are cyber security experts and Roshan will talk about
everything. Uh can I request everybody uh all the students who are here to put your
S number and the name S number and then your name so we can identif I can identify
you as attended this lecture. Some of you have already done that. put your S number
or your registration number and then your name. Okay, Roshan, over to you. Uh, as I
said, most of these students are final year students and will be graduating. So,
it's extremely important for them to be aware of the cyber security aspects of the
digital landscape. Thank you sir for introduction and and just share my screen. Um
just let me know when you can see my poweroint presentation and the screen. Yeah we
can we can see it see it right. Okay cool. So let me u just to let you know the my
topic and the speech will be on the security and why it is important and where I
need to apply it and so on and I'll try to have it as a more of a interactive
session where I'll be asking some questions where hopefully you will be answering
so that I can get an idea and to adjust my speech at the end of it so that you get
the best out of it rather then starting from a very say basic level and talking
about some basic uh things only. So if you have any questions and so on please do
feel free to speak up and ask questions then I'll get a better understanding
whether you got my points or whether I need to explain it more or do I need to give
a different example as well. So we'll start. So in in uh agenda wise what I have is
this kind of a outline. We have what is available in news as of now and what are
the type of cyber attacks that we have and about the information security and our
approach to our home security. So you might be thinking okay we are talking about
cyber security so why do we need to think about home security? When it comes to
that point, you will understand why uh that is important. And then what are the
type of frameworks and so on that is used in security to make sure that you do the
security in the best way possible that all type of cyber attacks can be kind of
avoided or at least minimized. In case if it uh happens then you are prepared for
it as well because uh that is the important part because in cyber security there is
no guarantee that 100% security will be there for everything. So there are places
where you can go wrong or you can be attacked you might be targeted. So in such
situations you need to come up with a plan. Okay, if I get targeted and attacked,
then what do I do next? So that is something that you have to plan it well before
rather than waiting until the last minute and see okay when something goes wrong
okay what do I do next so that's the kind of a overall approach I wanted to
highlight and of course uh with my uh background and the things that I know uh if
you ask me to do a uh programming part I will not be the best person to ask but if
I if someone ask okay what are the basics security things that you need to do when
you do programming or coding and as a software developer. Yes, there are lots of
things that you can do about it. But all of those I'll try to cover it in somehow
or the other. So that will be much more helpful for you as well. And of course
security is not only on software part of it because that is the mostly things that
people talk about but it is about the network security and so on and so forth. If
it is on the cloud right now then cloud security is another point and these days
the very hot topic that people are talking about is this AI security whether it is
secure and whether it is good to use it. Do we need to do some other things or
should we use AI only to do the coding part but not for security? But attackers
might be using this uh security tool which are also available for them as it is
available for us and how do we handle that part as well. Okay. Um, anyone can
remember or recall this uh picture or these people if you know anyone can give a
kind of a B I guess uh it's about a movie or TV series I identified the Matt Damon
and Brad Pit. Okay. At the center. Yeah. Okay. And this is George Clooney who is a
very good actor. And this is I would say it's a movie but it has become a kind of a
series. That's a very good uh answer from you. Anyone else who want to try? With
the number of people you might be able to guess the name of the movie. Just give it
a try. I mean there are no right or wrong answers. It is just breaking the ice for
you to speak up. So how many people are there? Can anyone tell me? About 31
including us. Rashan. Um yeah. Yeah. I'm talking about the you mean okay sorry I
also don't know what it is I can recognize some faces but some faces and there are
11 people in this picture 1 2 3 4 5 6 7 8 9 10 11 so this is a movie called Oceans
11 if you have it yeah O's level then it become ocean 13 because in the next series
they got the two colleagues to be the uh gang so why it is important important is
what they do is they break into these casinos and steal money in a simple way. But
the pro but the things to learn from that is how much planning they do before they
break into this system. So they do study the how much of people or how many people
are in the casino at a given time and what are the time where the security guards
are changing their positions at what time they take breaks where the CCTV cameras
are and how they monitor CCTV camera and what are the connectivity that they have
it and internal architecture structure of the building all of those they do study.
If you have watched it, you might know, you might remember what what I'm talking
about. If not, it's a very kind of a classical and very planned attack that they do
for the one of the largest casinos. I mean, of course, it's a movie, but they are
planning and everything, they show it very nicely. But the point is even in cyber
security or cyber world everybody whenever they do want to do a hacking or
something of that sort they do plan it. So as a security professionals or the
professional IT professionals whatever the things you do be it cyber uh on software
development or network security or cloud security or whatever the area it should
not be always cloud security but if you are developing some software to for clouds
and if you are developing some software for mobile security is a concern for all of
those areas and how an attacker can target you need to consider and have an idea
about it so so that you know how to defend it. So that's the basic point. So if you
have not watched this movie, it's it's a very nice movie in a way so that it gives
you a lots of understanding how much detailed planning they do before they attack
into this for every move, every second or every minute is counted and they carry
out those activity very kind of a professionally in a way so that they get into the
target that they are expecting. So that the kind of a similar thing that do that
happens in most of the other places as well. Okay, coming back to the real world
scenarios because in the oceans 11 you might think okay that's a movie so who cares
and that will not happen in the real world and so on but people do take
inspirations out of those movies to plan it properly. So these are few news that
was in the uh websites and in the media highlighting in different places. So this
is on 18th than a month ago. This is from what do you call it as this hacking group
EP arc. So if you search it in the internet you will get to know lots of details
around it. I guess being software development and in the IT field, you might be
using this GitHub very much for storing your codes and sharing codes among the
others and so on and so forth. So what these people have done is they uh this
information was published from this trellics. what they have uncovered a
sophisticated espionage operation targeting diplomatic missions across several
regions in South Korea during early 2025. So this was published in August but this
has happened in early 2025 between March and July in that early time. So what they
have done it they carried out a sphere fishing email attacks which we call it as a
fishing email. usually say okay somebody is sending a email to you pretending to be
somebody else asking for your personal information and if it is like okay address
like okay hello uh I'm sending you this email because you are a pinner of a lottery
or something something and provide your personal details to deliver the gift or the
price or something then it is not specifically targeted to you but if it says okay
uh hi rashan you have on a lottery and this uh we need to collect some information
from you to provide you the gift or the prize. If it is addressed to me then it is
specifically to me then I will think okay h this might be a good uh or genuine
email which might I might have won some
kind of a lottery so I might fall for it. So this fear fishing is a very specific
targeted kind of attack and they have sent 19 of such emails across uh embassies
worldwide and whenever the foreign missions or the foreign delegates uh come into a
country as a foreign delegate working in an embassy or something then obviously
those people are working in a different country. So the they are representing their
own country. So they are diplomatic communications and their stance on different
things like even recently you might have seen it with the UN sessions are
happening. So each and every country have their own ideas and uh supportive to the
other countries or against the other countries and the things that they need to do
and those kind of a things are very politically sensitive information. So how do
they communicate among themselves easily using emails and technology as we do but
they will also be aware that these kind of a cyber attacks and threats are there
and if someone can identify what these different countries are planning then we can
take some action against it. Say if I know okay some countries are planning to
attack Sri Lanka then we can say okay yes some people are trying to attack Sri
Lanka so we can take some remedial action or we can take proactive action to
protect ourel but these fear fishing attacks were sent so that usually this usually
this email attacks and things people say there are spelling mistakes and
grammatically it is wrong so that you can definitely identify it is a bogus email
you can be safe. But these uh DPRK attackers have been very carefully crafted this
emails and it is using some diplomatic terminologies and the ways of writing it and
also it is also used some current setups and scenarios that are happening and as if
the meeting invites for a meeting that happens in say next month some foreign
delegates are coming in. So why don't you join this meeting and so on so that
everybody's then tempted to respond to these emails and click on these links and
download these attachments which comes as a invites official letters and event
invitations. So all of those I mean whenever this kind of a thing happens everybody
says okay I have a virus card and our networks are protected from firewalls and so
on. So how this kind of a malicious content coming to my computer? So how they have
done it? GitHub is a place where everybody kind of trust the information and the
data that is there and the codes that you downloaded from there as well but they
have manipulated uh to have their command and control center in this GitHub as
well. So it's a very huge uh website or a database I would say to store lots of
information and along with it you have some malicious codes as well which most
people does not believe. So that might be a very trusted source of communication so
that you do list those kind of a website. So all the downloads that are coming in
we tend to trust it. But actually what has happened with the espionage taking
information from these diplomatic missions and diplomatic people from their
laptops, desktops or whatever the things that they have utilized. So they have been
collecting information about other countries for a while. So it is going on and
still some about these people and what they are doing it is also available in the
internet. So that is just giving you a setting of the context. Okay why we need to
consider these different kind of a things and of course when I share this slide
deck you can go through this link and read it through. It is not highly technical
details are there but it talks about how these people have carried out this certain
attack. ultimately spying on different diplomat high ranking diplomatic officials.
So they are sharing the password protected zip file and what is the steps that they
follow to get this information. Okay. So this is another um side of this kind of
attack. So it is it is in from the Poland and this was published on 21st of August.
Uh Poland successfully defended against this critical infrastructure attack. So
even in Sri Lankan context whenever we have a critical infrastructure be it water
supply, electricity supply and so on. We tend to believe okay there is nothing much
or if electricity goes down for one or two hours or 3 hours we might not be very
concerned about it too much. But if you consider a country like uh Poland where
they have snow and winter and the different seasons, if power fails during that
winter time period, it causes lots of other problems. Not only just the monetary
losses but due to the heating is not working in each and every household. uh they
might be affected people due to the winter strong um cold. So people may die due to
the cold. So in such situation cyber attack on a critical infrastructure or in even
in a power plant can cause human lives to loss. So that is not a healthy situations
to be beyond and also for water supply and so on in Sri Lankan. I don't know how uh
computerized the cleaning process and making sure the water is up to the uh
drinking water is up to that standard for human consumptions. If it goes into a say
chemical mixers and so on if you can change it through a computerized systems and
if it causes problem then it can also cause some human lives to loss. So what I'm
trying to say is even though we think the cyber attacks only steals money and only
have some damaging news about you or something of that sort but it can cause human
life losses as well. So this is also the critical infrastruct infrastructure thing
on the the a large police city could have had its water supply cut off on Wednesday
as a result of a cyber attack. Deputy
Prime Minister said after intrusion was oil so they managed to stop it and it the
water supply could have been uh stopped due to this cyber attack. And of course
when these countries are h I mean within the Europe's region and with the uh Russia
and uh Ukraine war there are lots of those kind of cyber attacks happening or in
two different angles as well. Of course I don't want to say who is right or wrong
but this is the reality what is happening. So whether it is good or bad we can
judge because it's ultimately the human lives that we are losing in either side of
it. Okay there is one more that is on the leak exposes this UK spies in an Afghan.
So this published on this 18th July. So this is also a very interesting uh story to
read. uh whenever this um data leak happened which was in 2022 February some time
back but now it is coming up to the light because the simple scenario what has
happened here when the UK US and all the some set of western countries try to
attack Afghan Talibans Afghan citizens supported um US UK troops to get inside
information or the intelligence out of the country saying okay these these are the
areas where these people live or these are the kind of a paths that they traveled
and so on because that has to be taken from the locals because they are the best
people in the ground which knows what is happening on the ground actually so they
have recruited kind of 19,000 Afghans to be kind of a spying on Talibans and all of
those details and along with the hundreds of British officials, secret service and
so on and the intelligence services people names were on an Excel sheet.
Accidentally, one of those people in the UK um secret service have accidentally
sent this sensitive database outside the government. So it has gone into the
outside. So when it goes to the outside they will obviously identify okay who are
the secret service agents in British or in Britain and also the 19,000 plus Afghans
who supported this UK people. So of obviously if this database goes into the
Taliban's hands of course definitely they will target their own citizens for
betraying them. So this has happened in 2022. What has happened as soon as they
identified okay they made a mistake and this name list is published and everybody
can identify okay these are the spies and so on then obviously it causes lots of
problems. But at that time what they have done is they put a court order saying
sharing this information is illegal and should not be sharing that information to
the outsiders or anywhere else. keeping this database would be some kind of a uh
illegal thing. So they had to kind of they keep it down from the news and
everywhere hoping that Afghan citizens would be protected from the Taliban attacks.
But only in this July uh time period now that court order was there for a 2 and a
half years or some time period after that it has been uh rest uh it has been
released. So now they believe after two two or 3 years time period these people
might have already come to US or UK and they are safe now but uh that also causes
some human um life uh in at stake. So those are the kind of a things that can
happen and this is a kind of a purely a sort of a accident that they have sent this
Excel sheet outward which supposed to be internal thing. So in security you might
have the best of the technology that you have but still they fail it. I mean you
and I might not be knowing what exactly the the UK special forces headquarters uses
for protecting their information but somebody has attached this Excel sheet
wrongfully. So that's a simple thing that has mistakenly done. So likewise uh
different types of data breaches and things do happen along with it it causes human
lives to loss. So that is what the important point and of course in this kind of a
uh espionage thing for different countries they might have a their own u say
drawbacks and the advantages out of it as well. So those are kind of a news that
I'm taking from different angles for you to get an feel for it. The cyber security
everybody says okay if my computer is having a strong password I'm okay but then
what about your banking systems you need to log into your banking system to do
transaction and if someone else can do it then your money will be gone. So likewise
it's in different angles we need to look at it and this is one of the website that
I would like to share with you the information is beautiful website where it talks
u different data breaches and so on they will list it in a one single place so that
if anyone is interested about reading about it going into the detail about it uh
understand how these attacks have happened and so on you can read it through. So
you can see here it says the Indonesian SIM cards 1.3 billion users data been
published or stolen and Indonesia's health agency health information was stolen or
broke broken into so that is in the U u attackers's hands and AT&T 73 million data
was lost so any of these companies if you looked at it. Shanghai police data lost
is also there and Twitter 20 million data was lost and Santend is another bank in
UK and uh Europe region. So they have lost Microsoft is not a surprise that is also
there. T-Mobile is one of the largest mobile operators and sometime about a year
and a half ago in Australia you might have heard about this one of their biggest
telecom operators also got breached and the citizens um ID cards the driving
license uh not the ID cards they they use the driving license as their identity
proof so the telecom operator lost about 24 million ion users uh driving licenses.
So then only that is the lost part and then the government has fined this company
for not failing to protect the citizens data information and then on top of it they
were fined for that and on top of it for is reissuing the license for each and
every individual again with unique numbers and tax and all kind of a things. All
the cost government will not spend but the tele operator supposed to spend it as
well. So tele operator had a huge blow through that. So it might be considered it's
due to a compliance issue because they were failed to take the necessary actions to
protect the customer data. Of course they are being the one of the biggest telco in
Australia they have should should have have all the latest technology and so on but
for some mistakes this data breach happens. So data breaches do happen not only for
smaller companies and where you have lack of security but the attackers would
target very high-end high secure environment either for their fame just to say okay
yes I have broken into these systems or if they have broken into those systems
those companies can go down or bankrupt even because of the financial damages
reputational damages and fines and other expenses. legal uh fees and so on for from
the people as well. So it it's a uh large area that we can discuss as we go along.
So this is just Yeah. Can I ask a question? May May now if say now there are
software developers who are involved in developing these systems, how much
responsibility goes to the software developers when when a breach like this
happens? very difficult to prove exactly who is responsible because it's ultimately
the company who is running the software. So if I do the development and of course
it's I'm not doing it my by myself I might have another 10 15 people to do the
coding and once the coding is done security team or a professional will check for
vulnerabilities and so on and try to adjust them saying okay these are the
vulnerabilities and this is how you need to fix it please fix and sometimes they
are very much in a hurry to deploy these products into the market so they might
just send it out. So when they send it out the board directors and the people who
sign it for it saying yes it is good to go live might be the final responsible
person for the entire security part of it. Maybe not the person who did the coding
and make the mistake. Okay. because it's a kind of a shared responsibility where
everybody has to be responsible for their part and ultimately the company uh
security team and people who missed that point they will try to see okay if the
security people have given all the vulnerabilities and whether it was properly
implemented and then if it happens a data breach then they need to do a proper
investigation to figure out who is actually responsible in development life cycle.
So as far as I know in any places people who finally says yes it is good to go live
and those kind of people are the ones who responsible because they have to make
sure that everything is in right place in the right way and a secure manner when
they go live and of course sometimes it might be I mean the other option is they do
cover it with the insurance the cyber insurance is another big talk that
everybody's talking about uh like you are insuring your vehicle when met with an
accident you can get it reimbured and fix it. Similarly for cyber risk also we have
the option of going for a cyber uh insurance where if some kind of a data breach
happens or uh data loss happen then all the the legal fines the other fines and all
the other um money that you need to spend will be covered by the insurance. So of
course based on the assessments they do they will give you a premium and you need
to pay it if you do so if there is a cyber attack then of course you can get it
reimbured. So that kind of a approaches are done so that uh otherwise what would
happen is nobody will take a risk in doing a coding if a junior programmer is uh
responsible for the entire thing. So it might be the case but it it's a
organizational level responsibility that you should uh take up for this kind of
activities. Okay your question. Yeah. Yeah. Thanks. Okay. So in different type of
cyber attacks you do have different ways of looking at it as we discussed the
fishing attacks, maninthe-middle attacks.
You just be in the middle of it. try to communicate to this person as of this one
and you are communicating with this server as the individual but you are the one
who is in the middle of it and does this those kind of attack denial of service
attacks say for example if you are doing some stock exchange or business so that
you're supposed to uh buy trade or buy shares So sales shares whenever you require
it you need to do it. If you do it right now you might make millions out of it but
if you can't do it right now you might lost millions of it. If someone is blocking
your path denying your service which is legitimate to you. If someone is blocking
it that you call it as a DOS attack or the denial of service attack. So the service
that you are expecting you will not be able to get it. But DOS attack is a denial
of service distributed denial of service attacks where attackers are much more
smarter and try to make sure from a service server point of view or the as
organization point of view I will be finding it very difficult to block this
particular attack. So ultimately you might lose businesses reputation and so on and
so forth. Now reputational losses uh typical examples would be if you can remember
recently there was a AI India plane crash and only one person survived out of that
thing but still many people whenever you get a flight details with India
everybody's are we going to go with the India or shall we move it to a different
airline so air India will find it difficult to come up to the earlier safety
standard than the reputation that they had earned. And also if you can remember
some time back you had this Malaysian airline MH370 gone missing. And during that
time period and even now when some people wanted to fly in Malaysian aine, they
still think okay are we good to go in Malaysian airlines still? Should we take
another flight? Can we change it to a different flight or something like that?
Because people are skeptic about it. So similarly reputational damage is a very
crucial thing in this industry if it is lost getting up to the previous level will
be really hard even though you have enough money and whatever the reputational
damage is the biggest damage that will be very difficult to restore. Of course the
password attack, bruis force attack, whatever the password you might have as we
know that when you have a password for your banking systems, your email system,
your social media accounts and if all of those are interlin together then only one
password needs to be guessed by a uh hacker so they can get into all of those. and
for your computer and if you have a if you are working and once you start working
you will be getting a computer from office as office laptop. So you need to have a
password for it and you have thousands of password ultimately to remember and
everybody might be reusing some password for different things which is not
advisable but can happen. But in that way if someone gets into one of your accounts
they might be able to go into the rest of the accounts as well. So likewise
different types of cyber attacks are there spyware kilogers and so on. If you still
I see some people whenever they wanted to install some genuine software they would
try to download a crack from somewhere and try to use it without paying the license
fee for the genuine product. Those crack software that you use might be a spyware
or a key logger where somebody's keeping track of what you do all the time and they
might be able to get your passwords easily because you type on the keyboard. Key
logger will log all of your key strokes and send it to somebody the attackers so
they can use it for their own advantage. So those kind of a malware attacks can
anyone uh tell me what's the difference between a virus and a malware or say um
Trojan and so on and so forth that people talk about virus guard, malware guard or
on the other hand we talk about the worms that goes around in the computer networks
Any suggestions? No idea. So it's a I mean if you are doing programming and coding
it's a very simple answer that I always say is virus malware whatever whatever it
is it's just a piece of code which is doing something bad malicious that is why we
call it as a malicious software or malware in short and what it can do is different
different either it can spread by itself then we call it as a worm and if it uh
attach to a file and so on then we call it as a virus. We call it as a Trojan. If
it comes as a legitimate software and you try to download it and install it and
once it is installed u it is collecting all of your data and damaging your computer
stealing data and so on and so forth and all of those are just this piece of code
which comes to your computer without your sometimes it is with your permissions but
uh it causes damages. So it it's in a personal level and as well as in organization
level if it happens then it can cause business to go down because it can affect the
sales and marketing and all the other things and um data losses and so on and so
forth. So it is always uh whether it is on a personal level, organization level as
a country, as a government everything is import. Okay. Uh whenever we say about the
security and information security specifically uh we do talk about three things.
Now whenever we say okay something has to be secure then next question is okay what
do you mean by security but we say okay this is secure and this is not secure. So
whether somebody can come and take our data and whether somebody can come and
modify my data and so on and so forth. So in that case whenever somebody says okay
your data is secure or not secure we need to
identify okay what do you mean by security. So first thing is this confidentiality
because uh you need to make sure that data is only with you and only the relevant
parties can see it not everybody and data integrity means whatever the data you
have you have to make sure that no one can modify it without your authorization and
so on. And the availability is the data and the website or whatever the systems
should be available whenever you wanted to access it. So if any of these points uh
are missing then we call it as okay there is a security concern or a issue that we
need to address and that is what you call it as a CIA. the C for confidentiality, I
for integrity and availability and the CIA traits and on top of it we talk about
authorization authentication, authorization and nonrepudiation. For a simple
example, authentication mean you need to verify whether this is the right person
who is coming into the system with the correct username and password. That is the
authentication part. If you identify who is coming, authorization mean you want to
make sure he is authorized to do certain activities the level of access that he the
individual is having. So that is the authorization part and nonreputation mean you
anyone using a electronic system does something like say for example you logging
into your banking system and you transfer money and when you do it they will send
you a SMS with the OTP or the one-time password which is generated for that
particular transaction when you enter it only the transaction will go through and
Then the bank will identify okay the user has used your username and password
authentication is done and authorization is done based on your account and so on
they will give the access to your bank account and to the money and so on and once
you do the transaction you can't say okay I did not do it that is the non-
reputation part you can't deny that I have done it I mean sometime back also I
heard in the news and so They were saying some people when they their username and
password was compromised or some hacker has that whenever they use the username and
password to loging into your banking account then the OTP will come to your phone.
Then then they will call you or the hackers will call you and say okay this is
calling from the bank security team we have sent you OTP can you share it to verify
this is you and you are the right person. So you might share the OTP with the
hacker. So hacker will use the OTP and they will transfer the money and they will
run away with it. So even if you go to the bank and say okay I did not do it, you
can't deny it because it is your username your password OTP came to your phone. If
you have given everything to somebody and somebody has stolen your money, it is
something that bank cannot interfere and safeguard you with because it is something
like your wallet and with the cash you have given to somebody and said okay he has
taken my money can the bank will reimburse that no way possible. So that is what we
need to consider in this kind of a setups. So you need to understand okay in
security what are the things that we need to protect and how to protect it. Okay.
Uh what do you think of these uh different uh things that you see on the screen? So
this is where uh talking from your end starts. What do you think of these? Anyone
wants to make a guess? Of course there are 20 of them but you don't have to
identify each of them but at least if you can share some lights. Okay. These are
this and something like any suggestions. Number 10 is a phone number. Mhm. So it's
number 12. Okay. Number 14 is IP address. So it's number 15 and 16. Number 17 is uh
what do you call it? The MAC address. Number 17. Yeah. Other ones are maybe short
codes. 1 9 0 1 9 1 9 Mhm. Number seven is a phone number. The rest of our numbers.
I think when you get into the phone number mode, you believe that every other thing
is also or most of them are phone numbers. That's okay. Anyone else want to give it
a try? Number 17 is IP6 address. Mhm. And 18th and 19th some MAC address or
something. Mhm. Uh five and six are emergency numbers. Five and six are emergency
numbers. Okay. Emergency numbers. Any idea what those numbers are to where it
belongs to something of that sort? I think one of these is the government
information service. No. 919. I think number five is uh that uh ambulance service.
Mhm. Uh press three is telecommunication IPS number short codes. Press three. Press
three is a hot mobile and dialogue. 911 is emergency number of Sri Lanka. 919. Uh
okay. 119. This is 119. 119. Yes. None is the newest I think. Yes. Yeah. The 10th
is Sri Lanka Colamut. Number Yes. Number 10. Okay. Number 10. Uh number 16 is local
IP address. Local in the sense Sri Lankan or no we have a local machine local rout
in routers home routers okay okay uh it's not not zero it's 108 we use it's I think
it's a publicly we can use without get permission which one uh number 16 uh it's 16
okay yes it's one uh 1 2 1 92 1 16 1 1 is used in router and 81 is I not I know
about I don't know about zero one okay all good good answers and anyone else wants
to try no one has spoken about number 20 is book number 20 Number 20. That's a good
attempt. All right. Good. Number six also. Uh campaign number dialog. Number seven.
Sorry. Number seven. Okay. So, how do you say it is a dialogue number? Because of
the number pattern. And uh it's 1 2 3 five six. Mhm. It's I I can remember it as a
combined number. Right. Good. Good. So, good attempt and good answers as well. And
anyone wants to guess on this um 11 12 13 is 20 ISBN 20 number is a ISBN number.
Okay. So I mean I'm not saying that anyone is right or wrong so far. I'm just
trying to get your opinion and ideas around it because my question is what do you
think of these? Right. Number 12 is a Singapore telephone number. I think I put
telephone number and this one or number 11 2 3 4 5 6 7 8 9 10 11 numbers are there
11 and two zeros that I don't know. Okay. So just for the interest and the ideas or
just to have the conversation I just wanted to ask this question. So what I ask is
what do you think of this? So when you say these are short code numbers and so on.
Maybe initially when you go through the list you don't understand what it is or you
don't have a clue. You have some set of data only but you don't know what are the
information behind it. So when you looked at these numbers and when you come down
here these are look like telephone numbers because the format or the pattern is
like three digits and then seven digits all together 10 numbers are there and then
you can break it down to saying okay this is a country code this is a area code and
so on. So this is the area code. Uh anyone knowing what this number would be in
that case? Not 55 area code. Anyone from Badul area? It is the Badul area telephone
code area code. And this is uh number 24 area code for WA and so on. If you have a
bit of an understanding around it because of your knowledge, you identify okay this
is a telephone number because it has 10 digits and so on. So this one somebody said
it is a colbo number. Anyone remember this number or use this number for any
communication? No. So this number is the telephone number of the open university
city itself. So general number is this number. So when you looked at these numbers
then you think okay all of these are telephone numbers. So this also supposed to be
some telephone numbers. Then you think okay this has to be a short code and in Sri
Lankan context we say yes it's a short code for the hutch and this is for dialogue
and this is for mobility and then okay this is not matching with this because in
Sri Lankan context we have 119 but here it is 911 and also then I can say okay this
is September 11th today's date 911 which is also a very kind of a in a way sad day
because uh US got attacked on 911. So 911 is a very special day for them.
Ironically they are hotline or the emergency number is also 911 and in that happens
in 2001 couple of hours ago I was checking on the 911 news and so on. It happens in
2001. So that is also very targeted planned not just by one or two days time but uh
over a long period of time they train pilots to uh fly or people to fly or the
terrorists and they managed to get into planes not only one but few of them and it
was a very long time period they planned it out and carried out that attack. So
similarly cyber attacks also not just I think okay I need to hack into this site
today and I'll do it. No I'll plan it. I'll do some collection of data what are the
strengths and weaknesses of them then I'll try to attack it. So likewise if you
think of these numbers only then it does not make any sense. So you try to make
sense out of it with your knowledge that you have. So then if you consider okay
these are telephone numbers and so on. I can argue no these are not telephone
numbers. This is the year 1788. This is year 1990. This is year 1919 where the
first world war happened or it was during this time period the war was there.
Likewise I can explain it just because of the numbers you with your understanding
and knowledge you determine okay this has to be the telephone numbers but these are
could be years and 1919 of course that is correct I mean in a way it is the year
where something happens or in the other way you can call it as a emergency suicide
ambulance service number likewise And these are also if you consider in this
particular line these are telephone numbers. This is in US and this is in Malaysia
I think. And this one is uh in Tonga the country which is very much closer to Fiji
and Australia. The to the right side of it you have a country called Tonga. Very
small country. So that's why their country code is 676. And this is the if I can
remember correctly this is the uh the telephone number within that region. So if
you're dialing from the
country itself only five-digit number in Sri Lankan context we have 10 digit
number because we have a large area to cover or the large population to cover. So
based on that we can get some kind of understanding around these numbers and of
course rightly so these might be the IP addresses and on the other hand I can say
okay these are some serial numbers on some device or equipment and these are
private IP addresses and this is a public IP address. So 192.1680.1 is an private
IP address that we can use it within our local area networks and it is given free
of I mean we don't have to get permission from anybody to use it. it is on our
internal network only and this 10001 of course it's if you consider it as IP
address it makes sense but then again I can say it's a binary number 1 0 0 0 1 with
some dots here and there so likewise the same thing I can explain it in many other
ways as well so here we have this uh number as a IPv6 number because it has lots of
digits It is in hexadimal notation. That is why we have this uh a e and f up to f
uh numbers as well because hexadimal numbers we have 16 digits 0 to 9 a b c d e f.
So those are the characters that we have it or the digits we have it in a hexadimal
number and this is these are with the number of characters and digits. You can
assume that these are MAC addresses. Yes, it is in the network interface card and
so on. So this is also rightly so someone mentioned it is the ISBN number for each
and every book to identify them uniquely you have this ISBN numbers and we it start
with 978. So likewise the same details of the data I can interpret it in different
ways. So that's why when I ask what do you think of this? How do we make sense out
of it is with our intelligence. So with our knowledge background understanding
telephone numbers you have used saved and people call you in different numbers. So
you understand okay these are the hotline numbers and so on and so forth. If it is
from a foreign country, they will not understand half of it because some of them
are specific to Sri Lanka and because since it is specific to Sri Lanka, if they
are in the foreign country, they will not know what is our how many digits we have
in a telephone number and so on and so forth. So my ultimate point in explaining
this one is to give you a feel for it. Whenever you see some set of things, you
make sense out of it with your knowledge and the intelligence that you have. So it
might be right or wrong because we are considering this number four as 911. I can
say it as the September 11th. Somebody can say this is a serial number or some kind
of a code number whatever. So it depends on the context. So because of this we need
to be very careful when we read some data or identify some data and if you can make
intelligence out of out of it that's the difference between the data and the
information because if I say these are telephone numbers then you can break it down
and saying okay yes this is a US number and this is the country or the state and so
on and so forth you get lots of information out of it and even the MAC addresses
the first 24 digits are for the bits 24 bits is for the manufacturer. So if it is
manufactured by D company then you have a certain understanding and if it is from a
HP then it will have a different serial number at the first 24 bits of that in
binary it is 48 bits altogether 24 of the manufacturer. So likewise they do have
some kind of a pattern and all of those information you can gather only if you
identify okay this has IP address this as a MAC address and so on otherwise it
could be this could be any numbers random numbers without making any sense out. So
why it is important to know those kind of a thing is with the intelligence only we
can do some valuable work. So this is the next point that I wanted to talk about
how we approach our home security. So at home these are the kind of a things that
you do to protect your home from robbers, thieves, I don't know whoever it is. So,
how many of you have these things installed? Anyone who is having keys and locks
for the doors, front door, gate and grills for your windows, padlocks like this
with different combinations and stuff like that. And this could be some kind of a
shieldings that you have so that the others will not be able to see inside once you
put the curtains in. How many of you have uh CCTV cameras at home? No one. That's
interesting. No one is having CCTV. Yeah, only one two people are raising hands.
Yeah. So at least few of them have CCTV cameras and these are motion sensor lights
where you have a sensor when there is something moving then this light will light
up so that uh you get an understanding okay something is moving in your background
or backyard or somewhere and the valuables you will protect it with a safe and if
you are not sure about your home safe you might put it into a bank safe something
like that and of course on top of it all of these might be considered as technical
stuff then to protect still you might get a say guard door so that you have a
protection in that line as well. So whenever you wanted to do these kind of a thing
um some of them are very basic things you obviously have it like the keys doors and
so on and the for the windows you would have this grills by default most of the
places the curtains but CCTV it's an optional thing it is not mandatory but
everybody is putting up CCTVs as a passion or just to see what is happening around
it because CCTV will protect you. It is only just a deterrent for robbers or
thieves if they try to do some surveillance about your home at what time you are
leaving the home and what time
you're coming back and so on. If a robber is trying to monitor what you do from the
camera, you can monitor it. Unless you see the recording once in a while at least
there is no point in having the CCTV and it will be recording for one or two weeks
time or one or two months time but it will not serve the purpose if you don't have
a take a look at it and sometime of course u as I mentioned it's a deterrent so if
you have a CCTV camera somewhere then anyone would be bit cautious what they do
because they get the feeling Okay, somebody's watching me. So, I need to be say uh
having a good behavior in front of the camera. So, that's the basic idea. So, it's
a deterrent for uh other people to do some damaging things to your house because
they might think okay you that robber or a thieves might get caught because they
have a recording of it. And of course, now the robbers are also smart. So simply
what they do is they put up a cap or a hoodie and mask and or a helmet. They will
come in and do whatever it is. Even though you see a person coming in and doing
some damaging thing, you will not be able to capture it. And also whenever you want
to put this kind of a thing in your home you need to identify few things rather
than just because everybody is putting CCTV I need to put CCTV will not work
properly because you need to have a proper understanding okay from from whom we are
going to protect our systems and the household and so on and of course how much of
effort we need to put into different uh things like do we need to have a very
strong uh iron bars for this grill or if we are looking with say bigger padlocks
will that be enough and should the safe be 1 in thick or 5 in thick and if you are
having a dog should I have one or two or three cuz if one dog is sleeping the other
one might be awake just for the protection. So those are different points that we
need to consider uh when you are putting up these security measures at home. Then
again you need to identify in which area you are in whether in that area there are
lots of robberies happening then you need to put up your defenses very much so you
know okay there are how many I don't know u people who use drugs are very common in
some areas so those might be coming and stealing something that they can take so
that you need to increase your defenses. And in some places the people are very
peaceful and there are no robbers, robberies or unusual activities. So you might
not have to concern it about it very much. So depending on the area where you live,
you have to customize your security level that you need to have. So that is just a
few points to think about because usually what happens is anywhere in anything uh
just because that is the best security thing you just put it up but it might not be
the one that you want to invest in it might be something else. So this is I'm
taking this home security example because we do it intuitively because yeah one
person comes and say okay it is better to have a 1 in thick door or one I don't
know very strong grill or a security uh system to lock up every doors and windows
at the night automatically or something like that. You can spend money and do it
but whether it is really necessary is the concern because you are putting up so
much of security without knowing from what you want to protect and what you need to
protect. So you need to know what are the strengths and weaknesses of the enemy.
That's why it's initially mentioned uh DPRK and so on these hacker groups there are
intelligence services or the police and the cyber intelligence people they try to
analyze these hackers and to see what are their strengths what are the types of
sites or the attack methods they use so that you know what is the strength of the
enemy based on that you can put up your defenses so that's the basic understanding
that we need to So in the recent past if you consider as I mentioned this AI
powered things uh are very much price of AI powered cyber attacks are happening
because as I mentioned AI will be used by us to do the coding much more faster and
efficiently and all that that's definitely us and at the same time the attackers
will use it to generate maybe malicious code malware writing malware it is not a
big deal now because AI tools will automatically write you the code for uh
necessary malware and somebody can say okay no AI tools are programmed or trained
so that it will not create a malware but recently we did some kind of experiment
with some of the tools initially if I say okay I need to create a malware can you
create me a malware it says okay I'm not supposed to do that that's the answer we
get it from the AI I too. But then if I say okay there is a code that I need to
write so that with that code I can it will do this this is activities which are
malicious but we are not saying it is malicious and once you do this we can protect
the citizens of that particular country and know something like that kind of a
story we can tell. So in that case most of the AI tools that our colleagues tried
created the malware without much trouble. So if if someone I mean it is just
tricking the AI tool so that you get what you wanted to do. So that kind of a
things do happen and this increasing sophistication of ransomware and supply chain
attacks. Ransomware attacks of course creating some malicious codes as I mentioned
not that hard in today's context and the supply chain attacks are the attacks where
it happens through sometimes big companies they do have all the security measures
in place so that it is very hard to get into them but if I know that okay they do
get some computers or software developed by another company which is very small
company somewhere then we can target that small company who develops software for
this larger company. So of course when the software is given to them they will
validate verify whether it is right or wrong and accurate and whether there are
vulnerabilities and so on and so forth. But you can break into the smaller company
which might be much more easy and possible and once it is in the in larger company
then you try to uh utilize that code base. So it might not be the definite malware
code that you write it into the first place. Maybe only a part of it. So you hack
into a smaller company, insert some part of the code, then when it goes into the
larger company, then you send the rest of the code which is also not malicious by
the looks of it. Early also the smaller part is not also malicious. So you don't
detect or any detection systems you can evade it and but when both of them are
together it will become really malicious and causing problems. So those kind of a
things are kind of a supply chain attacks that they try different tactics. So in
that case even though you search for vulnerabilities in a system and if it is at
least some suspicious uh codings there which you cannot explain what it is doing
then it is better to kind of a double check it or even do a bit of thorough
analysis whether it is really necessary cuz those are the kind of a weaknesses that
the attackers are using. with the AI powered attacks and the AI powered tools is
much more easy and very fast that they can do that. And of course, geopolitical
cyber nation test attacks are also happening as we discussed earlier with the news
that we see. So with all of these different attacks that are coming up, how do you
put up your defenses? Sometimes one of the biggest challenge is for security when
you put up some things the return on investment like if you develop a software code
say for food ordering like Uber, pick me or whatever when you do the coding you
know okay if I do this coding part and add a new customer or something something
then once it goes into the market you will be getting the benefit of it very
quickly because people will try to use it is much more easy and you can make money
out of it. Then whatever the amount of money that you spend on it, you can recover
it. But for security, you are putting up a firewall appear to be protecting you
from attackers. But what is the benefit you get? You need to justify it by saying
okay we had hundreds attacks we stopped 99 of it one is missing and it hit our
systems and our systems are down. So then everybody asks okay we spend lot of money
put up a firewall but uh it fails to protect our data and even if it protects it
then what's the benefit out of it. So that is where it comes the risk
identification and you need to identify okay if we don't have the firewall our data
might be lost and regulations and the regulator might be saying okay yes you need
to have these kind of a protection mechanism since you don't have it you might have
to pay a fine penalties and so on and so forth and in such situations you put up
these necessary things by the regulations just to we comply for the uh regulatory
maybe from the for a banking sector maybe from the central bank and for the telecom
sector it may be from the TRCSL or the telecommunication regulatory commission and
so and of course sometimes what do you do this u uh defenses how do you put up
these defenses is by the vendor products so Microsoft or crowd strike or so force
any other product might say okay this is the best virus guard. This is how you can
protect your systems. This will detect any unusual traffic pattern of the users and
so on and so forth. So in such situation we don't want it even but then uh the that
is what you can buy it in the market. So you because of them you just install it.
Whether it protects you from the way that you wanted to, it's pretty doubtful
because we are just getting something off the shelf and try to install it in our
mesh. And of course um in different companies you do have different expertise and
different people have and different companies as a organization as a country based
on their understanding their intelligence they
would say okay yes we need to protect our system from this particular type of
attack. So we need to put up a firewall ids intrusion detection system, intrusion
prevention systems and so on and so forth. So this is how we put defenses without
thinking too much and also if there is a incident happens or a data breach happens
because of that we need to do something. So in recent time also like in last March
April time there was a bank data was compromised. So every bank is now very worried
and trying to put up or spending lot of money just because it happens to one one
bank. Of course, there is an uh risk that the other banks also may face something.
But the initial data breach if it was due to a lack of security or lack of say
mishandling of the credentials or something that I mean the reasons for the attack
or the data breach is identified properly then you know okay should I be concerned
about it or should I just ignore the breach that happens to the other bank. Of
course, as I mentioned, they might be targeting you, but at the same time, if your
defenses are much stronger, then you don't have to worry about it. Because if it
was a email that came in and some individual did some stupid thing because of that
if they got breached and if our company or the organization are much more stronger
and they know what it is and they are not falling for that kind of a thing then you
don't have to worry about it. So that's the whole point. So how do we put up our
defenses is guided by mostly of those four points and some other things. Okay, this
happens in other country and we need to put something here and something like that.
Just because it happens somewhere, we need to protect oursel. It's not the way to
for the right way to go forward and going for this kind of approach the first thing
that you need to do is you need to understand what data to protect. First of all,
you need to identify that part. Then you need to identify from whom you are going
to protect your data, your enemies or your competitors and so on and how could
attackers could reach that data. Whatever the data you have, what are the avenues
that it has to come into that and of course not all the data I mean all the data is
important but if you classify them as critical data, confidential data and data
that can go into public and so on then you know okay what are the security level
that you need to put in for these different types of data. So my simple example for
that one is u while I'm was at early employment at Sri Lanka sometimes the
government website get compromised but what they have it on the website is only the
public information like maybe if it is the ministry's website the minister's name
but what are the things that he has done or opened in recent time period and what's
his biography and the political details where he started and where he studied and
all kind of a thing which is public information and if hackers hack into that
website will the hackers still get any additional information or data? No. Because
everything is already public. Everybody knows about it. Then what's the point of
hacking into that is to damage the reputation of that particular ministry or the
department. So it's only a reputational damage. So the data if it is public data
always and if it is what people have taken then I mean it is already available for
them. So if you classify your data saying okay I need to protect this data um very
much or this can be public data and the data classification part comes into play in
that situation and of course um one other concern is uh any organization supposed
to carry out background verification of the employees vendor and contractors. So
even if someone comes near your house and if you need to get some say repair work
done then you need to identify okay uh what is the um person who who is the person
coming in and whether he's a person with good reputation and that repair
technically whether he's capable of doing this repair And if he's at your house and
inside the house then you need to make sure that person is a reliable person not a
malicious person. Because sometimes what happens is this kind of a repair people
they will come and identify where your doors and windows and whether they are
locked or not where the locks are at a night time they might come back to steal
something. So you need to identify with person and only when you have some kind of
a confidence you will let them into the house. So that background verification is a
very important part even in any organization any employee we need to do a
background verification to find out whether he has been involved in previous I
don't know frauds and so on and so forth and how is his previous employment and so
on and whether it is contractor for one or two years time or product vendors and so
on we need to do this background verification properly then only you can get an
idea whether these people will do a proper job and in a reliable responsible
manner. So if you have all of these data and the protection mechanisms and so on
and so forth, then you have a kind of a structured way of protecting your data and
one of the ways to do that is using this kind of a framework which has kind of a
three pillars cyber threat intelligence, testing and evaluation and uh defensive
measures. So of course one thing is what we always try to do is to defend ourself
putting different different uh uh defensive mechanisms putting up a firewall
intrusion detection system username and password for login and so on and so forth.
But then we need to do a testing and evaluation part of it to verify whatever the
defenses we have done is actually
working in that line. whether it is actually serving the purpose that we are put in
place and the other one is the cyber threat intelligence. We need to know who is
going to be my enemies and what are their strengths and weaknesses that I talked
about earlier. So if you know okay these are the type of attackers that might come
in and these are the tools that they use and these are their strengths based on
that we can put up our defenses properly. So these are the three pillars. Cyber
threat intelligence, testing and evaluation. So once you do the testing of your
defenses, if you identify okay my defenses are not good enough, then of course you
need to go back again and put up your defenses and then you go back to the cyber
threat intelligence to identify okay whether these hackers or the attackers have
improved and they are using different tactics and then you do another testing and
evulation of your defenses and then you go back again and try to uh improve your
defenses and go And that's why it is like in a cycle you need to continuously do it
improving step by step so that uh you have a better defense organized and
structured defense rather than just adoptly putting different things as a security
measures. So cyber threat intelligence whenever we need to collect cyber threat
intelligence we need to consider whether we are collecting the right information
the depth of it how much depth I need to know what is the breadth of it and whether
it is relevant for me or breadth means how wide I am thinking about it and the
relevance means say if I'm a bank and if there are so much of hacking incident
going into the electricity board or the ecosystem or thing then if I'm a bank I
might think okay that is not relevant to me because whatever the system I use as a
bank is quite different what the electricity board is used but it will not be
totally irrelevant because if the then if you that is the identification of the
relevance part so if it is depth of it if you identify okay something happens into
the elixity Yes. Okay. We have that info. Whether it is relevant to me initially I
might say okay no it is not because it is electricity system we are bank but if I
identify when you dig deep you identify this attack happened using some kind of a
fishing email to a Windows machine and then that is relevant to me because I'm also
using Windows machines. So if that kind of attack comes into my system I might be
also vulnerable. So I need to put up my defenses. So I have that information to
work around and to see how good or how bad I am doing. And also whenever you
identify this state intelligence, how do I utilize it? Either I put up my defenses
properly or I can just say okay that kind of attack happened and I'm not u
utilizing it up to the level that I'm expect and dissemination of threat reporting.
So whatever the threat intelligence you get you need to report it internally to
different departments or the relevant parties so that they can take action. So
without any political uh ideas what I'm one example is this uh uh Easter Sunday
attack they had the threat intelligence have they had the relevance yes it is
relevant to Sri Lanka so they have to take action have they utilized it don't know
whether they have disseminated it seems that they have said the message to
different places but ultimately we were not able to protect it or protect the
citizen. So where it went wrong, we don't know but still under investigation. But
I'm just giving you the example because we had the information utilization was
poor, dissemination was poor and ultimately the attacker was successful. So that is
why threat intelligence you might have it if you don't utilize it in a proper
manner there is no point collecting that. And of course this threat intelligent can
come in different shapes and form. One is like strategic, tactical, operational and
technical. So strategic mean if you have a threat intelligent feed coming from
somewhere saying okay this kind of a uh high level decision making you need to have
some kind of a information you need to identify okay what are the trends in cyber
threats. So earlier I mentioned rise of AI enabled attacks. So how do I protect
myself? So at the high level you need to take a decision. Okay, we need to put up
some defenses against cyber attacks powered by AI. So it is not a normal firewall
will not be able to sort it out. So what do we need to do? So in a technical level
you need to identify a different thing. So I'll come back to this tactical thing.
or tactical insights, attack techniques, tools and procedures used by the
adversaries or the attackers. So that is another threat in intelligent type of it
tactical information what the strengths of the attacker and what are the uh tools
they use for attacks and this can be there then we can do the analysis and we can
put up our defenses by considering what we have in place right now and how long it
will take to that level and so on. The operational thing also cyber threat
intelligence is important because it's a real-time data thinking okay now there is
attack going on so it might come around to us as well then we need to do some
immediate uh threat uh prevention mechanisms so active campaigns that are going on
right now if you know then we know those are the important things for the
operational activities and also any specific technical data that comes along like
exact vulnerabilities, exact malware, latest exploits and so on also can come
through the threat intelligence. Those uh there are different organization who
carries out this state intelligence and they will feed it to different organization
if it is relevant along with it whether it is relevant whether it is depth of the
information is good enough whether the breadth of the information is good enough
and we can utilize them to protect ourself because we know what is the threat
intelligence that are collected and the defensive measures of course you need to
have the foundational security and the data collection around it. Just because you
have the defenses you can't be complacent saying okay yes everything is there I
don't have to worry about it but you need to collect info and see how it is because
we are trying to do the detection engineering how well we are detecting any
possible data breach that are coming in and the incident response part is the next
as I mentioned detection is only just one part of it we know 100% security is not
guaranteed it at any point. So when something happens, we need to have a plan for
it. So that is the incident response plan and deception operations also should be
there that is also comes under the defensive measures. Uh how many of you have
heard about um honeyotss? Anyone who has heard about honeyotss that is also a kind
of a very much defens or two people raising their hands. So deception honey is a
another kind of a system when the attacker scans our systems our original system is
there and the honeyot is there. So honeypot will if the attacker scans a honeypot
it will send the reply saying okay yes we are the this company and this is our
server IP address and we are running a windows server and so on and so forth. It
will send all the responses to the attacker. So the attacker might think okay this
is the real server that I'm trying to target and he will try to login using
different tools and brute post the passwords or whatever. So when something happens
to into the honeypot as a organization what I have I need to do is to monitor the
honeypot what is happening there. So if I know okay from this particular IP address
there is an attack coming in or possible attack because he's scanning collecting
information trying to login with different usernames and password. So if I know
that information right now then I know okay next time they will come into my
original servers original systems. So how do I protect myself in there? So then you
can put up a say firewall rule saying okay this particular IP address should be
blocked. So deception operation is whenever the attackers go into this kind of a
different um honeypotss you have a maybe one or two hours time worth head start to
identify okay there is an attacker who is trying to use this kind of a tool to
break into our system but you can protect your system by putting up the defenses
properly. So all of these are interrelated and interconnected. So you need to do it
in a proper manner. So then you get to know whether your defenses are up to date,
whether your threat intelligence is up to date and your testing and evaluation part
is properly done. So in the testing and evaluation we need type of testing we need
to decide with uh against what we need to protect I mean what type of a things we
need to do the testing and how frequent we need to do the testing because uh if you
do a security testing today and you can't say okay after 2 3 years down the line if
I do it again it will be okay it is not the case if you are doing some changes into
the coding and updating the features and so so on so forth every month. Security
testing has to be done every month as well. And test planning also needs to be done
because sometimes what happens in some organization when we say okay yes we need to
do a testing they say okay no no we need to go live and we need to do this one very
quickly. You can't do the testing during this time period. So then again it's a
problem because we need to decide how do we plan the testing so that it does not
affect the normal business but we will get enough time and um feedback from them to
fix those vulnerabilities and make sure that our testing is done frequently with
proper frequency rather than doing it every day or every hour because in that case
you will be always testing but no system will go live and of course with the test
execution and the test results we need to identify whether it is good if it is
not then we need to go back and fix our defenses according so that is why I said
the all of these are interconnected and interrelated so when you do one thing good
you need to check with the other one is whether it is good and all of these three
pillars you need to work it in a proper manner in a cohesive manner so that
ultimately your security posture will be improved properly rather than doing it in
ad hoc manner and in conclusion u what I can say is in each industry domain is
facing different cyber threats have a comprehensive approach for information
security. So as I was saying with all of these points so far in different
industries are facing different cyber threat critical infrastructure it is to make
sure there are systems up and running all the time because it can cause lots of
other problems water supply uh electricity and water and electricity are the more
most important thing and also if they have a critical infrastructure for it this um
scattera system for collecting data from remote locations and so on or weather
systems and so on. So those kind of a thing we need to identify. So those will not
be focusing on stealing personally identifiable data and so on but systems have to
be running accurately all the time and defensive mechanism as I was saying have to
be in a proper alignment with the threat intelligence that you get otherwise what
would happen is you will be spending money on different things which are not 100%
necessary and in all of those technical things that you can put in place for
security. Yes, that is good. You have to spend money and everything. But the most
important but the weakest link is the human. If the human is not 100% aware what
can happen, what are the risk involved in it? Downloading pirated software and so
on then um all the technical things that we do might not be worthwhile because it
can cause lots of other problem because we link the human. So those are the kind of
a overall idea that I wanted to uh talk about. So if you have any questions uh I'm
happy to answer. Um just if you have any questions just feel free to ask and any
points that you want to clarify or additionally if I have not covered because
insecurity is not a very simple thing. It can go up to hours explaining this but
I'm just trying to give you a understanding whatever the defenses you think of
think of what are the attackers would do and what are their strengths based on that
you try to put up the defenses rather than doing it blindly so you know actually
why you are doing each of these you can justify it and you can protect yourself
much better I mean the enemy any specific thing that you wanted to ask. I want to
ask anything. Anyone who wants to give me an answer for this kind of a question.
Um, how many of you are using any AI tools and check whether these are providing
correct answers or any thoughts on that? anyone who has done some experiment with
AI tools and so on. Roshan, what's your take on you know this AI and uh uh like uh
AI and you know with this quantum computing and all that the impact on security
cyber security AI agent agentic software and uh you know the increasing computing
power like uh quantum computing yeah with the AI also it is still at I don't know
we can't say at still early stage but still people are wondering what could happen
and what are the impact of it as I was saying earlier also AI tools still people
believe uh to what we can use this AI for and whether it will be giving us good
advantages yes it gives but whether it violates our privacy and whatever the output
that we get out of the AI tools the explaining it and providing some kind of a
feedback on it is also challenging. So that what they call it as explanability of
the AI tools because if we make a decision we can justify okay because of these
reasons we put this decision but AI tool will just give us a result but uh their
justification might not be 100% right. So as I mentioned earlier, we did some kind
of experiment with these different tools and ask them to create a malware. So if I
ask it directly uh it says okay no I cannot write a malware it is harmful and so
on. But if I say in a different way saying okay if you can write a code to do this
these activities and that will protect the human life or something then the AI tool
will think okay this is a real valuable thing that I need to create. So it will
create that code for me. So likewise it is there are lots of things that we can use
for and at the same time for the AI they use what do you call it as this guard
rails the initial tool or the AI model will give you the answers but on top of it
or the side of it you will have a guardrail to protect it for security. So whatever
the prompts that are coming in it will do a validation whether it has some
malicious content or the idea if so it will not come into the AI model and train it
in a wrong way. So that kind of a mechanisms are there as you mentioned sir it is
like AI related compliances and so on still on the way I would say uh standards and
how to use it and how not to use it or what it can be used and so on. So one other
thing that came to my mind when we talk about this different attacks that happens
from different uh countries like Russia and Ukraine and so on. Now like for a
normal physical war we do have some guidelines saying okay when you fight you
should not be targeting hospitals and schools and so on like in a normal physical
war. Similarly with ICRC they have put up some regulations. If you are fighting a
country on a cyber war you should not be targeting critical infrastructure
hospitals children's places schools and so on. So like in a
normal uh war now they do have a ICRC guidelines and the regula not the regulation
some guidelines how is everybody signed to that? It is a guideline. It's I haven't
seen it as a mandatory thing but it will be coming up. What they are saying is one
of the key point they highlighting even if the enemy is not following this
everybody should follow it. So that if you are not following it then the but the
world will support you or they will be against you because you are not following
the best practices kind of a thing. No, but but the issue is now the individuals
also can I mean other day somebody demonstrated a a drone uh that if it is
programmed to identify a person and shoot him in a large crowd it will
automatically yeah but I mean like I mean how how do we we are talking about
security right uh Yeah, I think it is and also with the drones what has happened
earlier somebody has to control it. Now with the AI tools we don't have to control
it because if you are using it a remote control then you can use a signal jammer
and it will stop. But now with the AI tool the drone will fly it by itself. No one
has to control it because it is already programmed and signal jammers will not be
able to stop it as well. Exactly. Yes, it's another step ahead of that and as you
mentioned sir it's very tricky I mean if it says okay go and shoot this person and
photograph you go and do the damaging thing that's why usually the drones are you
need to get permission to run it and so on that kind of a rules are there so at
least the people who try to do it as a fun activity will not do it only the real
person will do it and hopefully there will some things coming up out of it as well.
No, but I mean even even bringing you know the regulations, safety regulations on
AI and everything related to it is coming very slow. No, I mean far too fast. I
think it is something like a data protection act and so on because we need to have
some statistic to say okay yes it is being used for malicious activity that is why
we need to have this law otherwise just predicting okay this might happen and
putting up a law might not be worthwhile because it takes time by the time the law
comes in people might be resorting to different things to be done in the cyber
world which might be again you need to do a revision no the other other risk is
selfarning AI that is another risk. No the AGI general intelligence if it acquires
then then none of these cyber security measures will work. No work. Yeah that's I
mean I think sometime back I one of the presentations I mentioned that also the AI
tools are used for cyber defense and also for the cyber attack. So maybe in few
years down the line I professionals will be in a different state of mind and only
the AI will fight with AI and which one is fast learning fast and adapting fast
will survive. So that's the kind of thing that we can think of it because people
will not get involved in it. It's automatically trained and automatically learning
and auto autonomous systems. So they might fight each other and we might be sitting
back and enjoying what is happening. That could be the scenario. Anybody else has
any questions? You know it's earlier also in the slides also when I ask questions
they did answer. So it's a good interactive session rather than just me talking
about all the time they participated. Maybe if they have any questions they can
I'll share the slide deck as well with you sir. So you can share with the students
as well. Ah yes, please send it to me. I'll do that. Guys, if you have any any
security related questions, ask from because he's one of the top guys in Sri Lanka
on cyber security, you know, one who knows how to audit and all that. No questions.
Then Roshan, thanks again. You know, I mean this has been a wonderful lecture. you
know I also learned a part and thank you sir things are happening and hopefully uh
our our students also will realize you know how important the cyber security is
when when they do it's not right in code only you know you have to make sure that
they are safe they are secure uh put an extra effort to make them sure that they
are secure I think very recently the commercial bank was attacked right fishing
fact 600 million or something lost or something yeah I mean it's not only yeah
social engineering as I mentioned the human is the weakest link so if they target
the human and they don't expect that they will be targeted so if you know that okay
you can be targeted then they have to take some action against it so that's a
simple thing simple in the sense like everybody has to be aware of it and then then
only it can be protected otherwise it's can can you bypass the OTP a hacker can can
they bypass the OTP not directly what they do is they just call them up and say
okay we have we are calling from the bank we have shared it and can you share it
with me because we wanted to verify whether this is really you or something like
that it is also social without going through that step I mean I also got a couple
of calls like that but I I I knew about it but I mean like without doing that can
they can is there any way to bypass? No only thing is they can if they have the SIM
card obtained for the same number sometimes two SIM cards can be available. So it
it is another step ahead that they can do it and if the number is much much closer
to the uh tower then it might get delivered to that scene. So in that case you
might miss it. that is a possibility. Okay. Uh other than that usually the the most
of the fishing attacks why the banks were unable to stop it is because legitimate
username and password were used and also the OTP was legitimately used. So in that
case from the bank side if they look at the system the genuine user is logging in.
So they will allow the money trans and everything but what has happened is their
username and password was compromised and somebody is calling the genuine user
asking for the OTP that's why all of the time now I have seen it in all of the most
of the bank or I would say all the bank that I'm working with or I'm backing with
all the calls and even when you logging into the online portal so they send a
message saying okay don't share OTP with anybody even though when we The OTP being
in technical field we understand it but for a normal average business person or a
household house or somebody they will not understand what is OTP and what's the
importance of it. So only the education and the awareness is the best thing to
protect ourself from those kind of attacks. Okay, Roshan, thank you. Thank you.
Thank you so much. You know, I mean, it was it has been very very informative and I
I hope that you keep on helping Open University in the future as well. Yeah, sure
sir. Sure. Thank you very much for giving me this opportunity to talk to those
students and get it. Yeah. Thank you very much. Because this is one of the key
areas I think that of importance. Yeah. Yeah. Exactly. So, thank you very much.
Yeah. Thank you very much everybody. Good night. Uh good night to all. Hope you
enjoyed the lecture. Good night. Thank you. Thanks.