{"id":66884,"date":"2017-11-04T00:39:08","date_gmt":"2017-11-03T16:39:08","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/cooleys-sabett-data-security-laws-ai-and-cyber-threats\/"},"modified":"2017-11-04T00:39:08","modified_gmt":"2017-11-03T16:39:08","slug":"cooleys-sabett-data-security-laws-ai-and-cyber-threats","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/cooleys-sabett-data-security-laws-ai-and-cyber-threats\/","title":{"rendered":"Cooley\u2019s Sabett: Data Security Laws, AI and Cyber Threats"},"content":{"rendered":"<p>As an attorney and former crypto engineer, Randy Sabett approaches cybersecurity from both a legal and technical standpoint in his role at <strong>Cooley LLP<\/strong>. Sabett will participate in a panel called \u201cNew Generation of Cyberattacks: Assessment of the Evolving Threat Landscape in Satellite and Aerospace\u201d at the 2017 CyberSat Summit on Nov. 7. Here, he breaks down some of the major cybersecurity threats facing satellite and other industries, and highlights how data security laws must evolve to address them.<\/p>\n<p><strong><em>VIA SATELLITE:<\/em> Do you have an example of a hack or cybersecurity breach that exemplifies the vulnerabilities that must be addressed?<\/strong><\/p>\n<p><strong>Sabett:<\/strong> No matter how good the security is, if there is something connected to the internet and you have vulnerabilities, the attackers are going to find their way in one way or another. Stuxnet is a good example of that. I think Stuxnet resembles the kinds of things the satellite industry would have to worry about, because Stuxnet was penetration of what\u2019s called an air-gapped network. That was a system that wasn\u2019t connected to the internet and an attack was still carried out on those devices. The way they carried it out was by a USB drive that they were able to entice someone to insert into a machine that\u2019s inside this air-gapped network, and that delivered the payload that eventually brought down the machines. So, the point in giving you that example is that even something that is not connected to the internet can be attacked if there\u2019s a way in.<\/p>\n<p>I think the important thing to take away is that the technology is only part of it. There are other pieces to the security picture: \u201cpeople, processes and technology\u201d is a common phrase. No doubt you\u2019ve got to have good security technology. But the people are important as well. Look at Stuxnet; if that person had been better trained, perhaps the attack wouldn\u2019t have happened.<\/p>\n<\/p>\n<figure id=\"attachment_271291\" aria-describedby=\"caption-attachment-271291\" style=\"width: 291px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-271291\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2017\/11\/sabett-randy-10924-web-291x300.jpg\" alt=\"Randy Sabett, vice chair of Cooley\u2019s privacy &amp; data protection practice group. Photo: Cooley.\" width=\"291\" height=\"300\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2017\/11\/sabett-randy-10924-web-291x300.jpg 291w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2017\/11\/sabett-randy-10924-web-485x500.jpg 485w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2017\/11\/sabett-randy-10924-web-194x200.jpg 194w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2017\/11\/sabett-randy-10924-web.jpg 700w\" sizes=\"(max-width: 291px) 100vw, 291px\"><figcaption id=\"caption-attachment-271291\" class=\"wp-caption-text\">Randy Sabett, vice chair of Cooley\u2019s privacy &amp; data protection practice group. Photo: Cooley.<\/figcaption><\/figure>\n<\/p>\n<p><strong><em>VIA SATELLITE:<\/em><\/strong> <strong>What do you think is the biggest threat in the cybersecurity landscape? Is there any one technology or capability you\u2019re most worried about?<\/strong><\/p>\n<p><strong>Sabett:<\/strong> In the business world, the biggest issue right now is something called business email compromise. It is the number one threat according to the <strong>FBI<\/strong>. This could be indirectly a threat in the satellite landscape.<\/p>\n<p>Let\u2019s use \u201cAcme Corp.\u201d [as a hypothetical example]. They work off to the side with some network optimization company [that is] not necessarily totally security focused. The attackers have done their research \u2014 perhaps there\u2019s a whole bunch of social media vectors that can be used to find out information about Acme. They find out the names and email addresses of several employees, then use the compromised system of the service provider to send emails to somebody or multiple people inside Acme Corp. The email might say, \u201cClick here to get the documents you need,\u201d and to enter your credentials here. The Acme employee(s), trusting the email that has come from the service provider, enter their username and password and at that point the attacker is in. You can just imagine what could happen from there.<\/p>\n<table style=\"border: 10px solid #99a3a3; width: 100%; border-width: 2px; border-color: #dddddd;\" cellspacing=\"15\" cellpadding=\"15\" align=\"center\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"> Don\u2019t miss our <strong>CyberSat Summit <\/strong>on Tuesday, Nov. 7 and Wednesday, Nov. 8 in Tysons Corner, VA, where leading experts on cybersecurity will share the best practices for achieving end-to-end protection within the satellite ecosystem. Register now! <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><em>VIA SATELLITE:<\/em><\/strong> <strong>So, what are the potential implications for the satellite industry?<\/strong><\/p>\n<p><strong>Sabett:<\/strong> In the satellite scenario, the accessibility to the satellite network to be used for launching an attack might be more of an issue for the attacker. But if an attacker were to get in, they now have a significantly more concentrated type of attack target. What if they were to shut down the GPS system? What if somebody shut down a significant internet pipe that transmits lots of bits from one location to another? What if somebody shut down a significant number of phone lines? It\u2019s much different than breaking into a network and shutting down a couple hundred machines. We\u2019re talking about a device with much greater throughput, and therefore if you take it down, it will have much more significant effects.<\/p>\n<p><strong><em>[contextly_sidebar id=\u201dt48c6utFVWY5dnL1df6oeIvGlzmyoAA4\u2033]VIA SATELLITE:<\/em><\/strong> <strong>Where does Artificial Intelligence (AI) and machine learning fit into the cybersecurity ecosystem?<\/strong><\/p>\n<p><strong>Sabett:<\/strong> First of all, AI can be useful for certain things but it\u2019s not a panacea for all security problems. I prefer the phrase \u201cmachine learning\u201d because a lot of the applications from a cybersecurity perspective are not AI in the traditional sense. It\u2019s more the process of looking at patterns, detecting things that deviate from those patterns, and then alerting someone to it \u2014 and doing all of that in a way that\u2019s much faster than current technology. Technologies such as firewalls might not catch certain indicia of attack \u2014 machine learning, assuming it has learned enough about your network, might be able to detect it. To summarize, machine learning is going to be useful as an augmentation to other cybersecurity technology; it\u2019s not going to displace it.<\/p>\n<p>You flip the coin over, however, and then realize that attackers are just as likely to use machine learning to figure out ways to avoid the types of defenses that you have. It\u2019s a constant cat-and-mouse game but the expectation is that it\u2019s not just going to be the good guys using machine learning.<\/p>\n<p><strong><em>VIA SATELLITE:<\/em><\/strong> <strong>How do you see data security laws in the U.S. changing over the next few years?<\/strong><\/p>\n<p><strong>Sabett:<\/strong> Generally speaking, cybersecurity is a horizontal concept. It cuts across all different kinds of businesses. Even a mom-and-pop shop, whether it\u2019s restaurant or a little corner store, if they have a computer that is connected to the internet to do their books or file their taxes, they need to pay attention to cybersecurity. If they don\u2019t, they could be turned into a small part of a bigger attack being launched by, as one example, what are called \u201cbot herders.\u201d That can happen with big companies too.<\/p>\n<p>The difficulty with legislation is that if you\u2019ve got this horizontal concept, how do you legislate in one fell swoop across all these business verticals? No one has figured out how to do that.<\/p>\n<p>One thing that did come out of the prior administration is something called the NIST Cybersecurity Framework. It started out solely focused on critical infrastructure, which arguably satellites would be a part of, but its use has expanded out beyond critical infrastructure. I think the difficulty, though, is taking something like that and trying to turn it into something that is legislative.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As an attorney and former crypto engineer, Randy Sabett approaches cybersecurity from both a legal and technical standpoint in his role at Cooley LLP. Sabett will participate in a panel called \u201cNew Generation of Cyberattacks: Assessment of the Evolving Threat Landscape in Satellite and Aerospace\u201d at the 2017 CyberSat Summit on Nov. 7. Here, he [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":66887,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-66884","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66884"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=66884"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66884\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/66887"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=66884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=66884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=66884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}