SlideShare une entreprise Scribd logo
1  sur  18
Issue Date:
Revision:
Enhancing Security
Incident Response
Capabilities in the Asia
Pacific Region
6th APT Cybersecurity Forum
Adli Wahid
Security Specialist, APNIC
Agenda
1. About APNIC
2. Enhancing Incident Response
Capabilities
3. Recent and future activities
2
About APNIC
3
What is APNIC?
• Regional Internet Registry (RIR) for the
Asia Pacific region
– Comprises 56 economies
• Secretariat located in Brisbane,
Australia
– Currently employs around 70 staff
• Not-for-profit, membership-based
organization
• Governed by the Executive Council
(EC), who are elected by the Members
4
APNIC’s Vision:
A global, open, stable, and secure Internet that
serves the entire Asia Pacific community.
How we achieve this:
• Serving Members
• Supporting the Asia Pacific Region
• Collaborating with the Internet Community
5
Enhancing Incident
Response Capabilities in the
AP Region
6
Responding to Security Incidents
7
National Cyber
Security Agency
National CERT /
CSIRTs
Enterprise
CERTs/CSIRTs
End-Users
Critical Infrastructure, Network Providers, Hosting,
Cloud, Government, Financial Services, SMEs=
Network Operators / Service
Providers
• A key player in the Incident Response process
• Availability is important
– Critical Infrastructure (Internet Exchange)
– Increasing becoming a target
• Need to be aware of the (changing) threat landscape
– Help increase resilience the infrastructure by applying best practices
– Provide timely assistance & mitigation
– Emerging Trends - IOTs
– CERT/CSIRT of the last resort
• Network Operators Groups (NOGs)
– Local & Regional NOGs
– APRICOT & APNIC Conference
8
Network Operators – Incident
Response Relationship
• Interdependent entities
• Expectations
– Resources are not misused or
abused
– Fast ‘take-downs’ or response
– Share information (logs, billing etc)
– Communicate with Users /
Technical support
– 24x7x365
• Frequently, at the receiving end
9
Network
Operator
End-Users Customers
Security
Response
Community
Law
Enforcement
Incident Response Capabilities
• Managing Security Incidents
– Reduce impact of security incidents
– Prevent security incident from occurring
– Fixing actual vulnerabilities
– Gain insights about emerging threats or incidents (ISACs,
threat intel feeds)
– Collaborate with other stakeholders (i.e. investigation,
policy/strategy)
• Managing Security Incident Response Teams
– Establishing CSIRTs
– Operationalizing CSIRTs
– Having the right skill sets, knowledge and tools
– Being part of the community
– Mentoring
10
APNIC’s Approach
• Capacity development
– Internet infrastructure
– Cyber security*
• Strategic Partnership
– Various stakeholders
– Regional & global
– Shared goals
11
Security Outreach
12
Craig Ng
Promoting security best
practices in the
APNIC community
NOGs, CSIRTS and LEA
events
PK, CN, HK, KR, JP, PH
SG, MY, ID, AU, TW
Collaboration with JICA
and KISA to deliver
regional CERT training
Geoff Huston member of
ICANN SSAC
Adli Wahid member of
FIRST Board
MoU with APCERT
Interpol Global Cyber
Crime Group
Adli Wahid
www.apnic.net/security
CSIRT Best Practice Forum
• IGF 2014 & 2015
– Best Practice Forum on Establishing and Supporting
Computer Security Incident Response Teams (CSIRT) for
Internet Security
• Multistakeholder approach
• Addresses key concerns of establishing & setting up
a CSIRTs
– Key success factors
– Costs & capacity building
– Stakeholder engagement
– Opportunities & challenges
• Call for Comments
– http://intgovforum.org/cms/best-practice-forums/2-
establishing-and-supporting-csirts
13
Upcoming Activities
• Support for regional activities
– FIRST & IDSIRTII TC (October)
– FIRST & KRCERT/CC TC (November)
– Interpol Global Cyber Crime Meeting (December)
– APRICOT 2016 in Auckland (February)
• eLearning & Training
– https://training.apnic.net
• Follow us for the latest updates
– Blog https://blog.apnic.net
– Twitter @apnic
Resource Public Key Infrastructure (RPKI)
15
RPKI presentations to
NOGs and conferences
‘Ready to ROA’ Campaign
– hands-on sessions to
help Members create
ROAs
Shirts, stickers, web
content to promote
campaign
Regional RPKI adoption
has more than doubled in
past year - 0.82% to 1.92%
and rising
www.apnic.net/roa
• 10 face-to-face and eLearning RPKI training
courses delivered
• Offline simulation of production system
• Create and revoke ROAs, observe changes to
routing state in lab
Internet Operational Research Grants
16
New fund supporting the Internet research
community in the Asia Pacific
Research aiming to improve availability,
reliability, and security of the Internet in the
Asia Pacific
Network
measurement
and analysis
IPv6 deployment BGP Routing
Network
Security
Conclusion
• Capacity development is
fundamental & critical
• Approach must be flexible and
scalable
• Plenty of challenges &
opportunities
• Let’s collaborate!
17
Thank You
Adli Wahid
www.apnic.net
adli@apnic.net
18

Contenu connexe

Tendances

Tendances (20)

An introduction to APNIC
An introduction to APNICAn introduction to APNIC
An introduction to APNIC
 
PNG IXP Inauguration: APNIC Update
PNG IXP Inauguration: APNIC UpdatePNG IXP Inauguration: APNIC Update
PNG IXP Inauguration: APNIC Update
 
IPv6 in Vietnam + APNIC Update
IPv6 in Vietnam + APNIC UpdateIPv6 in Vietnam + APNIC Update
IPv6 in Vietnam + APNIC Update
 
AFRINIC 26/AIS 2017: APNIC Update
AFRINIC 26/AIS 2017: APNIC UpdateAFRINIC 26/AIS 2017: APNIC Update
AFRINIC 26/AIS 2017: APNIC Update
 
Apnic update-btnog1-sc
Apnic update-btnog1-scApnic update-btnog1-sc
Apnic update-btnog1-sc
 
NTT-CERT Activities by Yoshiki Sugiura [APRICOT 2015]
NTT-CERT Activities by Yoshiki Sugiura [APRICOT 2015]NTT-CERT Activities by Yoshiki Sugiura [APRICOT 2015]
NTT-CERT Activities by Yoshiki Sugiura [APRICOT 2015]
 
WHOIS Database for Incident Response & Handling
WHOIS Database for Incident Response & HandlingWHOIS Database for Incident Response & Handling
WHOIS Database for Incident Response & Handling
 
APNIC Update, APTLD 70
APNIC Update, APTLD 70APNIC Update, APTLD 70
APNIC Update, APTLD 70
 
ARM 7: ROA session
ARM 7: ROA sessionARM 7: ROA session
ARM 7: ROA session
 
APNIC Update, NPNOG 0.5
APNIC Update, NPNOG 0.5APNIC Update, NPNOG 0.5
APNIC Update, NPNOG 0.5
 
IPv6 Adoption by ASEAN Government Agencies
IPv6 Adoption by ASEAN Government AgenciesIPv6 Adoption by ASEAN Government Agencies
IPv6 Adoption by ASEAN Government Agencies
 
AFRINIC 24 - APNIC Update
AFRINIC 24 - APNIC UpdateAFRINIC 24 - APNIC Update
AFRINIC 24 - APNIC Update
 
Collective responsibility for security and resilience of the global routing s...
Collective responsibility for security and resilience of the global routing s...Collective responsibility for security and resilience of the global routing s...
Collective responsibility for security and resilience of the global routing s...
 
IDNIC OPM 2017: APNIC Update
IDNIC OPM 2017: APNIC UpdateIDNIC OPM 2017: APNIC Update
IDNIC OPM 2017: APNIC Update
 
Internet number resources - what's new?
Internet number resources - what's new?Internet number resources - what's new?
Internet number resources - what's new?
 
MMNOG: Internet infrastructure comparisons in the Asia Pacific
MMNOG: Internet infrastructure comparisons in the Asia Pacific MMNOG: Internet infrastructure comparisons in the Asia Pacific
MMNOG: Internet infrastructure comparisons in the Asia Pacific
 
Government Policy and IPv6 Adoption
Government Policy and IPv6 AdoptionGovernment Policy and IPv6 Adoption
Government Policy and IPv6 Adoption
 
IPv6 Update
IPv6 UpdateIPv6 Update
IPv6 Update
 
Global IPv6 Summit Presentation - Global Deployment or Digital Divide
Global IPv6 Summit Presentation - Global Deployment or Digital DivideGlobal IPv6 Summit Presentation - Global Deployment or Digital Divide
Global IPv6 Summit Presentation - Global Deployment or Digital Divide
 
APNIC Update - PacNOG20
APNIC Update - PacNOG20APNIC Update - PacNOG20
APNIC Update - PacNOG20
 

En vedette

En vedette (13)

APNIC Outreach Activities in Cyber Security
APNIC Outreach Activities in Cyber Security APNIC Outreach Activities in Cyber Security
APNIC Outreach Activities in Cyber Security
 
International Collaboration for Regional Cybersecurity Risk, by Yurie Ito [AP...
International Collaboration for Regional Cybersecurity Risk, by Yurie Ito [AP...International Collaboration for Regional Cybersecurity Risk, by Yurie Ito [AP...
International Collaboration for Regional Cybersecurity Risk, by Yurie Ito [AP...
 
Introduction to CSIRTs
Introduction to CSIRTsIntroduction to CSIRTs
Introduction to CSIRTs
 
APNIC's role in stability and security - 4th APT Cybersecurity Forum
APNIC's role in stability and security - 4th APT Cybersecurity ForumAPNIC's role in stability and security - 4th APT Cybersecurity Forum
APNIC's role in stability and security - 4th APT Cybersecurity Forum
 
Whois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcWhois - Addressing the Asia Pacifc
Whois - Addressing the Asia Pacifc
 
2016 Cybersecurity Predictions for Asia Pacific from Palo Alto Networks VP, C...
2016 Cybersecurity Predictions for Asia Pacific from Palo Alto Networks VP, C...2016 Cybersecurity Predictions for Asia Pacific from Palo Alto Networks VP, C...
2016 Cybersecurity Predictions for Asia Pacific from Palo Alto Networks VP, C...
 
Cyber Threat Intelligence: What do we Want? The Incident Response and Technol...
Cyber Threat Intelligence: What do we Want? The Incident Response and Technol...Cyber Threat Intelligence: What do we Want? The Incident Response and Technol...
Cyber Threat Intelligence: What do we Want? The Incident Response and Technol...
 
Pactera - Cloud, Application, Cyber Security Trend 2016
Pactera - Cloud, Application, Cyber Security Trend 2016Pactera - Cloud, Application, Cyber Security Trend 2016
Pactera - Cloud, Application, Cyber Security Trend 2016
 
Cyber Security Landscape and Systems Resiliency – Challenges & Priorities - T...
Cyber Security Landscape and Systems Resiliency – Challenges & Priorities - T...Cyber Security Landscape and Systems Resiliency – Challenges & Priorities - T...
Cyber Security Landscape and Systems Resiliency – Challenges & Priorities - T...
 
Ht seminar uniten-cyber security threat landscape
Ht seminar uniten-cyber security threat landscapeHt seminar uniten-cyber security threat landscape
Ht seminar uniten-cyber security threat landscape
 
Tools and methods used in cybercrime
Tools and methods used in cybercrimeTools and methods used in cybercrime
Tools and methods used in cybercrime
 
Outlook Briefing 2016: Cyber Security
Outlook Briefing 2016: Cyber SecurityOutlook Briefing 2016: Cyber Security
Outlook Briefing 2016: Cyber Security
 
Cyberthreat Defense Report 2017 by Impreva
Cyberthreat Defense Report 2017 by ImprevaCyberthreat Defense Report 2017 by Impreva
Cyberthreat Defense Report 2017 by Impreva
 

Similaire à Enhancing security incident response capabilities in the AP

Similaire à Enhancing security incident response capabilities in the AP (20)

Cyber Security Regional Forum: APNIC's cybersecurity work in the Pacific
Cyber Security Regional Forum: APNIC's cybersecurity work in the PacificCyber Security Regional Forum: APNIC's cybersecurity work in the Pacific
Cyber Security Regional Forum: APNIC's cybersecurity work in the Pacific
 
APEC TEL 63: Building cyber resilience - Internet of communities
APEC TEL 63: Building cyber resilience - Internet of communitiesAPEC TEL 63: Building cyber resilience - Internet of communities
APEC TEL 63: Building cyber resilience - Internet of communities
 
Cyber Security Week 2015: Get involved and contribute
Cyber Security Week 2015: Get involved and contributeCyber Security Week 2015: Get involved and contribute
Cyber Security Week 2015: Get involved and contribute
 
Engage with The Internet Society
Engage with The Internet SocietyEngage with The Internet Society
Engage with The Internet Society
 
inSIG 2021: APNIC and APrIGF
inSIG 2021: APNIC and APrIGFinSIG 2021: APNIC and APrIGF
inSIG 2021: APNIC and APrIGF
 
Scaling Global Internet - 13th APT Policy and Regulatory Forum
Scaling Global Internet - 13th APT Policy and Regulatory ForumScaling Global Internet - 13th APT Policy and Regulatory Forum
Scaling Global Internet - 13th APT Policy and Regulatory Forum
 
APCERT Updates
APCERT UpdatesAPCERT Updates
APCERT Updates
 
APNIC Policy Webinar
APNIC Policy Webinar APNIC Policy Webinar
APNIC Policy Webinar
 
APAN 44: Security outreach at APNIC
APAN 44: Security outreach at APNICAPAN 44: Security outreach at APNIC
APAN 44: Security outreach at APNIC
 
APEC TEL 62: APNIC Security Engagement Activities
APEC TEL 62: APNIC Security Engagement ActivitiesAPEC TEL 62: APNIC Security Engagement Activities
APEC TEL 62: APNIC Security Engagement Activities
 
PITA 22: Addressing interconnection and security in the Pacific
PITA 22: Addressing interconnection and security in the PacificPITA 22: Addressing interconnection and security in the Pacific
PITA 22: Addressing interconnection and security in the Pacific
 
PacNOG 18/APNIC Regional Meeting, Guam: APNIC Activities Update
PacNOG 18/APNIC Regional Meeting, Guam: APNIC Activities UpdatePacNOG 18/APNIC Regional Meeting, Guam: APNIC Activities Update
PacNOG 18/APNIC Regional Meeting, Guam: APNIC Activities Update
 
Support for IP-based infrastrucutre development - Preparatory Meeting of Conn...
Support for IP-based infrastrucutre development - Preparatory Meeting of Conn...Support for IP-based infrastrucutre development - Preparatory Meeting of Conn...
Support for IP-based infrastrucutre development - Preparatory Meeting of Conn...
 
Isoc Chennai Seminar Open Internet Policies For Business
Isoc Chennai Seminar Open Internet Policies For BusinessIsoc Chennai Seminar Open Internet Policies For Business
Isoc Chennai Seminar Open Internet Policies For Business
 
ISOC Engagement Activities
ISOC Engagement ActivitiesISOC Engagement Activities
ISOC Engagement Activities
 
09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono
 
Introducing APNIC
Introducing APNICIntroducing APNIC
Introducing APNIC
 
APNIC update PNG IXP Inauguration
APNIC update PNG IXP InaugurationAPNIC update PNG IXP Inauguration
APNIC update PNG IXP Inauguration
 
AIS19 Newcomers Session (EN)
AIS19 Newcomers Session (EN)AIS19 Newcomers Session (EN)
AIS19 Newcomers Session (EN)
 
ION Costa Rica Opening Slides
ION Costa Rica Opening SlidesION Costa Rica Opening Slides
ION Costa Rica Opening Slides
 

Plus de APNIC

Plus de APNIC (20)

APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff Huston
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet development
 

Dernier

VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
dharasingh5698
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
nilamkumrai
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
nirzagarg
 

Dernier (20)

Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
 
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrStory Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
 

Enhancing security incident response capabilities in the AP

  • 1. Issue Date: Revision: Enhancing Security Incident Response Capabilities in the Asia Pacific Region 6th APT Cybersecurity Forum Adli Wahid Security Specialist, APNIC
  • 2. Agenda 1. About APNIC 2. Enhancing Incident Response Capabilities 3. Recent and future activities 2
  • 4. What is APNIC? • Regional Internet Registry (RIR) for the Asia Pacific region – Comprises 56 economies • Secretariat located in Brisbane, Australia – Currently employs around 70 staff • Not-for-profit, membership-based organization • Governed by the Executive Council (EC), who are elected by the Members 4
  • 5. APNIC’s Vision: A global, open, stable, and secure Internet that serves the entire Asia Pacific community. How we achieve this: • Serving Members • Supporting the Asia Pacific Region • Collaborating with the Internet Community 5
  • 7. Responding to Security Incidents 7 National Cyber Security Agency National CERT / CSIRTs Enterprise CERTs/CSIRTs End-Users Critical Infrastructure, Network Providers, Hosting, Cloud, Government, Financial Services, SMEs=
  • 8. Network Operators / Service Providers • A key player in the Incident Response process • Availability is important – Critical Infrastructure (Internet Exchange) – Increasing becoming a target • Need to be aware of the (changing) threat landscape – Help increase resilience the infrastructure by applying best practices – Provide timely assistance & mitigation – Emerging Trends - IOTs – CERT/CSIRT of the last resort • Network Operators Groups (NOGs) – Local & Regional NOGs – APRICOT & APNIC Conference 8
  • 9. Network Operators – Incident Response Relationship • Interdependent entities • Expectations – Resources are not misused or abused – Fast ‘take-downs’ or response – Share information (logs, billing etc) – Communicate with Users / Technical support – 24x7x365 • Frequently, at the receiving end 9 Network Operator End-Users Customers Security Response Community Law Enforcement
  • 10. Incident Response Capabilities • Managing Security Incidents – Reduce impact of security incidents – Prevent security incident from occurring – Fixing actual vulnerabilities – Gain insights about emerging threats or incidents (ISACs, threat intel feeds) – Collaborate with other stakeholders (i.e. investigation, policy/strategy) • Managing Security Incident Response Teams – Establishing CSIRTs – Operationalizing CSIRTs – Having the right skill sets, knowledge and tools – Being part of the community – Mentoring 10
  • 11. APNIC’s Approach • Capacity development – Internet infrastructure – Cyber security* • Strategic Partnership – Various stakeholders – Regional & global – Shared goals 11
  • 12. Security Outreach 12 Craig Ng Promoting security best practices in the APNIC community NOGs, CSIRTS and LEA events PK, CN, HK, KR, JP, PH SG, MY, ID, AU, TW Collaboration with JICA and KISA to deliver regional CERT training Geoff Huston member of ICANN SSAC Adli Wahid member of FIRST Board MoU with APCERT Interpol Global Cyber Crime Group Adli Wahid www.apnic.net/security
  • 13. CSIRT Best Practice Forum • IGF 2014 & 2015 – Best Practice Forum on Establishing and Supporting Computer Security Incident Response Teams (CSIRT) for Internet Security • Multistakeholder approach • Addresses key concerns of establishing & setting up a CSIRTs – Key success factors – Costs & capacity building – Stakeholder engagement – Opportunities & challenges • Call for Comments – http://intgovforum.org/cms/best-practice-forums/2- establishing-and-supporting-csirts 13
  • 14. Upcoming Activities • Support for regional activities – FIRST & IDSIRTII TC (October) – FIRST & KRCERT/CC TC (November) – Interpol Global Cyber Crime Meeting (December) – APRICOT 2016 in Auckland (February) • eLearning & Training – https://training.apnic.net • Follow us for the latest updates – Blog https://blog.apnic.net – Twitter @apnic
  • 15. Resource Public Key Infrastructure (RPKI) 15 RPKI presentations to NOGs and conferences ‘Ready to ROA’ Campaign – hands-on sessions to help Members create ROAs Shirts, stickers, web content to promote campaign Regional RPKI adoption has more than doubled in past year - 0.82% to 1.92% and rising www.apnic.net/roa • 10 face-to-face and eLearning RPKI training courses delivered • Offline simulation of production system • Create and revoke ROAs, observe changes to routing state in lab
  • 16. Internet Operational Research Grants 16 New fund supporting the Internet research community in the Asia Pacific Research aiming to improve availability, reliability, and security of the Internet in the Asia Pacific Network measurement and analysis IPv6 deployment BGP Routing Network Security
  • 17. Conclusion • Capacity development is fundamental & critical • Approach must be flexible and scalable • Plenty of challenges & opportunities • Let’s collaborate! 17

Notes de l'éditeur

  1. We have to realize that different economies have different Cyber Security Environment. Some have frameworks, policies and institutions in place. But others don’t. Even if you have everything in place – there is a lot of dependencies. You need to look at the bigger picture (NEC Talk yesterday)
  2. Keeping information up to date
  3. Host Critical Infrastructure Case Studies – Take downs Environment
  4. Understanding about security incidents
  5. Win-win approach & through various means
  6. Security specialist Adli Wahid, is working with different teams within APNIC as well as building relationship with potential and new partners that APNIC can leverage. Adli was recently elected as a board member of the Forum of Incident and Security Response Teams Build capability through training, providing content on security at APNIC and LEA training Participation in NOGs, inter-governmental forums, CERTS etc. We take that knowledge and share it with Members to raise awareness Highlighting relevant initiatives to Members to improve security such as IRT objects in whois, RPKI, and SAVE (BCP 38) We also supported security community events such as the PHCERT & APCERT Conference this year MOU with APCERT in the area of promoting security awareness, improving incident response and supporting capacity development activities
  7. Where do we capture this CSIRT Knowledge
  8. We would like to encourage members to participate in our event. Let us know for opportunities
  9. In the last meeting I highlighted our ROA. Ready to ROA our initiative to promote security routing The main aim is to get Network Operators to create Route Object Authorisations – which will enable others to validate the origin of routing announcement. * 1.92 uptake as of September 2015 (https:// This is also part of our effort to promote Routing Security among network operators and cyber security agencies There has been some progress since we actively promote it at various events. It must be stressed however that his is only the first step
  10. APNIC is the secretariat of ISIF (Internet Society Innovation Fund) Help spread the word about ISIF grant – covers IPv6 and Operational Network Security. Up to 60k AUD grant
  11. How to make it scale? How do we cover areas that do not have enough resources?