R&D projects launched in response to the dynamic evolution of Internet security threats - CERT view

Speaker: Krzysztof Silicki

Wherever they are, CERTs (Computer Emergency Response Teams) as security incident handlers have hands-on experience with the latest attack techniques on the Internet. This is the result of direct contact with their constituency and other CERT teams, which often serve as the first line of support when faced with new threats. The dynamic development of threats remains a never ending challenge not just for them, but the entire security industry. Research and development projects that are launched in response to analyzing threats, often have a problem keeping up and developing adequate tools that can be applied in practice. Nevertheless, creating new platforms that can facilitate detection and improve situation awareness is critical in order to stop these threats. We will present technical issues concerning national and international research and development projects conducted by the CERT Polska team, operating within NASK structures. We will also present how these projects support the operational activity of CERT, which determines the requirement for new tools and research – namely for projects having practical application in e.g. threat monitoring, correlation, early warning, malware analysis or effective transfer of information to proper recipients. A few examples of building synergy between projects being implemented will be described. We believe that the most valuable part of our work is a very effective approach to the problem of relationship between practical needs of an operational work of CERT team and the outcomes of security projects and systems development within such team. We are convinced that such relationship should be very strong and we try to ensure it in our technical work. Thus the technical projects undertake the most important and the most novel topics related to the ICT security. We believe that a major idea of our work is the positioning of different projects in a way the enables them to work together, creating a synergy that results in a solution to today's security problems of the Internet. In each of the presented projects, we come up with novel algorithms that enable the achievement of specific project goals.