[OPS-AREA]Practical Cyber Security Side Meeting at IETF 126
Michael P1 <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <LO0P123MB39945FDA071B26BDC74807128FD22@LO0P123MB3994.GBRP123.PROD.OUTLOOK.COM> |
Hi All, I wanted to provide a readout from the Practical Cyber Security side meeting that was held at IETF 126. Thank you to all who attended for your input - we had about 60 participants from a range of backgrounds. A few people have asked for a summary due to clashes in schedules, so am providing some notes here which may be of interest to this community. The purpose of the meeting was to share insight on changes in cyber threats, and the real-world challenges need to be tackled. Some of the points discussed are outlined below. * We looked back on the last 20 years of attacker tradecraft and how that's changed. This led into focus on key issues that we face today including advanced phishing tradecraft, software supply chain risks, use of novel vulnerabilities, in particular against edge devices, and impact of credential attacks. That also led into discussion of emerging trends, such as increased capability of cyber attackers to evade defences and using AI to lower the cost of attacks. * This led into a presentation on vulnerability disclosure, with the point made that AI analysis of IETF standards will happen and prompted discussion of how reports of vulnerabilities or legacy issues can be triaged, managed and addressed if required. There was a suggestion that further discussion of a Coordinated Vulnerability Disclosure (CVD) scheme and how to deal with AI generated submissions would be worthwhile as well has how to use tooling during standards development. * We discussed examples of attackers misusing OAuth flows to trick users into sharing their authorization code, with a vulnerability observed in the wild but proving difficult to detect. * There were concerns raised about misbehaviour of AI agents and suggestions of mechanisms to revoke access for rogue agents. * Additionally, we had insight from a threat detection point of view that AI generate botnets have proved to require updating of current defensive practices, with suggestions of further discussions on how to distinguish and react to new attacks. There was agreement in the room that further discussion on these topics would be valuable, so we plan to ensure there is a venue for such at future IETF meetings. In the meantime, there is a mailing list to continue discussion List address: [email protected]<mailto:[email protected]> Archive: https://mailarchive.ietf.org/arch/browse/practical-cybersecurity/ To subscribe: https://mailman3.ietf.org/mailman3/lists/practical-cybersecurity.ietf.org/ Thanks, Michael _______________________________________________ OPS-AREA mailing list -- [email protected] To unsubscribe send an email to [email protected]