Key Concepts
- Canadian Centre for Cyber Security (Cyber Centre)
- Communications Security Establishment (CSE)
- Signals Intelligence
- Information Assurance
- Cybersecurity Incident Response Team (CSIRT)
- Foreign and Defensive Cyber Operations
- Threat Actors (Nation States, Cyber Criminals, Ideologically Motivated Groups)
- Misinformation
- Pre-Ransomware Notifications
- Cyber Threat Assessment
- Artificial Intelligence (AI) & Generative AI (GenAI)
- Cyber Defense Program
- XDR (Extended Detection and Response)
- Deception Technology (Sensors & Tripwires)
- Agentic AI
- Model Context Protocol (MCP)
- SharePoint Exploitation
- Quantum Computing
- Cryptographically Relevant Quantum Computer
- Shor's Algorithm
- Store Now Decrypt Later
- Quantum Transition Guidelines
- Canadian Cyber Defense Collective
- Security by Design
Cyber Centre Mandate and Operations
The Canadian Centre for Cyber Security (Cyber Centre), created in 2018, is the technical authority for cybersecurity and information assurance in Canada. It is part of the Communications Security Establishment (CSE), which has a history dating back to World War II as a code-making and code-breaking organization. The Cyber Centre's mandate includes:
- Information Assurance: Primarily cryptography, which is considered increasingly important.
- Advice and Guidance: Providing services to the Government of Canada.
- CSIRT Role: Serving as the Cybersecurity Incident Response Team (CSIRT) for Canada, including critical infrastructure. This mandate expanded in 2019 from solely the federal government to include provinces, territories, and critical infrastructure.
- Foreign and Defensive Cyber Operations: CSE is legally authorized to take action in foreign space, when authorized, to disrupt threat actors.
Example of Mandate Collaboration:
An incident occurs on Canadian critical infrastructure. The Cyber Centre assists with incident response, identifies the threat actor, and shares information with signals intelligence. Signals intelligence gathers further intelligence on the threat actor globally. This information is then passed to foreign cyber operations, which disrupt the threat actor's operations.
Annual Report Statistics:
- The Cyber Centre handles approximately 200 incidents, with about 100 affecting the federal government.
- Around 1,400 incidents are voluntarily reported to the Cyber Centre.
- The Cyber Centre anonymizes and shares incident data through threat intelligence feeds and incorporates it into advice and guidance.
- Over 300 pre-ransomware notifications are sent out, alerting organizations that they are on the verge of being hit by ransomware. Hundreds more are shared with the US.
International Cyber Threat Assessment
The Cyber Centre produces a future-looking threat assessment every two years, using a scientific methodology with weighted assessment judgments. The latest report was released in October.
Key Judgments:
- Threat Actors:
- Nation States: Advanced and sophisticated actors pursuing government intelligence, national security, and geopolitical priorities.
- Cyber Criminals: Motivated by money, increasingly sophisticated, and supported by a thriving dark web ecosystem.
- Ideologically Motivated Groups: Proxies of governments, potentially more unpredictable than nation states.
- Nation States Seeking to Disrupt and Divide: Misinformation is a growing threat to democracy. Nation-state activities have evolved from intellectual property theft and bulk data collection to prepositioning on critical infrastructure for potential disruption (e.g., Volt Typhoon).
- Cyber Crime Ecosystem: Cyber criminals can easily access tools, exploits, and money laundering services on the dark web. This ecosystem is resilient despite law enforcement efforts.
- Ideologically Motivated Groups Impacting Canada: Groups like Killnet and NoName057 may target Canadian websites and infrastructure in response to Canada's support for Ukraine.
Trends Shaping the Future:
- Artificial Intelligence (AI): Changing the ecosystem, presenting both opportunities and threats.
- Changes in Cyber Threat Activity: Evolving techniques, including anonymization networks, living off the land, and exploitation of non-standard devices (edge devices, telecom appliances).
- Geopolitically Inspired Actors
- Vendor Concentration: Reliance on a few key technology vendors creates vulnerabilities.
- Dual-Use Technologies: Technologies with both military and civilian applications (e.g., satellite modem systems, satellite communications, cloud communications) are increasingly prevalent.
Cyber Defense Program and AI
The Cyber Centre's cyber defense program monitors government systems using network traffic, endpoint traffic, and cloud telemetry. This program, started 15 years ago, serves as the security operations center for the Government of Canada, monitoring over 900,000 devices.
Key Aspects:
- XDR Ecosystem: The program established an XDR-like ecosystem (before the term was coined) by integrating multiple sources of telemetry.
- Importance of Multiple Telemetry Sources: Detecting certain threats requires network traffic, endpoint traffic (due to encryption), and cloud-based sensors.
- Deception Technology: Integrating deception sensors and tripwires as an asymmetric response to evolving threats.
- AI and Threat Volume: The volume of threats has increased dramatically, likely due to automation, necessitating new response strategies.
AI Implementation:
- Data Governance: Clean, scrubbed, de-duplicated, and normalized data is essential for effective AI.
- Agentic AI: The Cyber Centre is prototyping agent-based cyber defense systems with human approval steps embedded for governance.
- AI Security: Security must be a primary consideration in AI development to avoid repeating past mistakes.
- MCP Vulnerabilities: Protocols like MCP (Model Context Protocol) lack basic security features (cryptographic validation, authentication, encryption), creating exploitation opportunities.
SharePoint Exploitation Example
A recent SharePoint exploitation incident illustrates the Cyber Centre's response process:
- Rapid Response: Upon discovering the vulnerability, the Cyber Centre analyzed the situation, identified exploitation in Canada, and sent out 161 notifications to vulnerable servers actively being exploited.
- Unique Findings: The Cyber Centre discovered dozens of handcrafted Microsoft .NET plugins used for exploitation, differing from the web shell and "living off the land" techniques described in Microsoft's blog.
- Sharing Information: The Cyber Centre shared its findings with security vendors and updated its open-source tool, Assemblyline.
- Sophisticated Techniques: The plugins were memory-based and included features for lateral movement and privilege escalation, indicating a high level of engineering effort.
Quantum Computing and Cryptography
The Cyber Centre is concerned about the potential impact of cryptographically relevant quantum computers on cybersecurity.
Key Concerns:
- Shor's Algorithm: Quantum computers can run algorithms like Shor's algorithm, which can break asymmetric cryptographic algorithms used for key exchange.
- Store Now, Decrypt Later: Threat actors could collect encrypted data now and decrypt it later when quantum computers become powerful enough.
Quantum Transition Guidelines:
- Plan Now: Organizations should develop a quantum transition plan by April and revise it annually.
- Cryptographic Inventory: Create an inventory of cryptographic systems to prioritize replacements.
- Tiered Approach: Replace critical systems earlier and less critical systems later.
Partnerships and Summary
The Cyber Centre emphasizes the importance of partnerships in cybersecurity.
- Canadian Cyber Defense Collective: A group of security service providers that share threat intelligence.
- National Cyber Security Strategy: Collaboration is essential for implementing the strategy.
Summary Points:
- Security by Design: Security must be a primary consideration in all activities, especially when implementing AI and new technologies.
- What's Old is New Again: Avoid repeating past mistakes by incorporating security into standards and procurements.
- Continual Evolution: The threat landscape is constantly evolving, requiring ongoing adaptation and innovation.
AI summaries can miss context or contain errors. Check important details against the original video.