Jump to content

Recommended Posts

Posted

I've foolishly volunteered for something, and would appreciate any help, advice guidance or anything else people want to offer.

 

On Monday I'm giving a two-hour lecture to somewhere between 1-300 undergrads on cyber security. I've managed to work out an outline for the talk, between bouts of terror, and plan to put together the few illustrations I want to use over the weekend. I've also had some guidance from their main lecturer about topics to cover.

 

The outline I've got so far is:

- Introduction: a few minutes of saying who I am and why they should listen to me on cyber security

- Systems introduction: working up from a computer, to a small network, to a domain, to a multi-site domain, to the internet as scalable systems where each can be abstracted away as needed (30 minutes)

- The basic defense mechanisms: antimalware, IDS/IPS, firewalls, network monitoring, audit logs, NAT (and why it isn't a security system) and routers/broadcast domains (15-20 minutes)

- Break for coffee and panic attack (20 minutes)

- What penetrating a network involves, whether it be external over attack vectors, internal using a covert channel to evade monitoring, or exploit to subvert a user/station (20 minutes)

- Specific attacks, scaling from DoS, segueing into using exploits to build a botnet, then combining the two to describe a DDoS attack, with an aside on social engineering (20 minutes)

- A handful of actual attacks by pentesters (USB sticks dropped in the carpark, pretexting, spear phishing) (10 minutes)

- Crawling into a dark corner until the shakes go away

 

Most of this I can use whiteboards to present, though for the various levels of network I'm planning to put together a network diagram and zoom out to show how everything can be treated as just a system with inputs/outputs at some level.

 

Any reassurance, advice, thoughts on materials, thoughts on the outline, advice on changing my identity so I don't have to go through with it or other general feedback much appreciated. Also advice on presentation, how to deal with students, or anything else you think of that might help even more appreciated. I can't offer much in return, but if you happen to be nearby or I happen to be close to you I'm more than happy to stand people a drink in gratitude, assuming I survive.

Posted

I'd work the current FREAK vulnerability into the lecture - to be topical. It gives the listeners an anchor point to think what is being talked about is relevant even though everything will be.

 

Other tips I'd give - don't read from your slides if you use any.

 

The hardest thing for me when talking to large groups is I don't know where to look. Making eye contact with people terrifies me, but looking elsewhere makes me feel like I'm ignoring them. So I still force myself to make random eye contact with people - then calm down afterwards.

  • Thanks 1
Posted

As part of your defense side of things you've also got device control, nac, web proxy/gateway, email gateways, hybrid solutions to these using the cloud.

 

Ben

  • Thanks 1
Posted (edited)

Thanks - I was going to cover general SQL injection and the Heartbleed issue (with the help of XKCD). FREAK and it's POODLE relatives will now get a mention as well.

 

I think the cloud will have to wait as it's quite a large topic in itself, but will definitely be adding the other defense mechanisms to the list to give a quick run through. Thank you. :)

Edited by jamesb
Posted (edited)

If you're nervous, need a wee before you start. If you go into it needing a wee you'll concentrate on that more than nerves and you'll be fine/a bit grumpy rather than all stagefright-ed. Then wee in the coffee break and you'll be totally fine at that point, likely slightly bored of it.

 

Good luck but you'll do ace. The turning point for me in those sorts of situations always comes about two or three minutes in when I see the first person fiddling with their phone or chatting to a friend and then I realise that the intense, piercing gazes of scrutiny from 2000 pairs of eyes I'd been dreading actually never existed and nobody cares as much as I thought.

 

OH and honestly, there's nothing to worry about with regards to public speaking. As in, if you think there's a 'trick' to it then you're not really engaging with it and you'll become one of those people who rush or bumble through it nervously avoiding the audience whilst trying unsuccessfully to picture them in their pants or something. An audience who, in this case, are there to see you and don't have you 'on trial' if you understand me. So I'd say don't worry, get ready to engage. Tell everyone they're welcome and mean it, and get a joke in as quick as you can; when you hear that room (of people expecting what could be a reasonably dry topic) laugh even a bit it'll 'lift' you BIG style and then bam - you're engaged. :)

 

And needing a piss.

Edited by Miscbrah
  • Thanks 2
Posted

I'd say social engineering is more than an aside, it's a vital part of circumventing security and needs plenty of time to explain properly. As systems became harder to crack (thanks to the browser wars kicking off and IE6 getting trounced by Firefox making drive-by attacks harder), the weakest part of the chain became the people using the system. The human element is routinely exploited with cases of account resets being performed over the phone or spear phishing and 419 scams became ever more commonplace. This spread to text messaging through the PPI trade and now we are looking at pensions changes being used to exploit the older generation and swindle them out of their hard earned money.

 

This leads to the next consideration, exploits used to be the work of pranksters with the occasional financial motive, this has now shifted to predominately financially motivated crime and few pranksters are left by comparison. Even Lizard Squad's takedown of PSN over Christmas was a publicity stunt to sell their DDoS services. Fun fact: at the height of it's popularity a WoW account was worth more then swiped a credit card. Reason for this was to feed the currency farming trade in virtual worlds which used a combination of below minimum wage "sweatshops" and hacked accounts to launder and sell gold to players (who could promptly get their account swiped after purchase).

 

Also consider password sharing and it's implications. When dumping hacked details on Pastebin became all the rage, people tried those E-Mail and password combinations on other services. Guild Wars 2 suffered a hack attack immediately on launch because thieves used combinations pilfered from Pastebin dumps to find newly registered accounts as people were re-using their hacked details! Also, compromise the E-Mail account and you compromise all the accounts that use that E-Mail for password resets and verification.

  • Thanks 1
Posted (edited)

Others know more/have said more about the security said than I can, so I'll go for the public speaking tips instead.

 

PowerPoint - keep to no more than 4 bullet points per slide, and 4-5 words per bullet point tops. That's a 20 word limit on each slide (excluding title and header/footer guff). If you have lots of words on your PowerPoint, people will immediately start reading it as soon as your slide comes up, not be listening to you, and then when they're done, they've either got no idea what you're on about because they weren't paying attention to you, or they're bored because they've just read everyhing you're slowly talking through. Bullet points are basically sub-headings that give structure to what you're saying, and should never be a full explanation - in a way, they should only make sense after you've said your bit on that topic.

 

Look at the audience. You don't have to make eye contact with a person, but sort of... look into the middle of a cluster of people, like you're making eye contact with the group. You're never really looking at any one person so it doesn't get awkward. For the love of God don't turn your back on your audience and talk to your slides. Don't pace either.

 

Use a remote/slide clicker. Apart from the fact they're useful anyway, they give your hands something to do. They help avoid too many hand gestures and what The Thick Of It called "the invisible tits".

 

Talk slower than you think you need to. Especially when nervous, you'll go faster than you realise. Slow down enough so that it just about starts to sound odd & stilted in your head, and it'll be natural and easy to follow for everyone else who isn't in your head.

 

Most of the above boils down to: fake being calm. Force yourself to smile and, weirdly, your own body believes the lie and relaxes a bit. Pretend to be calm long enough and you'll start to actually be calm.

 

And as nervous as you get, don't think there's anything wrong with that: they're there for a reason, because they sharpen you and prepare you and build you up ready to face it. Accept them, don't fight them. A weird thing happens with public speaking: the steps up to the stage will feel leaden and heavy and full of portent, but once you're up and talking, you hit some kind of weird plane of calmness and peace, and all the nerves that threatened to drag you under five minutes before vanish like mist in the sunrise. By the end, you'll actually be enjoying yourself - especially if it's a topic you know something about and enjoy yourself.

 

Good luck! You'll be better than you know. You'll be amazed what you can get away with - all the fatal errors and missteps and mistakes you think you've made go completely unnoticed by people. It's all just a confidence trick.

 

EDIT: questions! Questions at the end. When someone asks you something, repeat it back to them slightly rephrased, for three reasons: (a) it means you can check you've understood their question; (b) it means everyone can hear the question when you repeat it, as otherwise questions from the audience tend to be lost on the audience; © it gives you a moment to think of where to start your answer.

Edited by sonofsanta
  • Thanks 1
Posted

I do a similar short talk for our A-level students. On the countermeasures side of things, you might want to cover:

 

The problems of signal-to-noise and tuning systems to show differentiation from the norm so the output is useful:

 

IDSTuning.jpg

 

and how poorly-thought-out security is circumvented:

 

road.jpg

 

---

 

If you're doing a live demo of something, consider screen-recording a run through of it beforehand. If it all goes pear-shaped you can play the video and talk through it.

Posted

I usually go bright red and sweat massively within a couple of words. But I find if I acknowledge this with the audience in the first few exchanges, it passes quickly enough.

 

I'd always have some water to drink while presenting, placed just out of reach to stop over use.

 

Let the students know if notes / slides will be available (don't hand out until after) - saves them just copying and not engaging.

 

Maybe get a volunteer to note questions / answers which can suplement any notes.

 

 

A funny bit of social engineering:

  • Thanks 1
Posted
Look at the audience. You don't have to make eye contact with a person, but sort of... look into the middle of a cluster of people,
Make that group somewhere beyond 1/2 way back, and (unless you are radio miced) pitch your voice to talk to them.
  • Thanks 1
Posted
Last year I attended the SW Regional ICT Conference at UWE Bristol. There were a few pretty dry and uninteresting presenters. On the otherhand without a doubt the star event for the day for me was Rhinan Khavanah who seemingly unscripted stood up to in front of a full lecture theatre and presented on Cyber Security. She was totally mesmerising and inspiring. She has since been into my EDB Special school and mad a presentation to our KS3/4 lads. Sadly I understand that funding for the outfit she works for E-Skills? has been pulled by this 'Government'.
  • Thanks 1
Posted

The only advise I can give is to try and relax, there undergrads so they are going to want to be there so they should not be talking to each other much.

 

If you have a chance maybe you could have a practice in front of some people to try and make it feel less worse.

 

You may want to leave sometime for questions

 

Remember when talk not to have a paper in front of your face.

 

I hope it goes well for you

  • Thanks 1
Posted
Thank you all. Just leaving the university now, having been bombarded with questions after the lecture - which I feel went well. Just need to stop shaking now.
  • Thanks 3
Posted
Thank you all. Just leaving the university now, having been bombarded with questions after the lecture - which I feel went well. Just need to stop shaking now.

If they were bombarding you with questions - that means they were listening to what you said!

Well done :)

  • Thanks 1
Posted
Thank you all. Just leaving the university now, having been bombarded with questions after the lecture - which I feel went well. Just need to stop shaking now.

 

Was it recorded? :)

 

Ben

  • Thanks 1
Posted
Not recorded sadly, and it's a bit of a blur when I look back. But as a result I've been asked to speak at a couple of other events - which may be recorded. :-)
Posted

Glad it was a success, just a shame you couldn't get out of the new invitations for other events :)

 

Having done a few of these and a few conference presentations, a couple of techniques I've found useful (YMMV) especially in longer talks like this - if you can get hold of some voting pads use them. Breaks up your monologue, gets the audience thinking a bit and gives you a breather from talking.

 

Also if you're explaining something where there is a recognised authority on the subject there's bound to be a video online of them explaining it - play that as part of the presentation rather than explaining yourself. You get a few moments to gather your thoughts, the audience get to hear it from the horse's mouth. Like the voting pads, this can reset the attention span timer.

 

I also recommend using screen recordings rather than live demonstrations of software things - much less likely to go pear shaped on the day and you can cut down the tedious looking at status bar bits.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...