Collaborative National-level Incident Response Model to Address Large-Scale Data Breach Attack in Malaysia

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

In October 2017, Malaysia was hit by the news that 46 millions of Malaysians’ personal data is up for sale on the Internet. Data breach attack is not something new in our constituency, however large-scale data breach is something serious that need to be addressed with collaborations between CERTs and various parties at national level. Investigation has been setup respectively by Malaysian Law Enforcement Agencies (LEA), CERT and Internet Service Providers (ISP) in responding to this large-scale national cyber attack. This presentation will share the analysis case study of the incidents reported to Cyber999 and the incident response steps taken by MyCERT with collaboration Law Enforcement Agencies (LEA), CERTs and Internet Service Providers (ISP).The statistic in the atatched document illustrates gradual decrease of data breach attack between 2012 and 2016, and significant increase in 2017 within Malaysia.The collaborative model between Law Enforcement Agencies, CERTs and ISPs, can be viewed as a method to overcome certain problems of Incident Response, such as:➢ Insufficient coordination between Law Enforcement Agencies, CSIRTs and ISPs in Malaysia during large-scale national-level attack. ➢ Unavailability of an Incident Response model that can be deployed by CSIRTs, Law Enforcement Agencies and ISPs in addressing large-scale national-level attack. ➢ Communication problem with the right parties during a large-scale attack. Having good communication with right people saves much time in incident response. ➢ Time limitation during a large-scale attack incident may deter immediate preventions of an attack at national level.To prove that the model has worked for us, we will highlight a case study on large-scale data breach attack involving Malaysians’ personal details exposed on public forums based in Malaysia and in foreign countries. The uniqueness of this model is that it brings together three major players in Malaysia in the field of IT, the CERT, the LEA and the ISP.The presentation is targeted for established CSIRTs, PSIRTs and also new teams. The key points that we would like to highlight in this presentation are: ➢ The significant collaboration between CERTs, LEAs and ISPs in eradicating and mitigating large-scale cyber attacks at national level. ➢ Share our model that illustrates how a large-scale attack can be mitigated through collaboration in efficient manner, which in this presentation focuses on large-scale data breach attack in Malaysia. ➢ Share our in-house developed tools and applications that we used for building up and implementing this model for effective mitigation of large-scale national cyber attacks. ➢ Share the work taken by us to further study the behavioral and anatomy of an incident so as to propagate and reduce the effect of similar type of incident in the future. ➢ How CSIRTs of various countries can base our model to build up their own national level collaborative model in responding to large-scale attacks in their country. CSIRTs can no longer work alone. Collaborative work is necessary for execution of effective incident response.