Skip to content

Details

Winn Schwartau we are very honored to announce will be the Keynote Speaker at the ISSA of WI on Tuesday 3/10 from 3:00 PM-5:00 PM. Happy Hour with will follow. 2 x CPEs are confirmed.

Winn is globally considered to be 1 of the foremost thought leaders in the history of IT security. Winn is likely the most long tenured authority in our industry having started in 1983.

Winn is a ISSA Hall of Famer, Ponemon Institute Distinguished Fellow, ISC(2) Top Rated Leader, an SC Magazine "Top 5 Security Thinker", an SC Magazine "Top 20 Industry Pioneer" and an RSAC Top Rated Speaker (4.85/5.0); https://winnschwartau.com

Winn will address our chapter on the topics of: Analogue Network Security and AI Ain’t So Smart: Should Infosec Professionals Even Bother?

Part 1 : Analogue Network Security: We grew up analogue. This talk is about applying analogue thinking to Network Security.

For those who believe that digital is God, I will attempt to show you the errors in your ways. Or at least, show you another way of looking at networks. The idea of Binary vs. Spectrum has hurt our field as well as general real-politik globally. I will stick to the tech aspects, I promise.

I will re-cover the traditional basics of TBS, Time Based Security basics ( P > D+R, E = D+R, F(s)/BW = T), from the book of the same name in 1998. I'll position it with a dose of analogue terms thrown in to get your analogue neurons stirring. Feedback and the OODA Loop are decidedly analogue concepts that add to the equations.

Trust is, unfortunately, often viewed as a binary function. I want to examine how an analogue view of Trust will give us a more accurate approach to trust in an ever-connected world.

Pat 2: AI Ain’t So Smart: Should Infosec Professionals Even Bother?

There is no such thing as AI. It is a sci-fi and marketing hype term with the most nebulous foundation. Rather, we actually employ machine and deep learning systems and neural networks to analyze massive data sets and come up with answers. Get ready to have your preconceived notions turned upside down!

History & Basics: AI is not absolute. It is NOT deterministic. AI is probabilistic. (Fuzzy, analogue, not binary). Errors will occur, no matter what you do. There is no way to ask an AI, “How did you arrive at that answer?” AI is entirely bias (data set) sensitive. If you ask your system a question today and then again tomorrow, there is a good chance you will get a different answer. Is that what you really want? Errors will compound over time, unless you know how to continuously monitor and tune the system.

Questions to ask yourself before investing in AI (Machine Learning) cybersecurity products: What problem – exactly – are you trying to solve? What results do you expect? How will you measure the results (ROI/time) How much error are you willing to take?

Questions to ask your vendor before investing in AI (Machine Learning) cybersecurity products: Can you or your product explain the output of your system? How do you prove your initial dataset is neutral (un-biased)? How can you prove the system is giving the ‘correct’ answers? In other words, how can Trust be validated? How does the system adjust for FP, TP, FN, TN fluctuations over time?

Bottom Line: We are at the 300 baud equivalent of sophistication.

Winn has lived Cyber Security since 1983, and now says, “I think, maybe, I’m just starting to understand it.” His predictions about the internet & security have been scarily spot on. He coined the term “Electronic Pearl Harbor” while testifying before Congress in 1991.

Winn is the author of 9 books most recently Analogue Security which will be distributed on March 10. See it here!:
https://winnschwartau.com/ans/

Related topics

You may also like