risk presentation sony 2012 the playstation network security breach

17
IS510 JAMES DELLINGER GRAINNE MALONE JENNIFER MURPHY RAN ZHANG Focus on Sony: The PlayStation Network Security Breach

Upload: james-dellinger

Post on 14-May-2015

330 views

Category:

Education


3 download

DESCRIPTION

Focus on Sony: The PlayStation Network Security Breach Overview  Focus on Sony  What data do they Collect?  High Profile Breach – What Happened and Why?  The Aftermath Response  Policies Introduced as a Result  What has Happened Since?  Vulnerabilities in Legalisation  Sony’s Sony  World’s leading digital entertainment brands, with a large portfolio of multimedia content.  Sony Computer Entertainment  The PlayStatio

TRANSCRIPT

Page 1: Risk presentation Sony 2012 The PlayStation Network Security Breach

IS510

JAMES DELLINGERGRAINNE MALONEJENNIFER MURPHYRAN ZHANG

Focus on Sony:The PlayStation Network

Security Breach

Page 2: Risk presentation Sony 2012 The PlayStation Network Security Breach

Overview

Focus on SonyWhat data do they Collect?High Profile Breach – What Happened and

Why?The Aftermath

Sony’s ResponsePolicies Introduced as a ResultWhat has Happened Since?

Vulnerabilities in Legalisation

Page 3: Risk presentation Sony 2012 The PlayStation Network Security Breach

Sony

World’s leading digital entertainment brands, with a large portfolio of multimedia content.

Sony Computer Entertainment

The PlayStation Network (PSN)

Page 4: Risk presentation Sony 2012 The PlayStation Network Security Breach

PSN Data Collection

NameAddressCountryE-mail addressDate of BirthPSN password and login nameCredit Card DetailsPurchase HistoryAnswers to Users Security Questions

Page 5: Risk presentation Sony 2012 The PlayStation Network Security Breach

What Happened?

Security Breach in PlayStation Network

Shutdown of service

77 million users put at risk

Personal information stolen

Page 6: Risk presentation Sony 2012 The PlayStation Network Security Breach

Security Issues

Weak security system

Lack of random number in algorithm

Lack of Firewalls

Obsolete web applications

Lack of Management support

Page 7: Risk presentation Sony 2012 The PlayStation Network Security Breach

Response from Sony ?

Very slow reaction time

Poor communication

Lack of transparency

Lack of direction

Page 8: Risk presentation Sony 2012 The PlayStation Network Security Breach

Measures Introduced

Software monitoring

Penetration and Vulnerability testing

Encryption

Firewalls

Security personnel

Page 9: Risk presentation Sony 2012 The PlayStation Network Security Breach

Creation of a New Position - CISO

“ to oversee information

security, privacy and internet safety across the company, coordinating closely with key headquarters groups and working in partnership with the information security community to bring the best ideas and approaches to

Sony.” – Sony Corporation

Page 10: Risk presentation Sony 2012 The PlayStation Network Security Breach

Number of Actions Taken

Moved PSN server to a new, more secure and

unnamed location

Enhanced levels of data protection and encryption

Enhanced ability to detect software intrusions,

unauthorized access and unusual activity patterns

Additional firewalls

Established a new data center in an undisclosed

location with increased security

Page 11: Risk presentation Sony 2012 The PlayStation Network Security Breach

Changes of Terms of Service

September 2011 - No Suing Policy!

“ Other than those matters listed in the Exclusions from Arbitration clause, you and the Sony Entity that you have a Dispute with agree to seek resolution of the Dispute only through arbitration of that Dispute in accordance with the terms of this Section 15, and not litigate any Dispute in court. Arbitration means that the Dispute will be resolved by a neutral arbitrator instead of in a court by a judge or jury.”

- Section 15, Terms of Service, Sony Entertainment Network

Page 12: Risk presentation Sony 2012 The PlayStation Network Security Breach

Recent Scandal ?

Page 13: Risk presentation Sony 2012 The PlayStation Network Security Breach

Ahhhhhh Not Again!!!

June 2011 - SQL injection attack against Sony Pictures disclosed personal information of over 1 million Sony customers

June 2011 – an attack against Sony’s Developer Network posted 54MB of Sony developer source code.

October 2011 – Brute-force attack broken into 93,000 PlayStation and Sony network accounts

January 2012 – attack against a several websites operated by Sony for the corporation’s support of the US Stop Online Piracy Act (SOPA).

Page 14: Risk presentation Sony 2012 The PlayStation Network Security Breach

Issues with Legislation

Security breaches of this nature fall under data protection and privacy regulation which the European Commission leaves to each EU

member state unlike Europe’s antitrust regulation, which is centralised.

United Kingdom - Information Commissioner’s Office (ICO)

Ireland - Data Protection Commissioner

Page 15: Risk presentation Sony 2012 The PlayStation Network Security Breach

Future Legalisation

E-Privacy Directive A swift, mandatory disclosure about a data breach

EU Justice Commissioner ‘They will modernize rules dating from 1995, and could expand to e-banking, online shopping or the personal data field’

Page 16: Risk presentation Sony 2012 The PlayStation Network Security Breach
Page 17: Risk presentation Sony 2012 The PlayStation Network Security Breach

Conclusion

What do you think? Who do you blame? What should be done?