SlideShare a Scribd company logo
Responsible disclosure in
Higher Education
Giles Howard
Surveying Higher Education for good responsible disclosure practice
» Public-facing policies indicating a commitment or understanding of cyber
issues and the risk that they represent
» Dedicated email addresses representing a route to report cyber issues
» A brief survey of acceptable use policies or disciplinary policies to indicate the
penalties for unauthorised access to systems
» Any whistleblowing policies that might extend to students or
cyber issues specifically
» Any mention of leveraging students as assets for ‘white-hat’ hacking or any
process by which systems may be tested involving students
A holistic, qualitative approach – we were looking around other
Higher Education providers for:
23/03/2016 Responsible disclosure in Higher Education
Additional work (undertaken simultaneously)
» Bug bounties
» Whitelists of systems that can be attacked
» Leaderboards
» Guarantee of safe disclosure if flaws are reported using a defined
procedure instead of being simply publically disclosed
» Assurances that flaws reported via the defined process will be afforded
high priority
» Test accounts for performing exploitation testing without damaging
own/other accounts
Surveying industrial practice in responsible disclosure:
23/03/2016 Responsible disclosure in Higher Education
Complications
» Professional services (student services, finance, HR, etc.) could not risk
interruptions to core business due to unregulated attempts to exploit their systems
» Concerns from multiple stakeholders as to which students/staff this was going to
apply to and in particular, how the students would be vetted
» Further concerns that this may need doing at a much higher level (i.e. an
institutional policy of responsible disclosure of a variety of situations, not purely
cyber security ones)
» Not all University systems are directly managed by the IT service – reporting
out to vendors and manufacturers might take substantial time before
fixes are available
Consulting with key stakeholders within our institution resulted
in the following issues being highlighted:
23/03/2016 Responsible disclosure in Higher Education
Primary outcomes
» Utilising either the student-run cyber security society or a self-selected population
of interested students to exploit systems with some further constraints
» Usage of ‘at-risk’ periods (as are used for schedule maintenance/system upgrades
at present) outside of core business hours which would allow the systems to be
tested with little-to-no risk to business processes
» Coordination with the Chief Information Officer and others to determine systems
which both had value in being tested as well as not representing a substantial risk
in letting students make attempts to exploit them
Initial groundwork for a localised responsible disclosure process:
23/03/2016 Responsible disclosure in Higher Education
Current work
» HEA-funded project led by Federica Paci (F.M.Paci@soton.ac.uk) at University of
Southampton under the title of “Enhancing campus cyber security through
constructivist student learning”
» Work is beginning on selecting systems for the first round of penetration testing by a
group of interested students
» There is no official policy on responsible disclosure (yet!) but multiple parties are
working together on this initial activity to hopefully iron out a more structured and
policy-backed process for doing this in future
23/03/2016 Responsible disclosure in Higher Education
23/03/2016 Responsible disclosure in Higher Education
Questions?
Thank you
23/03/2016 Responsible disclosure in Higher Education
Giles Howard
University of Southampton
giles.howard@soton.ac.uk

More Related Content

PPTX
Transforming assessment and feedback with technology - Jisc Digifest 2016
PPTX
Implemententing analytics part 1 - Niall Sclater
PPTX
Scaling upon online learning project update_22.04.15
PPTX
Collaboration through technology: moving from possibility to practice - Noel ...
PPTX
Understanding learning gain and why this might matter to you
PPTX
The changing face of assessment and feedback: how technology can make a diffe...
PPTX
FE digital student findings and recommendations
PPTX
Networks and DDoS
Transforming assessment and feedback with technology - Jisc Digifest 2016
Implemententing analytics part 1 - Niall Sclater
Scaling upon online learning project update_22.04.15
Collaboration through technology: moving from possibility to practice - Noel ...
Understanding learning gain and why this might matter to you
The changing face of assessment and feedback: how technology can make a diffe...
FE digital student findings and recommendations
Networks and DDoS

What's hot (20)

PPTX
Electronic Management of Assessment
PPTX
Implementing analytics part 2 - Moriamo Oduyemi
PPTX
Implementing analytics - Paul Bailey and Dr Nick Moore
PPTX
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
PPTX
Delivering online learning: are you ready?
PPTX
Making a difference with technology enhanced learning - Esther Barrett, Andre...
PPTX
Designing and developing great courses together - Jisc Digifest 2016
PPTX
Student digital experience tracker 2017: summary of key findings
PPTX
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
PDF
Keeping learners safe online presentation
PPTX
Facilitating your registration with the Office for Students using the Jisc st...
PPTX
YSJ and Jisc: standing on the shoulders of giants - Phil Vincent
PPTX
Jisc toolkit: supporting the digital experience of new students
PPTX
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
PPTX
Supporting staff to teach effectively online
PPTX
Making a difference with technology-enhanced learning - Sarah Knight and Sara...
PDF
Introducing professionalism as an assessed element of the nursing undergradua...
PPTX
The benefits and challenges of open access: lessons from practice - Helen Bla...
PPTX
Digital leadership
PPTX
Student experience experts meeting
Electronic Management of Assessment
Implementing analytics part 2 - Moriamo Oduyemi
Implementing analytics - Paul Bailey and Dr Nick Moore
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
Delivering online learning: are you ready?
Making a difference with technology enhanced learning - Esther Barrett, Andre...
Designing and developing great courses together - Jisc Digifest 2016
Student digital experience tracker 2017: summary of key findings
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
Keeping learners safe online presentation
Facilitating your registration with the Office for Students using the Jisc st...
YSJ and Jisc: standing on the shoulders of giants - Phil Vincent
Jisc toolkit: supporting the digital experience of new students
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
Supporting staff to teach effectively online
Making a difference with technology-enhanced learning - Sarah Knight and Sara...
Introducing professionalism as an assessed element of the nursing undergradua...
The benefits and challenges of open access: lessons from practice - Helen Bla...
Digital leadership
Student experience experts meeting
Ad

Viewers also liked (20)

PPTX
IPv4 address planning - Networkshop44
PPTX
Ipv6 deployment at the university of reading - Networkshop44
PPTX
SafeShare - Networkshop44
PPTX
Network engineering surgery - Networkshop44
PPTX
Find out about Jisc - Networkshop44 2016
PPTX
Ipv6 deployment at the university of warwick - networkshop44
PPTX
Development of Jisc security programme - Networkshop44
PPTX
IPv6 experience from a large enterprise - Networkshop44
PPTX
Trust and identity services and architecture - Networkshop44
PPTX
IPv6 at Mythic Beasts - Networkshop44
PPTX
The simplification of the campus network Juniper - Networkshop44
PPTX
Telephony developments at pirbright - Networkshop44
PPTX
Data networking at UCL - Networkshop44
PPTX
Session initiation protocol (sip) the force awakens in the Janet network comm...
PPTX
Handling vulnerability reports - Networkshop44
PPTX
Data centre networking at the University of Bristol - Networkshop44
PPTX
IPv6 deployment status - Networkshop44
PPTX
Vscene - Networkshop44
PPTX
Data centre networking at London School of Economics and Political Science - ...
PPTX
Software defined networking - huawei - Networkshop44
IPv4 address planning - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44
SafeShare - Networkshop44
Network engineering surgery - Networkshop44
Find out about Jisc - Networkshop44 2016
Ipv6 deployment at the university of warwick - networkshop44
Development of Jisc security programme - Networkshop44
IPv6 experience from a large enterprise - Networkshop44
Trust and identity services and architecture - Networkshop44
IPv6 at Mythic Beasts - Networkshop44
The simplification of the campus network Juniper - Networkshop44
Telephony developments at pirbright - Networkshop44
Data networking at UCL - Networkshop44
Session initiation protocol (sip) the force awakens in the Janet network comm...
Handling vulnerability reports - Networkshop44
Data centre networking at the University of Bristol - Networkshop44
IPv6 deployment status - Networkshop44
Vscene - Networkshop44
Data centre networking at London School of Economics and Political Science - ...
Software defined networking - huawei - Networkshop44
Ad

Similar to Finding vulnerabilities - networkshop44 (20)

PPTX
Jisc's FE and skills strategic priorities and opportunities to get involved
PDF
Travel ppt presentation of travel bla bl
PPTX
Right Here; Right Now: Providing the Information your Students Need and your...
PDF
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
PPT
PreventionMitigation_Philadelphia_Breakout.ppt
PDF
10 Essential Considerations in Selecting a School Management System.pdf
PDF
Digital Proctor Whitepaper #1
DOCX
introduction of data structure and design and analysis of algorithm
DOCX
introduction of data structure and design and analysis of algorithm
PDF
Slides - Leveraging institutional open practices to promote access- AVU Confe...
PPTX
Access denied? Managing access to the Web within the NHS in England: technolo...
PPTX
METRAC's Campus Safety Audit Process
PPTX
Are you really ready to roll out learning analytics across your entire instit...
PPTX
What data from 3 million learners can tell us about effective course design
PPTX
Kuali - Building a Community (KDUK14)
PPTX
Information security at University of East London: the benefits (and pitfalls...
PDF
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
PPTX
OLI Findings and Innovations Panel
PPTX
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
PDF
A Review On Recommender Systems For University Admissions
Jisc's FE and skills strategic priorities and opportunities to get involved
Travel ppt presentation of travel bla bl
Right Here; Right Now: Providing the Information your Students Need and your...
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
PreventionMitigation_Philadelphia_Breakout.ppt
10 Essential Considerations in Selecting a School Management System.pdf
Digital Proctor Whitepaper #1
introduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithm
Slides - Leveraging institutional open practices to promote access- AVU Confe...
Access denied? Managing access to the Web within the NHS in England: technolo...
METRAC's Campus Safety Audit Process
Are you really ready to roll out learning analytics across your entire instit...
What data from 3 million learners can tell us about effective course design
Kuali - Building a Community (KDUK14)
Information security at University of East London: the benefits (and pitfalls...
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
OLI Findings and Innovations Panel
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
A Review On Recommender Systems For University Admissions

More from Jisc (20)

PPTX
Strengthening open access through collaboration: building connections with OP...
PPTX
Andrew-Brown-JUSP-showcase-20240730.pptx
PPTX
JUSP Showcase - Rebuilding Data presentation
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
FE Accessibility training matrix partnership - information session
PPTX
Procuring a research management system: why is it so hard?
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
How libraries can support authors with open access requirements for UKRI fund...
PPTX
Supporting (UKRI) OA monographs at Salford.pptx
PPTX
The approach at University of Liverpool.pptx
PPTX
Jisc's value to HE: the University of Sheffield
PPTX
Towards a code of practice for AI in AT.pptx
PPTX
Jamworks pilot and AI at Jisc (20/03/2024)
PPTX
Wellbeing inclusion and digital dystopias.pptx
PPTX
Accessible Digital Futures project (20/03/2024)
PPTX
Procuring digital preservation CAN be quick and painless with our new dynamic...
PPTX
International students’ digital experience: understanding and mitigating the ...
PPTX
Digital Storytelling Community Launch!.pptx
PPTX
Open Access book publishing understanding your options (1).pptx
PPTX
Scottish Universities Press supporting authors with requirements for open acc...
Strengthening open access through collaboration: building connections with OP...
Andrew-Brown-JUSP-showcase-20240730.pptx
JUSP Showcase - Rebuilding Data presentation
Adobe Express Engagement Webinar (Delegate).pptx
FE Accessibility training matrix partnership - information session
Procuring a research management system: why is it so hard?
Adobe Express Engagement Webinar (Delegate).pptx
How libraries can support authors with open access requirements for UKRI fund...
Supporting (UKRI) OA monographs at Salford.pptx
The approach at University of Liverpool.pptx
Jisc's value to HE: the University of Sheffield
Towards a code of practice for AI in AT.pptx
Jamworks pilot and AI at Jisc (20/03/2024)
Wellbeing inclusion and digital dystopias.pptx
Accessible Digital Futures project (20/03/2024)
Procuring digital preservation CAN be quick and painless with our new dynamic...
International students’ digital experience: understanding and mitigating the ...
Digital Storytelling Community Launch!.pptx
Open Access book publishing understanding your options (1).pptx
Scottish Universities Press supporting authors with requirements for open acc...

Recently uploaded (20)

PPTX
Pharmacology of Heart Failure /Pharmacotherapy of CHF
PDF
VCE English Exam - Section C Student Revision Booklet
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PPTX
Pharma ospi slides which help in ospi learning
PDF
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
PDF
Module 4: Burden of Disease Tutorial Slides S2 2025
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PDF
RMMM.pdf make it easy to upload and study
PPTX
human mycosis Human fungal infections are called human mycosis..pptx
PDF
01-Introduction-to-Information-Management.pdf
PDF
TR - Agricultural Crops Production NC III.pdf
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PPTX
Institutional Correction lecture only . . .
PPTX
master seminar digital applications in india
PPTX
Lesson notes of climatology university.
PDF
Supply Chain Operations Speaking Notes -ICLT Program
PDF
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
PPTX
PPH.pptx obstetrics and gynecology in nursing
PPTX
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
PDF
102 student loan defaulters named and shamed – Is someone you know on the list?
Pharmacology of Heart Failure /Pharmacotherapy of CHF
VCE English Exam - Section C Student Revision Booklet
O5-L3 Freight Transport Ops (International) V1.pdf
Pharma ospi slides which help in ospi learning
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
Module 4: Burden of Disease Tutorial Slides S2 2025
FourierSeries-QuestionsWithAnswers(Part-A).pdf
RMMM.pdf make it easy to upload and study
human mycosis Human fungal infections are called human mycosis..pptx
01-Introduction-to-Information-Management.pdf
TR - Agricultural Crops Production NC III.pdf
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
Institutional Correction lecture only . . .
master seminar digital applications in india
Lesson notes of climatology university.
Supply Chain Operations Speaking Notes -ICLT Program
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
PPH.pptx obstetrics and gynecology in nursing
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
102 student loan defaulters named and shamed – Is someone you know on the list?

Finding vulnerabilities - networkshop44

  • 1. Responsible disclosure in Higher Education Giles Howard
  • 2. Surveying Higher Education for good responsible disclosure practice » Public-facing policies indicating a commitment or understanding of cyber issues and the risk that they represent » Dedicated email addresses representing a route to report cyber issues » A brief survey of acceptable use policies or disciplinary policies to indicate the penalties for unauthorised access to systems » Any whistleblowing policies that might extend to students or cyber issues specifically » Any mention of leveraging students as assets for ‘white-hat’ hacking or any process by which systems may be tested involving students A holistic, qualitative approach – we were looking around other Higher Education providers for: 23/03/2016 Responsible disclosure in Higher Education
  • 3. Additional work (undertaken simultaneously) » Bug bounties » Whitelists of systems that can be attacked » Leaderboards » Guarantee of safe disclosure if flaws are reported using a defined procedure instead of being simply publically disclosed » Assurances that flaws reported via the defined process will be afforded high priority » Test accounts for performing exploitation testing without damaging own/other accounts Surveying industrial practice in responsible disclosure: 23/03/2016 Responsible disclosure in Higher Education
  • 4. Complications » Professional services (student services, finance, HR, etc.) could not risk interruptions to core business due to unregulated attempts to exploit their systems » Concerns from multiple stakeholders as to which students/staff this was going to apply to and in particular, how the students would be vetted » Further concerns that this may need doing at a much higher level (i.e. an institutional policy of responsible disclosure of a variety of situations, not purely cyber security ones) » Not all University systems are directly managed by the IT service – reporting out to vendors and manufacturers might take substantial time before fixes are available Consulting with key stakeholders within our institution resulted in the following issues being highlighted: 23/03/2016 Responsible disclosure in Higher Education
  • 5. Primary outcomes » Utilising either the student-run cyber security society or a self-selected population of interested students to exploit systems with some further constraints » Usage of ‘at-risk’ periods (as are used for schedule maintenance/system upgrades at present) outside of core business hours which would allow the systems to be tested with little-to-no risk to business processes » Coordination with the Chief Information Officer and others to determine systems which both had value in being tested as well as not representing a substantial risk in letting students make attempts to exploit them Initial groundwork for a localised responsible disclosure process: 23/03/2016 Responsible disclosure in Higher Education
  • 6. Current work » HEA-funded project led by Federica Paci (F.M.Paci@soton.ac.uk) at University of Southampton under the title of “Enhancing campus cyber security through constructivist student learning” » Work is beginning on selecting systems for the first round of penetration testing by a group of interested students » There is no official policy on responsible disclosure (yet!) but multiple parties are working together on this initial activity to hopefully iron out a more structured and policy-backed process for doing this in future 23/03/2016 Responsible disclosure in Higher Education
  • 7. 23/03/2016 Responsible disclosure in Higher Education Questions?
  • 8. Thank you 23/03/2016 Responsible disclosure in Higher Education Giles Howard University of Southampton giles.howard@soton.ac.uk