{"id":3713,"date":"2019-10-01T08:44:53","date_gmt":"2019-10-01T08:44:53","guid":{"rendered":"https:\/\/dev-alumn-nus.pantheonsite.io\/alumnus\/?p=3713"},"modified":"2025-07-15T16:08:11","modified_gmt":"2025-07-15T08:08:11","slug":"the-art-and-science-of-cybersecurity","status":"publish","type":"post","link":"https:\/\/alumni.nus.edu.sg\/thealumnus\/2019\/10\/01\/the-art-and-science-of-cybersecurity\/","title":{"rendered":"The Art and Science of Cybersecurity"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3713\" class=\"elementor elementor-3713\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-438b84e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"438b84e\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-73c7512\" data-id=\"73c7512\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3b18c3c elementor-widget elementor-widget-image\" data-id=\"3b18c3c\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"400\" height=\"442\" src=\"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-content\/uploads\/sites\/4\/2025\/05\/pano-2.jpg\" class=\"attachment-large size-large wp-image-3716\" alt=\"\" srcset=\"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-content\/uploads\/sites\/4\/2025\/05\/pano-2.jpg 400w, https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-content\/uploads\/sites\/4\/2025\/05\/pano-2-271x300.jpg 271w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-66 elementor-top-column elementor-element elementor-element-0701f0e\" data-id=\"0701f0e\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e77465f elementor-widget__width-initial elementor-widget elementor-widget-testimonial\" data-id=\"e77465f\" data-element_type=\"widget\" data-widget_type=\"testimonial.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-wrapper\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-content\">Mr Tommy Hor, Chief Information Technology Officer, NUS, spearheads the IT development on campus supporting teaching, learning, research and administration. Conferred the CIO Asia Award in 2006, Mr Hor won the 2008 MIS Asia IT Excellence Award for the Best Security Strategy Category, and also received the Public Administration Medal (Silver) at the 2017 National Day Awards. His current work includes IT governance, cybersecurity, research &amp; mobile computing, and applications of artificial intelligence and big data.<\/div>\n\t\t\t\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-eb5d7f7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"eb5d7f7\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2fd012e\" data-id=\"2fd012e\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bf1e913 elementor-widget elementor-widget-text-editor\" data-id=\"bf1e913\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Given the number and frequency of news reports these days on the topic of cybersecurity \u2014 and in particular breaches in this area \u2014 it would not be unreasonable to believe that organisations around the world are fighting a losing battle when it comes to the protection of data and other IT assets. And as we might have read or heard, cyberattacks have become more targeted and sophisticated. No longer just \u2018entry-level hackers\u2019, our adversaries now are armed with abundant resources and the most advanced techniques. The standard, age-old defensive and preventive measures adopted by many organisations are proving increasingly incapable of countering these threats effectively. We also see a rapid convergence of IT, operational technology (OT) and the Internet of Things (IoT), making the execution of cybersecurity measures much harder, as these significantly expand the surface for attack. In addition to standard Internet protocols and programming languages, OT and IoT extend the security risks to industrial control systems and communication protocols which often deal with human safety, and essential supplies such as water and electricity.<\/p><p>Whatever it takes to prevent, or protect us from, such threats will have a huge potential impact on the physical world. Obviously, cybersecurity issues affect more than just University staff and students \u2014 they ought to concern us all. As such, the leaders in this field must adapt their strategies, frameworks and technologies to deal with threats in a rapidly-changing environment.\u00a0 \u00a0<\/p><p><span style=\"font-size: 1rem\"><b>SOMETHING PHISHY<\/b><\/span><\/p><p><span style=\"font-size: 1rem\">When it comes to cyberattacks, phishing tops all threats that lead to security breaches today, based on a 2019 report by global communications company Verizon[1]. Its findings stated that 32% of breaches reported involved phishing, and 94% of malware-related incidents had been found to come through emails. For those unfamiliar with the term, phishing is a form of social engineering that exploits human vulnerabilities, where, for example, many of us would empathise when asked to help in a situation. Likewise, most staff act swiftly when they receive requests from their managers. But vulnerability can also manifest as greed, which may surface when one is tempted with an opportunity to make a quick profit \u2013 causing us, for instance, to enter our login credentials without a thought. This is especially so if we are accessing the same website repeatedly without realising the website is fake.\u00a0<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1230154 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1230154\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-7a44a5a\" data-id=\"7a44a5a\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ac0b494 elementor-widget elementor-widget-text-editor\" data-id=\"ac0b494\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Among the forms of email phishing, impersonation is the hardest to detect, as it becomes increasingly sophisticated with techniques such as the Business Email Compromise (BEC). The Internet Crime Complaint Center (IC3) \u2014 which is linked to the US Federal Bureau of Investigation (FBI) \u2014 received 15,690 BEC complaints with adjusted losses of over US$675 million in 2017[2]. A BEC attack is a highly-targeted one. The adversary will conduct thorough research on his subject, finding out his roles, regular contacts, staff subordinates, working hours and even hobbies before launching a personalised attack. A BEC often begins with a casual pretext such as \u201cDo you have a minute?\u201d or \u201cAre you available?\u201d to sense its target\u2019s vigilance and interest in following up. The perpetrator will time it well, impersonate the victim\u2019s manager and appeal for money transfer by claiming that he is overseas and\/or just robbed when he is indeed travelling. If this is not sufficient to trick the victim, he will launch a takeover of the accounts of the manager in question (or those of close friends in other cases) and if successful, send a phishing attack on you using the compromised (and yet legitimate) ID.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-6267f78\" data-id=\"6267f78\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2ab69a4 elementor-widget elementor-widget-testimonial\" data-id=\"2ab69a4\" data-element_type=\"widget\" data-widget_type=\"testimonial.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-wrapper\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-content\"><span style=\"font-size: 20.8px\">378 business email impersonation scams were recorded in 2018 \u2014 up from 332 in 2017 \u2014 resulting in $58 million in losses, according to the Cyber Security Agency of Singapore<\/span><\/div>\n\t\t\t\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-86f4c8c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"86f4c8c\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-93f768f\" data-id=\"93f768f\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d450f73 elementor-widget elementor-widget-text-editor\" data-id=\"d450f73\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>What is important to note is that while humans form the first level in the entire cyber-defence system, they are also its weakest link. Security measures like email filtering and sandboxing (where a programme is \u2018quarantined\u2019 from other programmes in a separate environment so that if errors or security issues occur, these will not spread to other areas on the computer) work best with predefined rules. As such, they are less effective with BEC attacks, as these work on writing styles, the language used, words chosen and expressions of intent. Like an Arts subject, BEC is a language on its own, understood by an individual, and it works by exploiting the social and behavioural dynamics of a society.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9ccb552 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9ccb552\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-66 elementor-top-column elementor-element elementor-element-b064eff\" data-id=\"b064eff\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9d8c3fa elementor-widget elementor-widget-text-editor\" data-id=\"9d8c3fa\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-size: 1rem\"><b>FIGHTING FIRE WITH FIRE<\/b><\/span><\/p><p><span style=\"font-size: 1rem\">Having come to understand the continually-evolving nature of such threats, the University has been investing significantly in cybersecurity in technology, processes and people over the years. We are transforming our cybersecurity strategies and framework in a number of ways. Firstly, we deploy Machine Learning (ML) as a possible solution in situations where humans remain a weak link, such as in the case of a BEC attack. A ML model learns from past data, identifies patterns and makes decisions with minimal human intervention. Once an ML model learns your email writing style, it is possible for your acquaintances to infer an email received was indeed from you or not. Under supervised learning conditions \u2014 or if learning is augmented by human intelligence \u2014 one can label certain data set to help the ML model achieve a good level of accuracy. It mimics the type of training that is used if the ML model is, for example, taught to recognise a dog by feeding it thousands of pictures of dogs of various breeds, colours and sizes. Over time, the accuracy improves and error rate drops to the extent that the ML is able to identify a dog from a picture that it has not seen before.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-47ed2e3\" data-id=\"47ed2e3\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8c1476a elementor-widget elementor-widget-testimonial\" data-id=\"8c1476a\" data-element_type=\"widget\" data-widget_type=\"testimonial.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-wrapper\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-content\">While humans form the first level in the entire cyber-defence system, they are also its weakest link.<\/div>\n\t\t\t\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3cee589 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3cee589\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e55be09\" data-id=\"e55be09\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6a19030 elementor-widget elementor-widget-text-editor\" data-id=\"6a19030\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Secondly, the University is moving to an Advanced Threat Hunting model. We do this by establishing partnerships with industry experts and become much more proactive to research and listen into the dark web and global happenings as well as blog activity on indicators, variants, targets and the motives behind attacks. We may then deploy deception tools to purposely build a fake environment comprising virtual workstations, servers, devices, applications, services and protocols to detect, lure, entice and ultimately engage attackers. There are over 150,000 devices connected to the campus network. We view every device an asset rather than a burden to our defence as we will enable every device as a sensor, providing us intelligence and insights to potential threats in networks, systems and applications.<\/p><p>Thirdly, we have to strike a balance in the University for our users to do their jobs efficiently and closing off avenues of attack. User Behavior Analytics (UBA) is one of our key strategies, where we detect anomalies in the behaviour of users or systems without imposing extra steps and controls. UBA studies logs of past behaviour to identify standard patterns \u2014 such as login hours, assets accessed or data transfer volume, etc. \u2014 that can be picked up over a year or more of analytics. The more UBA knows about a user or system, the more precise its patterning and anomaly detection become.<\/p><p><b>IT TAKES PEOPLE POWER<\/b><\/p><p><span style=\"font-size: 1rem\">For all the measures that can be taken however, science or technology alone is not enough to combat cyber-attacks. The \u201cart\u201d of defence \u2014 where humans become aware of the threats and learn to defend against them \u2014 plays an important role. As in the case of phishing attacks, we need to change our behaviour and perspectives towards emails received. NUS Information Technology for one conducts regular phishing drills, with an aim to change working culture and behaviour through education. The drill targets various groups of employees at different frequencies and by employing different themes, occasionally through impersonating an important sender. It is fascinating that people\u2019s reactions to various scenarios of appeals for help (with dire consequence to follow if no action is taken by certain deadline) can be vastly different.\u00a0<\/span><\/p><p>All said, we believe in nurturing a holistic cyber-secure personal lifestyle that includes good cyber-hygiene habits that will permeate the workplace, households and social spaces. Besides modernising our cybersecurity framework, our drive towards lifelong learning will impart the essential skills and behaviour to individuals, and hopefully serve to strengthen the weakest link in the cybersecurity ecosystem.\u00a0<\/p><p><i>[1] Verizon Data Breach Investigations Report 2019\u00a0 \u00a0 [2] Internet Crime Complaint Centre Report 2017<\/i><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>As IT threats become more prevalent, increasingly sophisticated strategies<br \/>\nare needed to deal with them. NUS Chief Information Technology Officer Mr Tommy Hor examines these threats and shares how the University is countering them.<\/p>\n","protected":false},"author":1,"featured_media":3714,"comment_status":"closed","ping_status":"open","sticky":false,"template":"elementor_theme","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-3713","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-leadership"],"acf":[],"_links":{"self":[{"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/posts\/3713","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/comments?post=3713"}],"version-history":[{"count":8,"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/posts\/3713\/revisions"}],"predecessor-version":[{"id":4201,"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/posts\/3713\/revisions\/4201"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/media\/3714"}],"wp:attachment":[{"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/media?parent=3713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/categories?post=3713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/alumni.nus.edu.sg\/thealumnus\/wp-json\/wp\/v2\/tags?post=3713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}