Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

7/26/2017
01:30 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

The Wild West of Security Post-Secondary Education

Black Hat researchers will show how inconsistent security schooling is at the university level.

Although an increasing number of universities and post-secondary institutions are offering some level of cybersecurity education, the discipline suffers from a lack of consistent accreditation or measurement of educational efficacy. As things stand, educators aren't carefully considering their curriculum standards and recruiters are having a hard time using scholarly credentials as a measurement for new employees.

This is the premise of a Black Hat talk by two Rochester Institute of Technology (RIT) professors who today plan to expose one of the fundamental problems behind the shortage in security talent across the industry.

They took a deep dive examining security programs across the US for their presentation. Foremost among their findings was that while most schools today use their computer science degrees as the main method for disseminating cybersecurity knowledge, the actual security content of these compsci degrees is absolutely miniscule.

The Association for Computing Machinery (ACM) curriculum guidelines that govern compsci degree accreditation only requires three to nine lecture hours of security for a four-year computer science degree, says Rob Olson, a professor of programming, mobile security, and Web app security at RIT. As he emphasizes, those aren't credit hours — those are actual hours in the classroom.

"That's not just application-level security or coding-level security. That includes, in the computing science curriculum, where networking security and strong security principals would fit in," chimes in his co-presenter, Chaim Sanders, also a professor at RIT.

The breakdown typically looks something like one hour dedicated to fundamental security, one to two lecture hours of secure design, one to two hours on defensive security, one hour on threats and attacks, and two optional hours on network security.

"And then — this is one of my favorites — one lecture hour on all of cryptography," Olson says. "And that's optional. That's optional."

Meanwhile, a number of schools are recognizing that they need to step up their game for cybersecurity and are making program changes accordingly. According to Olson and Sanders, for about 25% of schools that means specialized cybersecurity degrees. This is good in theory, but it presents problems at the execution level. First of all, some worry about whether this is even an effective method for teaching security today. While increasingly more real-world organizations move toward DevSecOps, where security is a shared discipline across the developer and operations teams, breaking it out like this goes in the opposite direction that most IT departments are moving.

"So that seems to be an interesting, although maybe not necessarily very effective, maneuver, because it separates out who will essentially become the developers from the people who are going to be doing security in organizations," says Sanders.

Meanwhile, at a more fundamental level there's no true accreditation available as a backstop for these specialized cybersecurity programs. At best, the National Security Agency (NSA) has its own set of designations that have been serving as a pseudo accreditation and which governs grants to these schools from the government for cybersecurity improvements.

"The closest thing to accreditation we have is NSA designations and in those cases there's been a lot of open-endedness historically, which has fueled a lot of fly-by-night schools that are doing it as a draw but which don't necessarily have the technical expertise to maintain the computing security program," Sanders says.

This has created a large degree of stratification of the haves and have-nots, with only the tech schools able to offer a curriculum that keeps pace with today's rapidly changing attack and defense trends. The trick is that it's difficult to even convey that to employers because there's no consistent measurement of cybersecurity educational efficacy either.

"There is very little assessment within higher education of things like learning outcomes for cybersecurity," Olson says. "The curriculum guidelines that are there say these programs are supposed to teach security, but they're not actually assessing the security knowledge that students are getting all that much."

Related Content:

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
7/31/2017 | 2:15:43 PM
Educated on the Digital Streets
I grew up in the 80s so that meant a "security" education entailed BBS chatter, the latest issue of 2600, attending a good CON (even if it was just all locals), lots of social hacking to get library time on any system they'd let you on, walking the "digital streets" and falling, getting up and learning from your mistakes.  All the while keeping in mind that what you learned one morning might need to be discarded the next and learning something new.  And above all - no formal education.  When I see the needs in the InfoSec industry now, with all its shortages, I still feel this is the best bet for young White Hat (or Grey Hat) hopefuls.  Nothing will hold back a talented hacker more than not being able to hack freely, to build and destroy penetration labs and learn from their own mistakes, or from the knowledge of the underground.  Just the fact InfoSec education right now is considered to be a "Wild West" says it all.  Artists need freedom.  Maybe InfoSec needs some non-artists in the management roles to wrangle the wet cats, but in the end, who are these certificate programs and lengthy higher education course really designed for?  The people making all the money.  Information changes by the minute.  Exploits are born and die hourly.  there is another path to education, and it will allow you to prove yourself in measurable results.  Show me the code, somebody once said.  Talk is cheap.  And ultimately the Wild West of InfoSec education is mostly talk.

       
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-28048
PUBLISHED: 2021-04-14
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-28157
PUBLISHED: 2021-04-14
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
CVE-2021-26030
PUBLISHED: 2021-04-14
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page
CVE-2021-26031
PUBLISHED: 2021-04-14
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an LFI.
CVE-2021-27710
PUBLISHED: 2021-04-14
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system funct...