Showing posts with label sun tzu. Show all posts
Showing posts with label sun tzu. Show all posts

Monday, July 30, 2012

the folly of offensive cyberwarfare

i often feel like i can't speak freely about cyberwarfare (due almost entirely to my principles about not helping or giving ideas to those who make things worse, be they criminals or warmongers), but it's hard to deny the importance of the subject, and frankly when i read what others have written i can't help but think they haven't really thought things through very well.

when it comes to the development and use of digital weapons there are a couple of key points whose implications need to be understood and kept in mind. the first of these is the problem of attribution. the difficulty in attributing the source of a computer attack is both tactically advantageous, and strategically constraining. the advantages should be obvious - you can attack an opponent without the opponent knowing who is responsible for the attack (unless you screw up and reveal yourself). the problems begin, however, when you consider that the opposite is also true - one or more of your opponents can attack you without you being able to tell who it was.

consider what that means. if you can't tell who is attacking you, how can you possibly retaliate? imagine you're blindfolded, you're ears are plugged, you're handed a gun, and stuck in a room with other people who may or may not also have blindfolds, earplugs, and guns. if someone starts shooting at you, how can you realistically return fire to defend yourself without knowing where to shoot? without the ability to target the your opponent you cannot retaliate, you cannot end him before he ends you. further, when the threat of retaliation becomes empty like this, deterrence no longer works. as a result, so-called cyberweapons have no defensive value.

in the absence of attribution, a conflict must consist entirely of first strikes. there is no retaliation, there is no deterrence, there is no scaring an enemy off by showing what you can do, there is no point to visibly stockpiling armaments. that is significantly different from most conventional models of warfare. this is one of the reasons why cyberwarfare must only ever accompany traditional warfare - only then can combatants avoid firing blindly in the dark.

another important aspect of digital weapons to keep in mind is the fact that they're digital. they're code, bits and bytes inside a computer. what is the one thing computers are exceptionally good at doing with those bits and bytes? copying them. imagine a world where it's expensive to develop guns and tanks and bombs from scratch, but it costs virtually nothing to copy them. that is the world of cyberwarfare, and that is a world that actually does not favour the attacker, per se, but rather one that favours the forager (one of the things sun tzu teaches is to forage on the enemy) because s/he gets the most benefit (a sophisticated digital weapon) for the least cost.

when weapons cost a lot to develop from scratch but very little to copy, what conditions do you suppose would make their development and use make sense? if you could eliminate the possibility of copying and re-use, if the weapon assured you a decisive victory over your opponent then it wouldn't matter that it would be falling into your opponent's hands simply by you using it. unfortunately in the real world a nation has many opponents. they cannot all be fought at once and so a decisive victory against all whose hands such a weapon may fall into is not possible. 

what's more, not all of those opponents are necessarily other nation states. the low cost of copying weapons means that the barrier to entry on this battlefield is lowered and more mundane opponents like terrorists or even sophisticated criminals can join the fray. as you can well imagine, those kinds of opponents are far less disciplined and restrained than a nation state would be.

our best example of a digital weapon thus far is stuxnet. it's believed to have cost millions of dollars and many man-years of effort to develop, and now anyone who wants a copy can download it for free from the internet. i would be remiss if i failed to point out that by now stuxnet is pretty well neutered (since the windows vulnerabilities it exploited have been patched and most anti-malware will detect it's presence) and it would actually take a fair bit of time and money to replace the neutered bits so it could be re-used; but there was a time before that was true when stuxnet was still in many people's hands and could have been re-used at a much lower cost. as strange as it may sound, the malware's discovery and subsequent neutering actually served to mitigate the potential for it's re-use. it's creators are lucky it happened before the malware could be re-used against them, their allies, or other interests they might have. that might not be the case next time.

it's a peculiar irony that the people most capable of developing digital weaponry (the technologically advanced and dependent) are the same people who have the most to lose if such weaponry is used against them. this should make it obvious that defense, not offense, is where one's money and effort would better spent. just so i'm not that guy who makes overly general, hand-wavy suggestions, here are some ideas that are more specific than just "you should do defense":
  • fault tolerant designs
    • redundancy is already something we know how to do, but we don't always do it well (as the 2003 blackout clearly demonstrated). the internet is said to be so fault tolerant that if part of it goes down the rest will just route around it. there are many paths to the same destination. obviously that's a property we want for power, communications, water, etc. it's something we should be designing for and unfortunately because it costs it's something we need to pay for. 
    • ease of recovery is something we perhaps don't think quite as much about. how easy is it to replace physical equipment that no longer operates as intended? how easy is it to overwrite logical systems from backups? how many minutes, hours, or days does it take? aiming to minimize that time also serves to minimize the impact of anything unfortunate happening to the system in question.
  • system hardening
    • vulnerability research and patching is something that already enjoys a certain measure of success in consumer and enterprise environments. if a nation wants to protect it's critical infrastructure then perhaps more money and energy should be poured into researching vulnerabilities in that critical infrastructure.
    • eliminating or rethinking external connections (including both network connections as well as removable media) basically stands in direct opposition to the trend of hooking more and more of our most important systems up to one of the most dangerous networks on the planet (the internet). as with most things, the business incentives that are driving the current trend need to be accounted for. the cost saving benefits of remote connections are understood, but there are other ways of achieving that goal without resorting to the internet - that's simply the cheapest/easiest option
    • whitelisting of code and possibly even data on critical infrastructure systems, because quite frankly why should new unknown material be introduced to these systems? it may make sense to occasionally and in a very controlled way apply fixes or make changes corresponding to changes in the industrial processes those systems are a part of, but in general those machines should be unchanging and that should probably be enforced. as a corollary, eliminating dual use is probably a good idea too. there's no reason you should be writing your TPS report on a machine that can control whether the lights stay on. 
  • early warning detection
  • evasion
    • disinformation can be useful in a couple of ways. it can raise the cost of successfully performing an attack by tricking the attacker into doing useless things, and it can also trick the attacker into doing something that sets off an alarm (ie. they walk into a trap).
    • decoy systems that look and act for all intents and purposes just like the real ones can reduce the impact and success of attacks, especially if they have the same warning sensors the production systems do, by turning the problem of attacking the right system into a game of chance for the attacker. holding out baits for the attacker to reveal their presence and/or intentions can certainly confer advantages on a defender.

i've made a few veiled (and not so veiled) references to sun tzu. while some people may argue that "the art of war" is over-played and not particularly relevant to information security, when it comes to warfare of any kind i think it's very relevant:
Sun Tzu said: The good fighters of old first put themselves beyond the possibility of defeat, and then waited for an opportunity of defeating the enemy.
that is to say, of course, that we need to take up a defensible position first before we start attacking. by most accounts (including president obama's) we aren't there yet.

Wednesday, December 05, 2007

why X is insecure - and probably always will be

about 2 weeks ago (old i know) you may have come across these two articles (by drazen drazic and lonervamp respectively) about why businesses are insecure (the 7 reasons why businesses are insecure and more reasons why businesses are insecure)...

i'm sure they're very good business reasons for why businesses are insecure, but i'm also sure that a business that addressed all of these problems would still be insecure for reasons that have nothing to do with that business or businesses in general or business security in general...

the fact is there's a technical reason why virtually any non-trivial thing (of which anything computer related would definitely fall under) we'd want to secure is almost certainly not secure and probably never will be... i'm not talking about the fact that there is no such thing as secure, rather i'm talking about the asymmetric relationship between attack and defense... if you're trying to defend something you have to try to defend it from all possible attacks, but if you're trying to attack something you only need to find one successful attack vector...

clearly defense takes a lot more work and that's a problem, but it's not clear that we can ever really change that... if we were going to try to change it, though, how would we go about it? the two obvious answers are: 1) make defense easier (presumably by reducing the amount of possible attacks we need to defend against), or 2) make finding that one successful attack vector harder...

making defense easier sounds good but it's easier said than done... sun tzu talked about this very thing when he said that one should force the enemy to engage in an environment of one's own choosing and thus choose what one has to defend and what the enemy can attack (art of war, part 6: weak points and strong)... now you might be tempted to limit the scope of your analysis to an arbitrarily narrow frame of reference (as schneier does here when he refers to cryptography to the exception to the rule of asymmetry between attack and defense) but in reality that doesn't actually get us any closer to our goal of reducing the amount of defenses we need... what we would really need to do is reduce the pool of potential attack vectors, to literally remove things from systems that could be used as an avenue of attack... that means fewer hosts on our networks, less diversity amongst the hosts on our networks (gasp! yes, i said it - diversity is great for minimizing the overall effect a successful attack has on a given population of hosts but it increases the pool of potential attack vectors and so makes compromising assets on the network easier; in essence, what's good for availability may not be so good for confidentiality), fewer services running on those hosts, fewer system components exposed to incoming content (ie. browsers, email clients and other network clients/servers that can do less/have less functionality), less potentially sensitive data stored on those hosts, etc... unfortunately this is completely backwards when viewed through the lens of technological progress, and while minor efforts in this area are no doubt considered beneficial, it would take extreme measures (perhaps even beyond the realm of the realistic given the complexity of modern operating systems) to actually make a significant change in the asymmetry between attack and defense for a system...

making it harder to find that one successful attack vector isn't necessarily a piece of cake either... there's one fairly well known school of thought that posits that reducing the number of vulnerabilities will shrink the pool of potentially successful attack vectors... this school of thought may be right, in a theoretical sense, but in practice it's starting to look like the total number of vulnerabilities is high enough that patching vulnerabilities at the rate we're going right now isn't really having that big an impact on the difficulty of finding a successful attack vector... another well known approach is to devise a system where the attacker has to successfully defeat multiple defenses in order to be successful on the whole... this is, of course, defense in depth... naively one might think this could put attacker and defender on more or less equal footing because now not only does the defender have to defend against a large number of possible attacks, the attacker has to breach a large number of possible defenses... unfortunately, there are only so many defenses one can reasonably deploy and, even with all of them deployed, the amount of work an attacker has to do still won't compare to the amount of work required for defense - nevermind the fact that all those defenses carry with them potential vulnerabilities which could themselves be used in an attack...

that said, it isn't necessarily true that we can't use the asymmetry to our benefit... we can, we just can't do it as a defender... richard bejtlich would i'm sure suggest what he likes to call threat-centric security but which, in the context of this post, i'll call offensive security - that is where we (who have things that need defending) go and 'attack' (as in track down, identify, charge, and imprison) those who would attack us... to quote sandi hardmeier:
Also - I have a special warning for the bad guys - you can hide from some of us, but you can't hide from all of us, and you most certainly cannot hide from your victims.
alas, this too is a kind of defense, and although we can turn the asymmetry around for individual cases, to actually protect our systems this way we'd need to go after all potential attackers (which is an unknowable set of people) whereas the attackers realistically only need to worry about the actual organizations/people they attacked (which is a much smaller and more knowable set of people)... ultimately, reducing the pool of attackers is much the same as reducing the pool of vulnerabilities - for each one you remove there's more where that came from...

so there really doesn't seem to be a good way to turn the asymmetry around and make defending easier than attacking... there are things that can improve the situation to some extent but it can be a real balancing act sometimes...

Tuesday, August 01, 2006

understanding anti-malware intelligence

a recent post on the internet storm center's handler's diary by their CTO, johannes ullrich, tries to apply military strategy to computer security...

i say tries because it goes horribly wrong when he calls signature based anti-virus systems outdated...

signature based anti-virus systems, or more generally known-malware scanners are capable of detecting (and often removing) the vast majority of malware in existence (despite what has been said recently about their performance on a very small subset of that malware) - only the malware that is too new to qualify as known is really outside it's reach... what's more it has the power to do so before control is ever turned over to that malware, thus preventing the malware from getting control/gaining an advantage... turning one's back on known malware scanning ammounts to turning one's back on knowing your enemy as known-malware scanners represent knowledge of the enemy (or at least one aspect of the enemy) codified into a programmatic form for ease of distribution and deployment...

my own preference for strategic military thinking is sun tzu, who is perhaps most famous precisely for his thoughts on knowing the enemy:
Hence the saying: If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.
unlike the popularized misquote of "know your enemy" he's actually balancing knowledge of the enemy with knowledge of oneself - and by extension one's limitations and weaknesses (in order that one may know "when to fight and when not to fight")... not understanding the limitations of one's security measures prevents one from being able to effectively mix technologies and techniques so that the strengths of one can mitigate the weaknesses of another - basically preventing one from reaching any reasonable state of preparedness, which is a key to any effective strategy...

so what was johannes getting at, i wonder... well, for one thing he was quoting an entirely different military strategist - a one carl von clausewitz - but was clausewitz as cavalier about the importance of intelligence as johannes? it doesn't seem that way... as you can read here, although he talks at length about the innaccuracies of the intelligence one may have on hand, ultimately owing to the failings in those collecting and reporting it (intelligence itself has weaknesses and limitations and he tries to impress on the reader the importance of common sense and experience as a corrective measure), still maintains at the outset that the information we have about the enemy is "the foundation of all our ideas and actions"...

so then perhaps it's just johannes ullrich that underestimates the importance of intelligence in the formation of strategies - but how can that be since in the same post he's advocating information sharing which itself furthers the goal of gathering and using intelligence...

i think it must come down to the knowing oneself half of the intelligence equation... the notion that known malware scanning is a bad idea or outdated or the like has become quite popular and it seems to me that this often forgotten principle is to blame... knowing the strengths and weaknesses of the weapons in your arsenal (or that you could have in your arsenal), appreciating what they can and cannot do, and realizing what they represent strategically and how to deploy them tactically - these are the things people don't seem to understand, not even the CTO of the ISC...

known-malware scanners aren't outdated; they have obvious weaknesses that dictate one's strategy be supplemented with more generic techniques, but they also have considerable strength against a huge (and ever growing) body of malware... for every security defense you deploy there exists a counter-measure, but once the malware implementing that counter-measure becomes known (as all but the most narrowly targetted malware eventually does) it should no longer be able to sneak past known-malware-based defenses... known-malware scanning is weak against the counter-measure of novelty, but that's a counter-measure that expires...

in more simple terms: known-malware scanners are a form of information sharing between anti-malware experts and the rest of the world... throw that information away if you want, but at least realize what you're doing when you're doing that...

Tuesday, March 14, 2006

why virtual machine based 'rootkits' won't be the next big problem

ok, ignoring the issue of what rootkits really are for the moment, let's examine this idea of rootkits that are so low level they're even below the OS...

first, as greg hoglund points out you're pretty much guaranteed to notice the performance hit when your entire OS gets dropped into a virtual machine...

second, as pointed out on the f-secure blog it's actually been done before over a decade ago, back when stealth was still called stealth...

but really, i think i'm going to go them both one better (at least) and say that we solved the full stealth problem over a decade ago... that solution was called booting from a known clean bootable floppy disk and scanning with a known virus scanner...

"but kurt, how are we supposed to use our generic rootkit detection technology if the rootkit isn't active?" - simple, you aren't... those sorts of generics require the malware to be active, which gives it a tactical advantage (it's able to actively defend itself then)... it also allows the malware to know more about the security application than the security application knows about the malware, which is another tactical advantage for the malware... if you're unfamiliar with what sun tsu had to say about engaging the enemy when you're at a disadvantage then i suggest you go do your homework right now... you can't rely solely on generics that way - known-malware techniques (know your enemy) must be employed in an environment and under conditions of your choosing in order to maximize your tactical advantage, and the generics are then used in a supporting role to partially cover what that strategy can't...

now, those of you who've been following things for a few years now you probably know that microsoft screwed that option up with the advent of NTFS... no version of MSDOS is capable of parsing an NTFS partition natively and microsoft seems unwilling to do much about that - probably because so far there really hasn't been that great a need these days... however, should the need arise a fair amount of effort has gone into correcting microsoft's oversight... things like bart's pe disk, NTFS4DOS, or any one of the many recovery oriented live-cd linux distributions can give you access to an NTFS partition after booting from a known clean bootable medium...

all in all, the majority of what's being said out there about microsoft's subvirt and the technology it represents is just hype... in the very unlikely event that anyone ever actually bothers trying to deploy it in the wild, it's an old problem that we've had a solution for for some time now...

[obligatory terminology rant]
of course all of this is one of the consequences of the rootkit redefinition... it clouds the issues in both the rootkit problem-space and the stealth problem-space... we wouldn't be forgetting this history if stealth was still called stealth, and then maybe the brain-trust at microsoft wouldn't have to spend untold millions reinventing the wheel that we already know how to deal with...
[/obligatory terminology rant]