I want to juxtapose 2 classes of group successful the information manufacture connected the defender broadside of security engineering for products. The first are the Security arsenic Identity people. This goes backmost to the security-as-counterculture attitude, glamorized successful Hackers and making love backmost to telephone phreaking. It reflects Thompson’s “Workism”, wherever activity is not conscionable a measurement to gain a living, but a measurement to build a consciousness of identity, purpose, and community. In the lawsuit of security, this personality tends to beryllium built astir being different, seeing things different group do not, and being clever successful an edgy and misunderstood way. Someone who is beyond simply a information professional, but has the persona of a Hacker. Stylish outsiders smarter than the system. Detectives uncovering insights others miss.
There’s thing incorrect pinch the hacker ethos. The thought of uncovering places wherever systems break down and activity successful unexpected aliases incorrect ways is evidently highly valuable. Careers, conferences, and master communities each reward vulnerability discovery, the much astonishing the better. Similarly, the hacker artistic is what it is. At this point, it’s mainstream. Around 25,000 group be DEF CON each year.
Valuing unexpected insights is not only a hacker thing. In the 2000s, the book Freakonomics was highly popular. It besides took the shape of proposing astonishing explanations for seemingly straightforward aliases different unremarkable societal phenomena. If you tin find thing unexpected, you must beryllium very smart and cool! But should astonishment really beryllium a awesome of intelligence? You tin return that cognition moreover farther, and do a Paul Graham style “it turns out” misdirection. Instead of saying you judge successful Y, opportunity you expected X, investigated, and it turns retired that Y is true. That way, you don’t person to warrant Y, you conscionable opportunity X is false.
The personality you take matters beyond aesthetics. Problem definitions inherently transportation an associated worldview, and it’s very difficult to alteration a worldview, peculiarly if you’ve built your identity, community, and occupation astir that worldview. Evidence for solutions that reside the underlying problem, but not successful a measurement that validates the worldview, tin beryllium rejected. As a actual example, Nordhaus and Shellenberger reside this nonaccomplishment mode for ambiance alteration activism successful their notorious “Death of Environmentalism” effort from 2004. Environmentalists wanted to get group to work together to protect “the environment” arsenic a expected “thing”, a typical liking deserving of good, that should person method argumentation interventions successful bid to beforehand it, specifically. This meant solutions needed to return the shape of being related to “the environment”, for illustration cap-and-trade and c emanation limitations. Solutions that resulted successful the desired result of little greenhouse gases, but were not sufficiently “environmental”, specified arsenic decreasing cleanable power costs (even pinch accrued usage), higher-yield agriculture (not conscionable integrated farm-to-table), and the thought that technological substitution tin activity amended than behavioral modification, were rejected. Ironically, successful the 2 decades since the arguable essay, we tin spot that galore of these rejected solutions are the ones yet played out. Improvements successful star and artillery technology, alongside electrical cars and different renewables, galore of which had authorities subsidies successful the 2010s, did much to trim greenhouse emissions than the policies that validated the accepted worldview of environmentalism successful the 2000s.
In security, solutions that do not look for illustration many times discovering, exploiting, and patching technically awesome vulnerabilities whitethorn beryllium overlooked if they do not fulfill the worldview of the Security arsenic Identity person, peculiarly if they would alternatively enactment arsenic a detective than arsenic a mechanic. An attacker mindset and a coherent threat exemplary are important to building unafraid systems. But while necessary, are they complete? And are they moreover a bully starting point? We do not thatch group to navigator by telling them to “think for illustration a chef”.
This brings america to the 2nd people of person, the Security arsenic Robustness people. It turns out, immoderate group successful information are chiefly motivated by building correct systems that sphere their desired properties, including during nonaccomplishment conditions, separator cases, and inconsistencies. Security is portion of building a well-engineered strategy that operates decently successful each conditions, including successful the look of an attacker.
To exemplify the difference, let’s look astatine really group deliberation astir vulnerability rewards programs (VRPs), besides known arsenic bug bounties. What’s the constituent of a VRP? At minimum, a VRP serves arsenic a constituent of interaction for information issues specified that they tin beryllium patched successful merchandise earlier they are leveraged by attackers. If you tally a sufficiently ample merchandise (or, successful particular, a platform), you will person group interaction you pinch information issues. At slightest immoderate of the information reports will beryllium valid, and require patches. A VRP is simply a modular process for this that forces the statement to person the expertise to respond to some outer and soul information bug reports, revenge by group different than the individual characteristic teams moving connected immoderate portion of the product. It financially incentivizes participants to study bugs to you successful a measurement that’s productive for you. There’s a very straightforward economical statement to opportunity the VRP is successful truthful agelong arsenic the number of bugs recovered increases faster than the comparative payout prices. The much bugs recovered by the VRP, the better.
Beyond bug uncovering and patching, VRPs tin and should beryllium utilized to pass the strategy of the information team. The VRP is arsenic adjacent to a replacement for the domiciled of the customer successful the modular attack to merchandise guidance arsenic you tin get. Attackers aren’t your users, and the afloat group of insecurity is an chartless unknown. While it won’t enumerate the full onslaught surface, the VRP is simply a repeated and accordant measurement to summation penetration into attacker methodologies and validate the activity of the information team, specified that you tin bound the size and effect of the chartless unknowns. What types of bugs are showing up successful the VRP, wherever successful the merchandise are they occurring, why are they happening, and what teams ain them tin each beryllium inputs to a information roadmap that should beryllium building towards a early wherever the bugs are rare. VRPs are besides a two-way street. Vulnerability researchers respond to incentives, truthful if the information squad wants to validate a presumption to warrant immoderate information initiative, they tin besides tweak the rules and rewards successful the VRP to incentivize submissions that either validate the presumption and tin beryllium utilized arsenic collateral to warrant the roadmap to different teams and leadership, aliases that show the presumption was incorrect. If the VRP results propose the roadmap is not attached to reality, the information squad tin cull the presumption and effort thing different. One of the champion things astir a VRP is that what bug hunters look for is not constrained by the beliefs of the group who activity connected the product.
When the VRP is utilized arsenic an input to a broader strategy, the overarching extremity of a VRP is not to afloat enumerate each bugs and frankincense person a unafraid product. The constituent of a VRP is to grapple pinch the insecurity. Arguably, dealing pinch bugs that travel externally done the VRP is the worst imaginable measurement to prioritize those bugs, because it is inherently interrupt-driven and not capacity-managed by the teams that spot the bugs. Patching VRP bugs is different lawsuit of playing whack-a-mole. Actually securing thing remains the work of the information team, who should beryllium making judge that either the bugs can’t hap (e.g. via safe coding), aliases that the bugs don’t matter anymore (e.g. done architectural changes that little impact). This favoritism pinch VRPs, betwixt enumerating each bugs versus informing a strategy to trim insecurity complete time, is the litmus trial for Security arsenic Robustness.
There’s a polarity successful that uncovering much issues moreover quicker is good, because it is amended to find things and spot them than to ne'er cognize location were problems, but it is besides bad because it is grounds that your strategy is not moving arsenic intended. Finding problems is simply a diagnostic metric. It proves that your sensor is working. Tracking incidence of types of problems is an result metric. Ensuring that the aforesaid type of problem is not happening many times complete and complete again is the existent motion of success.
Every bug aliases incident is simply a failure, and while failures do happen, we should beryllium huffy astir it if they are happening each the time, moreover if we are responding to them very fast. Outside of security, see tract reliability engineering (SRE). If a work is consistently having downtime aliases different errors that break the SLO and devour the correction fund eventually, an SRE team, under the original meaning of the term, is empowered to halt characteristic improvement and releases, move resources towards reliability alternatively than features, and activity pinch the merchandise squad to build and deploy systemic fixes. Once SLO compliance is backmost wrong the correction budget, merchandise activity continues. In different words, the superior semipermanent extremity is robustness, quickly resolving SLO non-compliance incidents is secondary. The SRE attack is not whack-a-mole, but it does require alignment astatine the activity level for erstwhile the SRE squad is allowed to intervene and perchance interrupt the goals of the merchandise team.
Unfortunately, it is acold excessively easy successful information for whack-a-mole to go the goal. It’s awesome astatine the metrics and compliance crippled because you tin make a chart of resolved incidents going up and to the right. Maybe moreover time-to-resolution going down complete time! It besides requires little organizational alignment than intervening successful the roadmaps of different teams, making it easy to person the quality of a information squad that owns its ain destiny. Taking ownership of existent information outcomes is scary, because attackers are unknown. But playing whack-a-mole is losing.
Every mole that is whacked is an opportunity for an attacker. Optimizing for reacting to issues, only to resoluteness them quickly (and successful immoderate cases, whack the aforesaid hole over and over and over again) tin make it consciousness for illustration you’re succeeding, erstwhile you’re really losing. Winning is not having issues successful the first place. The only point amended than a chart of resolved incidents complete clip that goes up and to the right, is simply a chart of incidence of immoderate bug people complete clip that goes down and to the right, approaching zero. Recognizing that uncovering and patching vulnerabilities is simply a accomplishment that a information squad needs, but not a bully northbound star, tin beryllium scary if your profession and worldview are built astir information being uncovering clever bugs that different group can’t see. This tin lead to hostility where, if you person built your personality astir the problems, past immoderate solution starts to look for illustration an onslaught connected your identity. The logic why you sewage into information will often effect really you deliberation astir the problem and, arsenic Nordhaus said, your worldview and solutions will bespeak that. Are you successful information because you for illustration uncovering unexpected insights and solving puzzles, aliases because you want to build systems and information is 1 of the astir absorbing places to build them?
The cognition that information is simply a counterculture astir unexpected insights is prevalent capable that moreover if you haven’t built your personality astir it, group who are not chiefly moving connected information deliberation a bunch of brilliant hackers is what it intends to person a successful information team. Unfortunately, if your cognition of information is that it is astir searching for insecurity, it seems improbable that you’ll ever build a unafraid system. You’ll conscionable support playing whack-a-mole until yet you illness nether your ain weight.
The hacker mindset whitethorn thief you understand really a strategy fails, and if that nonaccomplishment tin beryllium leveraged for nefarious means, but information is much than uncovering the insecurity. A bully information squad is reasoning critically astir underlying causes and systemic fixes, and wants to triumph by building a strategy that is fundamentally amended than before. Beyond articulating attacker capabilities and threat models and past searching an efficaciously unbounded hunt abstraction for problems, much defenders should specify invariants astir what should beryllium existent astir a system. Breaking these invariants is bad whether aliases not an attacker does it. Good information teams are looking for deviations from good, alternatively than trying to hunt for the bad. In galore cases, these invariants tin beryllium implemented successful codification done languages, interfaces, and safe abstractions, and enforced successful CI utilizing devices as elemental arsenic grep. Other invariants whitethorn beryllium enforced done architecture and operational controls. A vulnerability is grounds that immoderate invariant is missing, wrong, aliases unenforced. Success intends continually updating and encoding these invariants truthful that full classes of vulnerability extremity recurring.
Verifiable properties of a strategy are needed moreover much successful the property of AI agents. Vulnerability find is presently the cheapest it has ever been. Agents besides thief pinch remediation, though not arsenic efficaciously arsenic astatine vulnerability discovery. At first glance, if AI is making find and remediation cheaper than ever before, possibly a reactive attack tin yet scale? But moreover pinch AI, whack-a-mole is still losing. A cheaper diagnostic does not inherently alteration the outcome. If you tin ever find different bug, the marginal use of patching the adjacent 1 is zero.
The conventional wisdom astir the “vulnpocalypse” is that we’re successful a section minimum, wherever information indebtedness from the past 30 years is each being called successful astatine once. Once we get done patching that, eventually, package will beryllium overmuch much unafraid wide and the expected costs of uncovering and exploiting a vulnerability will spell up.
This will only beryllium existent if we return an progressive domiciled successful really improving things. A amended early does not simply happen, you person to bring it into existence. Things do not get amended without effort, and successful this instance, Jevons paradox is fighting to support the position quo. Using agents, you tin take to simply play whack-a-mole moreover faster. At the aforesaid time, package engineers are utilizing agents to write exponentially much code. While the token costs of “scanning” for vulnerabilities will spell down complete time, the complexity and costs of doing truthful will spell up alongside the lines of code, which are expanding exponentially, suggesting that AI vulnerability hunting will person the aforesaid shortcomings arsenic fuzzing for defenders. After the first group of vulnerabilities popular out, it’s exponential costs for defenders to effort to enumerate each vulnerabilities, but only polynomial costs for attackers to find useful vulnerabilities. For a sufficiently ample project, solely utilizing AI to find vulnerabilities will ne'er consequence successful a early wherever vulnerabilities are rare.
This doesn’t person to happen! Defenders besides person coding agents and vulnerability hunting agents. Now is the clip to leverage them to place and reside systemic issues that let you to forestall vulnerabilities by construction. You cannot bug hole your measurement retired of the vulnpocalypse. We only get the bully result if we take to make things better, alternatively of choosing to play much whack-a-mole. For AI to scale, defenders request to beryllium capable to articulate the invariants of the system, and past leverage AI to instrumentality verifiable enforcement of the invariants. This besides helps the non-security engineers utilizing AI, who will person much verifiable outcomes for their ain coding agents, enabling much productive agent-driven development.
Producing an endless watercourse of findings is not a bully usage of information expertise, quality aliases AI. If each you do is play whack-a-mole, you’re going to lose. We should not position information arsenic an endless proviso of mysteries to lick because being a detective is the weighted identity. Instead, the domiciled of defenders is to move failures into new, broader, and stronger invariants, and to encode these invariants into the strategy truthful that engineers (and agents) don’t person to perpetually rediscover the aforesaid people of problems. If that result feels for illustration a loss, it’s because personality has displaced information arsenic the goal.
Thank you to Ryan Lopopolo for first saying “Don’t you see? We tin play whack-a-mole moreover faster now!” to me. Thank you to Dev Akhawe, Alex Clemmer, Alex Gaynor, and Matt Riley for feedback connected early drafts of this post.
English (US) ·
Indonesian (ID) ·