Feeds

Q: Why do defenders keep losing to smaller cyberwarriors?

A: 'Ant smarts' not 'asymmetry'

5 things you didn’t know about cloud backup

Forget everything you've read on The Reg or anywhere else about wars that target computer networks, power grids and other essential electronic infrastructure because it's loaded with fallacies, a prominent security consultant said Wednesday.

Contrary to conventional wisdom, the damage from cyberwar can kill people, and those who wage it aren't as anonymous as most security experts and military advisers claim, Dave Aitel, CEO of Immunity said during a talk at the 20th Usenix Security Symposium in San Francisco. But the biggest myth of all, he submitted, is the idea that cyberwar inevitably favors the opponent, allowing people with modest means to inflict disproportionate mayhem on much larger opponents.

“People assume the current asymetricness, the current offense-seems-to-be winning feature of the internet, is built in and it's not,” he said during his 90-minute talk, which was titled “The Three Cyber-war Fallacies.” “This is a danger for attackers as well, because attackers can get lulled into a false sense of security. You have the advantage because you got lucky and the current field is on your side, but that changes quickly.”

Aitel said that contrary to the oft-repeated claim that cyberwar is “non-kinetic,” its effects include real physical effects that can be every bit as devastating as a bomb blowing up a bridge. He held up the ability of the Stuxnet worm to sabotage centrifuges used in Iran's uranium enrichment program as a prime example.

“People miss the message of Stuxnet, which wasn't: 'I blew up your nukes, I'm cool,'” he said. “The real message was: 'I can take out any factory you have at any time I choose.' That's a much scarier message.”

He also tried to debunk the idea that cyberwar is different from conventional war in that it's often impossible to attribute the party that's waging an attack. Attributing actors in more traditional war theaters is often tough, and security researchers often find plenty of clues about those behind sophisticated threats, he explained.

But Aitel saved his most biting criticism to challenge the notion advanced by a chorus of renowned security analysts – Bruce Schneier and Deputy Secretary of Defense Michael Lynn by name – that the fundamental characteristics of the internet and critical infrastructure allow a handful of well-trained operatives to wage guerrilla warfare campaigns against much larger adversaries.

He also criticized a keynote given at last year's Black Hat security conference in which Retired US General Michael Hayden referred to critical systems as “Poland on the web, invaded from the west on even-numbered centuries, invaded from the east on odd-numbered centuries.”

“None of this is inherent in the cyber domain,” Aitel said. “You don't have to be dumb, but just because you are doesn't mean you have to do it in the future.”

He held up the so-called ”smart meters” being deployed by the state of California as one example of the kind dumb behavior exhibited by defenders of criticial infrastructure.

“The unfortunate thing is that price pressure means you're going to [build meters] with chips that cost about a half cent,” he said. “So the smartness has to be very very minimal. We're talking about ant-level smarts at best, and that doesn't lead its way to security.”

At times, Aitel's talk seemed to digress into asides that undermined his premise. The ability of attackers half a world away to take out any factory they choose whenever they want only seems to strengthen the point that cyberwarfare is indeed asymmetrical. And he blithely referred to Google's Chrome OS as “a much more secure platform,” despite recent research showing it's vulnerable to many of the same devastating attacks that have plagued websites for a decade.

Aitel seemed to approach his speech (slides to which are here) as a series of Zen koans for the security set that was geared more toward making them grasp new ideas than providing them with practical observations about how people defending critical systems should operate differently.

But when pressed to do just that during a question and answer session, he offered some pithy advice.

“Very few corporations have the organization structure now which will say: 'All new things we buy we run through a security team. If it doesn't meet our mark, the security team can neg it.' That's a very painful thing to do for an organization, but you have to have that if you're going to move forward in any secure way.”

He continued:

“Obviously, the defenders can make the decision not to run this crap, and it's a very easy one to make.” ®

Next gen security for virtualised datacentres

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.