One of the seminal movies that all cybersecurity professionals should watch is of course War Games. It features a young hacker, played by Matthew Broderick, who almost starts a nuclear war when he starts playing war games with a central military computer.
While the premise itself seems improbable, the concept of playing war games isn’t new. The many arms of government do it. Large corporations do it. This concept has also made its way into the cybersecurity world—cyber war games to test one’s security infrastructure. In a red team and blue team engagement, the red team attacks and the blue team defends to validate readiness. In the cybersecurity world, war games can range from table top exercises to actual live exercises where attack scenarios are simulated.
To date, most of the cyber war exercises have been deployed by governments to test both public and private sector infrastructures, or large corporations with the time and resources to support them. But as attacks become more sophisticated and automated, and attackers more greedy, the need for all organizations to at some level understand and experience the mind and method of hackers is becoming more urgent.
The mindset of an attacker
The fundamental premise behind this is simple. To better defend yourself, you need to put yourself in the mindset of an attacker. It’s about learning from the hackers and understanding their behavior -- and understanding how your own actions (or inaction) affects the outcome. Most importantly, it is about proactively executing real breach scenarios on your network to find holes before an attacker does, and understanding what vulnerabilities are most pressing for you.
This mindset makes sense. After all, we spend more than $70B in cybersecurity, yet we continue to be breached. The latest Mandiant report states that organizations take almost 205 days to discover breaches in their network -- only a marginal improvement from the year before. No surprise, the latest PWC Global State of Information Security report shows that we’re seeing more security incidents in 2015 than last year: 38% more security incidents were detected in 2015 than 2014 and the theft of “hard” intellectual property increased 56%.
It doesn’t feel like we’re winning, does it? One reason is the current reactive approach to cybersecurity – if and when a new threat is exposed, a new security solution is deployed. Each of these point products requires a unique management system and configurations that needs to be optimized. Complexity impacts security.
The biggest challenge for CISOs today is not waiting for a vendor to offer a solution to their problem; it’s prioritizing their efforts (amidst a talent shortage), understanding which of their security systems are working as expected, and knowing what their cybersecurity risks are at any one point in time. How does a CISO answer the board-level question of “Are we secure”? The answer is combining current approaches with an offensive security approach that adopts the mindset of the hacker.
But first, there are specific characteristics of the hacker that we need to understand:
Cyber war games of the future
When we look at these characteristics, it’s clear we need automation to more effectively (and continuously) execute war games -- with an emphasis on the word “war.” So many security strategies and solutions today are focused on individual battles. You can win some, but not all, and in cybersecurity, one loss can cost you the war.
At the same time, breach methods must be supported by a human element that understands and can analyze patterns, tactics, and procedures. In a kill chain model, breaking one step thwarts the adversary; proper analysis and understanding of how attackers are behaving and their techniques can only be performed by skilled security professionals.
In other words, the cyberwar games of the future will be played by machines powered by humans. It is the combination of human plus platform/machine that will tip the advantage towards the defenders. Just like Amazon’s Chaos Monkeys in the cloud world where failures occur to force systems to be more resilient, we need to proactively execute breaches in our environment to find holes -- before an attacker does.Danelle is vice president of strategy at SafeBreach. She has more than 15 years of experience bringing new technologies to market. Prior to SafeBreach, Danelle led strategy and marketing at Adallom, a cloud security company acquired by Microsoft. She was also responsible for ... View Full Bio