A significant problem currently faced in the field of immunology is the proliferation of bacteria which have gained resistance or tolerance to antibiotics. Bacteria can gain resistance or tolerance by a number of different methods; 1) by evolving genes which allow them to survive, 2) by acquiring genes via from other bacteria (transduction by a bacteriophage or conjugation [e.g. horizontal gene transfer]), or 3) uptake of genetic material from the environment (transformation). Bacteria such as these are responsible for a large number of infections that are difficult to treat and are becoming more common in environments such as hospitals. Methicillin-resistant Staphylococcus aureus (MRSA) is one such example. Although MRSA is resistant to most antibiotics, it has a lower fitness than non-antibiotic resistant Staphylococcus aureus (Staph) in an environment without antibiotics. This trait means that if the antibiotics treatments are stopped, the common forms of Staph will out compete and replace MRSA as the dominant form of bacteria in a colony.
It is possible that such observations could lead some people within the information security community to believe that possibly reducing the barriers to malware could cause malware to become less sophisticated or more easy to observe and subsequently easier to remediate. Although this is a possibility, it is unlikely since the costs involved in maintaining genes are different than those in maintaining attack strategies. Evolutionary trade-offs or costs manifest themselves in different ways. They are paid by the reduction of the fitness of an organism. An organism is said to have a higher fitness with the more off-spring that survive into subsequent generations. An organism which must reallocate resources away from the production off-spring runs the risk of reducing its fitness. As an example, removing resources away from reproduction to defense, reduces the theoretical number of off-spring and organism can produce. Defensive strategies can allow an organism to survive and reproduce. Mutations in a genome cause an organism to reallocate resources and depending on the phenotypic effects, they can increase or decrease the fitness of an organism. Evolutionary costs can be thought of as having three different costs and benefits: 1) there is a cost of evolving a strategy (e.g. the costs associated with the creation of a new strategy), 2) there are developmental costs of a strategy (e.g. the specific implementation of within an organism), and 3) there is a cost for maintaining a strategy (e.g. the day-to-day costs associated with maintaining a strategy or maintaining the ability to utilize a strategy). These three costs combined with the benefits of maintaining a set of strategies work in conjunction to raise or lower the overall fitness of an organism.
With bacteria, the reduction of any non-essential genes results in an increased fitness as the costs associated with replication are reduced. The replication of a smaller genome utilizes less resources than the replication of a larger genome. This reduction means that anytime a gene can successfully be removed from the bacterial genome without reducing its fitness, it will benefit for the bacteria to do so as it will reduce the costs associated with replication. This process is referred to as genome economization and has been observed with the Mimivirus in a controlled laboratory setting and the resulting genome reduction in an environment in which its competitors have been removed. In the case of tolerance or resistance genes, the costs to the bacteria are greater than just occupying a portion of the genome and increasing its size. There are production costs associated with tolerance or resistance genes. These genes create proteins and the production of these proteins consumes resources that the bacteria could have utilized elsewhere. Beyond the simple consumption of resources due to the production of these proteins, these proteins that are being produced can interfere with common intracellular functions. All of these factors combined mean that bacteria can make substantial gains in fitness if they are able to remove these genes when they are no longer required. In the case of malware or the tools of determined attackers, the replication and storage of the software used is not a significant issue. In the case of exploits with stagers or malware with droppers being able to remotely load software the advantages of maintaining a smaller code base are not a limitation as resources can be remotely accessed as needed. Actually having a smaller code base to utilize during an attack can limit the options of an adversary as they may not be able to try all of the possible avenues of attack. Blind application of the strategies and methods used by organism for survival may not function as expected within information security without understanding the costs and trade-offs associated with these strategies. The adaptations that bacteria and other micro-organisms utilize for dealing with evolutionary costs are different than those encountered within information security.
Another thing to consider is that even if antibiotics are not applied in the environment to reduce the population of tolerant or resistant bacteria, it does not mean that the human immune system is not going to react to an infection. A substantial portion of the human genome is dedicated to the immune system. Of the entire genome (estimated at 27,478 genes), it is estimated that there are approximately 1,562 genes are dedicated to the immune system. This quantity of genes represents a significant amount of resources dedicated to fighting pathogens. Furthermore when the immune system is actively fighting a pathogen an average metabolism of a human host increases by 14%. Maybe simply reducing the application of security controls to fight malware is not the best solution.
Looking at the issue of bacteria gaining tolerance and resistance from a different perspective may provide another insight into the issue. The problem is not that MRSA exists in the environment but it exists within an environment in which the potential hosts are already suffering from weakened or compromised immune systems. The resistance of MRSA means that the application of traditional antibiotics is ineffective. It seems that the main issue is that MRSA already has the tools to defend itself against the common defenses in that environment. To rephrase this, MSRA has the tools to persist in the prevailing environmental conditions otherwise it would not have survived. From the perspective of information security, attackers have already acquired the necessary tools and techniques to persist in the common computing environments otherwise they would not be successful. Furthermore the tools and techniques that have used previously in compromising similar security controls means that if those security controls are encountered else where they can also be compromised as they have been primed with the necessary experience.
Instead of reducing the security controls in an enterprise to possibly make the detection and remediation of malware based on observations of various bacterial adaptations to antibiotics, security should instead attempt to understand how the environment is being prepared for attackers and focus on making it more difficult for attackers to persist in the enterprise.
Showing posts with label evolutionary cost. Show all posts
Showing posts with label evolutionary cost. Show all posts
Wednesday, July 6, 2011
Wednesday, July 29, 2009
Extinction and End Games
Recently Jeff Moss gave an introduction to the opening of Black Hat DC 2009, in which he essentially asked "is there any problem in security that has been definitively crushed or completely eradicated? Is there a problem from 10 years ago that is no longer a concern?" Specific instances of problems have been eradicated but the families of problems that persist include computer viruses, buffer overflows, cross site scripting (XSS), SQL injection (SQLi), etc. Computer viruses have existed since 1971, buffer overflows were popularized in 1996, XSS has been around since about 1997, and SQLi has been present since 1998.
Managers and security professionals are often looking for that silver bullet for solving all of the information security issues that an organization may have. Vendors of security products are often willing to demonstrate that their single or integrated security solution will provide all of the protection that an enterprise needs against emerging threats, the next generation of attacks, etc.
As information security is engaged in a Red Queen race or an evolutionary arms race, there should be no expectation that a single or multiple strategies can always ensure the survival of an organization. The security controls that are put in place will act as selection pressures on their adversaries to ensure that only the successful exploitation strategies are passed on to the next generation of attacks. The security controls are going to ensure that attackers and malware authors continue to escalating their exploitation strategies against the implemented security solutions to ensure their survival. This escalatory relationship is akin to the evolutionary arms race between predator and prey.
There are multiple outcomes for predator and prey resulting from an evolutionary arms race (Evolutionary Biology, 3rd Edition, Futuyma);
In order to cause an extinction of predator strategies (or in the case of information security an attacker's or malware author's strategies), it is not necessary to wipe out an entire population in a single event. Within evolutionary biology, an estimate of effective population size is given by the following equation; Pi = P0 * exp([b-d]*t), where Pi is the population size in the future, P0 is the initial effective population size, t is the time, b is the birth rate, and d is the death rate. As long as the birth rate is higher than the death rate, the population size will grow exponentially. If the death rate is higher than the birth rate, the population is shrinking. The birth and death rates are typically associated with environmental factors such as competition for available resources and types of selection pressures. Essentially the environment only has to change faster than the opponent's strategies can adapt.
By inspecting the rate of growth for malware, it appears that the "birth" rate is higher than the "death" rate. The effective malware population (based on the number of unique samples) is growing exponentially. The costs for malware populations have not reached their carrying capacity on the environment. Within evolutionary biology and ecology, the carrying capacity is the population size that a given environment can support based on the available resources. If a population is increasing in size, then the carrying capacity has not been reached as more resource are available to support the growth. As the population approaches the carrying capacity, the population growth decreases as available resources are more difficult to access. If the population exceeds the carrying capacity, the population will reduce in size as selection works against the population and the entities which are not able to extract enough resources to survive.
Ideally, security professionals would like to see the current situation change from being a continually escalating arms race or a cyclic strategy/counter-strategy to that of the extinction of attacker/malware strategies. By changing the selection pressures that are applied against these invasive strategies, it could be argued that extinction can be triggered. A set of selection pressures could be implemented such that nothing could survive or the selection pressures of the environment change so quickly that the invasive strategy does not have time to evolve successful adaptations. Another solution could involve changing local environmental selection pressures independent of the global selection pressures such that only specific strategies can thrive in specific "regions." This strategy is similar to having an organization switch to a different operating system and/or browser, so the commonly employed exploit strategies fail on the organization.
One of the main problems with implementing a strategy to solve the issue drastically changing the environment is that the environment has to change quickly, more quickly than the invasive strategy can evolve adaptations. The current computing environment is not conducive to drastic changes implemented through out the entire infrastructure. Virtualization is often proposed as a security solution, but to implement this solution globally would take years to decades. Most users are not going to upgrade to a virtualized operating system, unless they are going to acquire a new computer. Typically computers are not replaced or even upgraded annually. This represents a significant period of time in which attackers and malware author's can update their strategies and adapt to the new environment. As previously discussed, attackers and malware have the advantage when the environment changes due to their smaller size.
Another method for improving the situation within the Red Queen race that is occurring within information security, would be the attempt to convert the situation into an ESS. In an ESS, there is an equilibrium reached that is resistant to invasion by outside strategies. If this occurred attackers and malware would achieve a balance with the security professionals in which new infections are cleaned at approximately the same rate as they are occurring.
Instead of focusing on the extinction of malware in the near term, another strategy would be to focus on the infectious nature of malware and reducing the associated virulence. In dealing with the interactions between diseases/parasites and their hosts, the virulence of the disease/host tends to be associated with how it is transmitted between the hosts. A disease or parasite that is transmitted from parent to offspring is said to be vertically transmitted though a population. Diseases and parasites that are vertically transmitted tend to have a lower virulence, or exhibit avirulent behavior. If the disease or parasite reduces the host's fitness too much, then they will not be able to propagate to its offspring after/during reproduction, since no offspring will be produced. Horizontally transmitted diseases/parasites jump from host to host in a population through a variety of different mechanisms; direct contact, the environment or a pathogen vector (such as a mosquito in the case of Malaria). As the virulence of the disease/parasite is not dependent on the survival of the host to reproduce, only the contact with other vulnerable hosts, it is capable of reaching a much higher virulence and significantly reducing the fitness of the host.
There are a number of different ways that an evolutionary arms race can play out; it can continue to escalate, it can continue to escalate until the costs associated with the escalation cause the system to stabilize into an ESS, it can develop in cyclic phases such as the case in the interactions between diseases/parasites and hosts with their immune responses, or one of the interacting entities can go extinct as it is no longer able to adapt to the environment. With the rate that the malware population is increasing, it does not appear that the evolutionary arms race has stabilized into an ESS or that malware will go extinct in the near future, so either the escalatory nature of the race will continue or the cyclic interplay between strategy and counter-strategy will continue for the foreseeable future. The strategies employed by attackers and malware authors rely on small easily adaptable applications, which in terms of evolutionary biology means that the can more readily adapt to environmental selection pressures. Instead of causing malware to go extinct, perhaps a way can be found to tie it to the host, and force it to adopt a more avirulent or beneficial behavior by being vertically transmitted through a computer population instead of horizontally transmitted.
Managers and security professionals are often looking for that silver bullet for solving all of the information security issues that an organization may have. Vendors of security products are often willing to demonstrate that their single or integrated security solution will provide all of the protection that an enterprise needs against emerging threats, the next generation of attacks, etc.
As information security is engaged in a Red Queen race or an evolutionary arms race, there should be no expectation that a single or multiple strategies can always ensure the survival of an organization. The security controls that are put in place will act as selection pressures on their adversaries to ensure that only the successful exploitation strategies are passed on to the next generation of attacks. The security controls are going to ensure that attackers and malware authors continue to escalating their exploitation strategies against the implemented security solutions to ensure their survival. This escalatory relationship is akin to the evolutionary arms race between predator and prey.
There are multiple outcomes for predator and prey resulting from an evolutionary arms race (Evolutionary Biology, 3rd Edition, Futuyma);
- The first outcome is that neither side gains the advantage. In this situation, the evolutionary arms race continues with each side escalating their strategies (Richard Dawkins and J. R. Krebs, Arms Races between and within Species, 1979). Within an escalatory arms race, both the predator's weapons and the prey's defenses become more effective than previous generations, but neither has an advantage (G.J. Vermeij, Evolution and Escalation, 1999). More simply stated, as time passes a predator's weapons become more refined, and in response to the evolution of these better weapons a prey species evolves better defenses. The end result is neither side makes any progress, but a modern predator would be able to better exploit an ancestral prey than a predator from that period.
- The second outcome is that as the evolutionary costs for continuing the escalation increase, a set of strategies employed by both sides causes an equilibrium to be established. This equilibrium can form what is referred to as an Evolutionarily Stable System (ESS). In an ESS, a point is reached where the system is stable and resistant to invasion from outside strategies based on the costs associated for each strategy. ESSs are detailed in Evolution and the Theory of Games, by John Maynard Smith, 1982 and in the Selfish Gene by Richard Dawkins.
- The third outcome is that the system suffers from continual or periodic changes as a new strategy is employed and a counter-strategy is evolved and then deployed. This is similar to disease/parasite and host relationships, in which a disease or parasite invades a host. The population takes time to develop resistance or immunity to the invasive disease/parasite. For a period of time the population may be quite successful at repelling the disease/parasite, but eventually the disease/parasite can develop a strategy to overcome the factor that was keeping them out of the host. This is commonly seen as the over use of antibiotics has caused various strains of antibiotic immune diseases to develop; such as Methicillin-resistant Staphylococcus aureus (MRSA) or Extensively Drug-Resistant Tuberculosis (XDR-TB).
- Lastly the outcome of an evolutionary arms race can result in one or both of the species going extinct. One of the sides of the evolutionary arms race evolves an adaptation which allows it to fully exploit or evade exploitation from the other species in a way that it cannot adapt before becoming extinct. Conversely, if the predator was entirely focused on exploiting a single prey species, with the extinction of the prey, the predator species may also collapse.
In order to cause an extinction of predator strategies (or in the case of information security an attacker's or malware author's strategies), it is not necessary to wipe out an entire population in a single event. Within evolutionary biology, an estimate of effective population size is given by the following equation; Pi = P0 * exp([b-d]*t), where Pi is the population size in the future, P0 is the initial effective population size, t is the time, b is the birth rate, and d is the death rate. As long as the birth rate is higher than the death rate, the population size will grow exponentially. If the death rate is higher than the birth rate, the population is shrinking. The birth and death rates are typically associated with environmental factors such as competition for available resources and types of selection pressures. Essentially the environment only has to change faster than the opponent's strategies can adapt.
By inspecting the rate of growth for malware, it appears that the "birth" rate is higher than the "death" rate. The effective malware population (based on the number of unique samples) is growing exponentially. The costs for malware populations have not reached their carrying capacity on the environment. Within evolutionary biology and ecology, the carrying capacity is the population size that a given environment can support based on the available resources. If a population is increasing in size, then the carrying capacity has not been reached as more resource are available to support the growth. As the population approaches the carrying capacity, the population growth decreases as available resources are more difficult to access. If the population exceeds the carrying capacity, the population will reduce in size as selection works against the population and the entities which are not able to extract enough resources to survive.
Ideally, security professionals would like to see the current situation change from being a continually escalating arms race or a cyclic strategy/counter-strategy to that of the extinction of attacker/malware strategies. By changing the selection pressures that are applied against these invasive strategies, it could be argued that extinction can be triggered. A set of selection pressures could be implemented such that nothing could survive or the selection pressures of the environment change so quickly that the invasive strategy does not have time to evolve successful adaptations. Another solution could involve changing local environmental selection pressures independent of the global selection pressures such that only specific strategies can thrive in specific "regions." This strategy is similar to having an organization switch to a different operating system and/or browser, so the commonly employed exploit strategies fail on the organization.
One of the main problems with implementing a strategy to solve the issue drastically changing the environment is that the environment has to change quickly, more quickly than the invasive strategy can evolve adaptations. The current computing environment is not conducive to drastic changes implemented through out the entire infrastructure. Virtualization is often proposed as a security solution, but to implement this solution globally would take years to decades. Most users are not going to upgrade to a virtualized operating system, unless they are going to acquire a new computer. Typically computers are not replaced or even upgraded annually. This represents a significant period of time in which attackers and malware author's can update their strategies and adapt to the new environment. As previously discussed, attackers and malware have the advantage when the environment changes due to their smaller size.
Another method for improving the situation within the Red Queen race that is occurring within information security, would be the attempt to convert the situation into an ESS. In an ESS, there is an equilibrium reached that is resistant to invasion by outside strategies. If this occurred attackers and malware would achieve a balance with the security professionals in which new infections are cleaned at approximately the same rate as they are occurring.
Instead of focusing on the extinction of malware in the near term, another strategy would be to focus on the infectious nature of malware and reducing the associated virulence. In dealing with the interactions between diseases/parasites and their hosts, the virulence of the disease/host tends to be associated with how it is transmitted between the hosts. A disease or parasite that is transmitted from parent to offspring is said to be vertically transmitted though a population. Diseases and parasites that are vertically transmitted tend to have a lower virulence, or exhibit avirulent behavior. If the disease or parasite reduces the host's fitness too much, then they will not be able to propagate to its offspring after/during reproduction, since no offspring will be produced. Horizontally transmitted diseases/parasites jump from host to host in a population through a variety of different mechanisms; direct contact, the environment or a pathogen vector (such as a mosquito in the case of Malaria). As the virulence of the disease/parasite is not dependent on the survival of the host to reproduce, only the contact with other vulnerable hosts, it is capable of reaching a much higher virulence and significantly reducing the fitness of the host.
There are a number of different ways that an evolutionary arms race can play out; it can continue to escalate, it can continue to escalate until the costs associated with the escalation cause the system to stabilize into an ESS, it can develop in cyclic phases such as the case in the interactions between diseases/parasites and hosts with their immune responses, or one of the interacting entities can go extinct as it is no longer able to adapt to the environment. With the rate that the malware population is increasing, it does not appear that the evolutionary arms race has stabilized into an ESS or that malware will go extinct in the near future, so either the escalatory nature of the race will continue or the cyclic interplay between strategy and counter-strategy will continue for the foreseeable future. The strategies employed by attackers and malware authors rely on small easily adaptable applications, which in terms of evolutionary biology means that the can more readily adapt to environmental selection pressures. Instead of causing malware to go extinct, perhaps a way can be found to tie it to the host, and force it to adopt a more avirulent or beneficial behavior by being vertically transmitted through a computer population instead of horizontally transmitted.
Monday, May 4, 2009
Risk Management with an Evolutionary Perspective
Evolutionary biology can provide useful insights into the risk management process that is used in information security. The current risk management process as described in NIST Special Publications 800-30, Risk Management Guide for Information Technology Systems and 800-39 Rev 1 (Draft), Managing Risk from Information Systems, could be summarized simply as: 1) identify the risks present in the environment, 2) counter/mitigate the risks that have been identified, and 3) repeat. This cycle is ultimately reactive in nature as flaws are only uncovered when vulnerabilities or new attacks are announced. SP 800-39 Rev 1 (Draft) is more focused on categorizing a system, and applying a set of requirements based on the system's categorization and security control customization based on tailoring. This methodology requires that the system's sensitivity rating has been appropriately determined and the predefined security controls appropriately address the threat environment.
If the assumption is made that information security is indeed a system which operating under the rules of a Red Queen hypothesis and that the security controls that are implemented are acting as selection pressures on our adversaries, the risk management process appears to be lacking as that there is nothing that takes into account how an adversary will respond to the environmental selection pressures (i.e. implemented security controls).
When a risk is identified, there are a number of ways that it can be handled within the current risk management framework. A risk can be corrected, accepted, mitigated, or transferred/insured. Each of these methods for dealing with an identified risk can be treated as one of the three types of selection pressures: directional, disruptive or stabilizing.
Predicting the resultant strategies is not trivial, but understanding the selection pressures involved may make the situation more manageable. In the case of the SSH brute force and the adoption of Virtualization some strategies can be determined based on the attributes of the strategy implemented. Inspecting the strategies that are found within the natural environment could provide additional insight into how an adversary could respond. Any of the following could also be potential responses.
The current risk management process has weaknesses when it is applied to an environment which evolving. The basic process is reactionary in nature and gives all of the initiative to the adversary and requires that the adversary first advertise their latest strategy before it could be countered. Instead of waiting for an adversary to attack an information system, the risk management methodology should include steps which attempt to determine how the current security strategies will force an adversary to adapt. Based the types of selection pressures that are applied to counter an adversary's strategy, anticipated actions can be made as to how an adversary will be forced to respond. When selecting among several different counter strategies, preference should be given to those strategies which have the highest evolutionary costs to counter (e.g. most likely disruptive selection pressures).
If the assumption is made that information security is indeed a system which operating under the rules of a Red Queen hypothesis and that the security controls that are implemented are acting as selection pressures on our adversaries, the risk management process appears to be lacking as that there is nothing that takes into account how an adversary will respond to the environmental selection pressures (i.e. implemented security controls).
When a risk is identified, there are a number of ways that it can be handled within the current risk management framework. A risk can be corrected, accepted, mitigated, or transferred/insured. Each of these methods for dealing with an identified risk can be treated as one of the three types of selection pressures: directional, disruptive or stabilizing.
- Corrected risks can act as disruptive selection pressures. It is a disruptive selection pressure in the sense that the risk has been removed; an adversary must abandon the strategy that could be used to exploit the system. The adversary will be forced to evolve a new strategy if they are going to continue to exploit the system.
- Accepted risks can act as a stabilizing selection pressure. It is a stabilizing selection pressure in that it encourages an adversary to continue to use the existing exploitation strategy and discourages the use of other strategies in that they will cost resources to evolve and develop (which could be used elsewhere). Some would argue that an entity can also deny that a risk exists in the first place, if so then by default they are accepting the risk and treated it as an accepted risk.
- Mitigated risks can act as either a disruptive or directional selection pressure. If the mitigation causes an adversary to abandon their exploitation strategy it will be a disruptive selection pressure on the adversary. If the mitigation simply causes the adversary to modify their existing strategy it will act like a directional selection pressure.
- Transferred/Insured risks can act as a stabilizing selection pressure. Like accepted risks, transferred/insured risks will not exert a selection pressure on an adversary's strategy which causes them to either modify or abandon their existing strategy. If the risk is transferred or insured, it should be noted that it does not transfer the risk of an incident occurring. Just as when car insurance is purchased, the insurance company does not actually assume the risk of getting into an accident, the driver still carries that and the insurer carries the risk of having to payout out after an incident.
- Disruptive selection pressures are the most likely method to extract the highest evolutionary cost from an adversary in that they will force them to not only evolve/develop a new exploitation strategy, but also waste the effort of continuing to maintain a strategy that may not succeed.
- Directional selection pressures will tend to exert minimal evolutionary costs on an adversary, as they must only modify an existing exploitation strategy to continue to be successful. The adversary does not need to abandon their existing strategy or develop a new strategy, just refine an existing one. There is an evolutionary cost associated with this but it will be less than if they had to abandon their current strategy and evolve a new one.
- Stabilizing selection pressures will tend to cost an adversary the least, as they do not need to modify their current strategies therefore experiencing no change in to their evolutionary costs. There may be evolutionary costs associated with stabilizing selection pressures as the maintenance of an adversary's strategies may have a cost associated with them. Stabilizing selection pressures are not likely to force an adversary to incur any additional evolutionary costs as they have already adapted to the environment, but even then an adversary may be able to reduce their costs further by evolving a more efficient method for existing in the environment.
Predicting the resultant strategies is not trivial, but understanding the selection pressures involved may make the situation more manageable. In the case of the SSH brute force and the adoption of Virtualization some strategies can be determined based on the attributes of the strategy implemented. Inspecting the strategies that are found within the natural environment could provide additional insight into how an adversary could respond. Any of the following could also be potential responses.
- Some organisms have developed adaptations which advertise to others that they are something they are not, or they are poisonous. An adversary could mimic the behavior of the system employed. Malware such as Anti-Virus 2009 or Anti-Virus 360 appears to be anti-virus software which protects a user from attacks on the Internet when instead it is actually a Trojan.
- Like parasites subverting the central nervous systems of hosts, an adversary could exploit the strategy that is used to help the system survive. Malware can attempt to exploit vulnerabilities in anti-virus software to attack a system, as anti-malware software usually operates as a privileged service making it a priority target since it has access to the entire system in addition to protecting the system.
- Some animals have developed better camouflage to help mask there presence in the environment. A smaller and less noisy profile means that an attacker is less likely to detect their presence. Malware is moving to HTTP command and control channels to help mask its presence in the traffic being sent across the network.
- Another response is to completely abandon the current strategy, and develop a new strategy which catches an organism unprepared. As part of an experiment in evolutionary biology, a predatory lizard was introduced onto several islands which were inhabited by Anoles. Initially the average length of their legs increased, which allowed them to survive by running faster to evade their predators. Eventually the average leg length decreased as the Anoles were able to avoid their predators entirely by spending more time in the trees. Malware can react to countermeasures by simply avoiding the countermeasures entirely or attacking an information system at different layers. A worm can be written to exploit web applications instead of targeting flaws in the operating system.
- Sometimes the best response is not to respond to the strategy employed. If the counter strategy will only be infrequently encountered, it is often more cost effective to ignore it. In the case of the natural environment some predators that interact with prey populations interact so infrequently that it is more effective to not response as a population then to evolve a response. Malware authors should be aware that almost all analysis of their binaries will be conducted in a virtualized environment, yet not all malware encountered is able to detect when it is operating in a virtualized environment.
The current risk management process has weaknesses when it is applied to an environment which evolving. The basic process is reactionary in nature and gives all of the initiative to the adversary and requires that the adversary first advertise their latest strategy before it could be countered. Instead of waiting for an adversary to attack an information system, the risk management methodology should include steps which attempt to determine how the current security strategies will force an adversary to adapt. Based the types of selection pressures that are applied to counter an adversary's strategy, anticipated actions can be made as to how an adversary will be forced to respond. When selecting among several different counter strategies, preference should be given to those strategies which have the highest evolutionary costs to counter (e.g. most likely disruptive selection pressures).
Wednesday, April 8, 2009
Monoculture/Heterogeneous Computing and Resource Exploitation
Using the same baseline, configuration, or technologies throughout an industry can reduce costs through ease of maintenance and deployment. It can foster information sharing as all parties involved communicate using the same formats and standards. Within cryptography, using standards and certified products allows others to gain a level of assurance regarding the trustworthiness of an algorithm or product. Reliance on the same computing platform/practices is referred to as monoculture. Despite the benefits of operating within a monoculture, there are a significant number of risks associated with it.
Looking at monocultures in information security from an evolutionary biology perspective, there are significant risks. In terms of evolutionary biology, a monoculture represents a large population which is composed of the same characters and utilizes the same strategies for survival. This represents either a lack of genetic diversity or genetic variability within the population. Genetic diversity represents the number of characters that are present within a population, while genetic variability represents the individual tendency of individual characters to vary from one another. Variation of characters within a population is one of the four conditions that is required for natural selection to operate (Evolution, 3rd Edition by Ridley and Evolutionary Biology, 3rd Edition by Futuyma). Without any variability in a population, it follows that when selection operates on a population it will either select against the entire population or select for the entire population. There is no intermediate state without variability. This does not mean that every selection event will cause the population to go extinct, but the potential for an event exists.
An entire population that is dependent on the same survival strategy is vulnerable to exploitation. If an entity is capable of finding a way to exploit the strategy used, then it has found a method which is capable of exploiting the entire population. If the population of hosts can either be easily accessed by the attacker or the hosts are in frequent contact with on another, the attacker leverages the exploit effectively such that it can spread rapidly through the entire population before a counter measure can be developed. As this entire population is employing the strategies, it can take a significant period of time before the entire population is inoculated against the exploit.
Currently the 'Cavendish' banana population is at risk from the fungus Fusarium oxysporum (i.e. Panama Disease or Agent Green) due the monoculture environment in which it is cultivated. Panama Disease already caused the collapse of the previous 'Gros Michel' crop in the 1960s. Originally the Cavendish banana population was resistant to the Panama Disease, but in 1993 a new strain (referred to as Tropical Race 4) emerged and has since contributed to the collapse of the Cavendish population of bananas in Southeast Asia. This is not the only case of a monoculture impacting a food crop. Previous to the banana monoculture, there was a potato monoculture in Ireland. In the early 1800s, Ireland was dependent on the potato crop to feed their population. Potatoes were essential clones of one another, and eventually the mold Phytophthora infestans exploited and destroyed a majority of the 1845 potato crop and one and a half million of people died from starvation.
Currently there exists a monoculture environment within computing associated with Microsoft Windows operating system; the dominant operating system in the market. A majority of the attacks on the Internet have focused on this operating system, as there is an abundant population which can be exploited.
The alternative to monoculture in information technology is a heterogeneous computing environment where there are different operating systems and applications are in use. The result is a diversified environment in which a single strategy is incapable of compromising the entire environment by exploiting the operating system or applications. Monocultures within the information technology are not just limited to the operating system. The heterogeneous computing environment associated with cell phones and mobile devices is seen as providing protection from malicious software despite their being 3x the number of mobile Internet-capable devices connected to the Internet as compared to computers.
The risks associated with a monoculture are present at all levels of computing where the same resources and standards are used. Monocultures can exist at other levels such as network architectures, office automation applications, email services/clients, web browsers, application/web servers, web application frameworks, and databases. In addition to the possible application level monocultures, hardware and standard/protocol level monocultures exists. Common protocol monocultures found in networking and the Internet include: IP, TCP, HTTP and DNS.
At BlackHat USA 2008, a DNS flaw which had been discovered earlier in the year was released to the general community. This flaw took advantage of the DNS standard and since most implementations followed all of the recommendations in the standard, they were vulnerable to exploitation from this flaw.
Although web applications can differ in their implementation, their reliance on the same back-end database technology (and a lack of input validation) allowed a large number of sites to be compromised by a SQL injection worm. The worm targeted websites which used Microsoft SQL Server as their database.
Monocultures pose a risk to information systems when they exist at any level. A system may have different web browsers deployed in its environment, but if the browsers are all running on the same operating system, exploits can target the operating system and bypass the heterogeneous browser level. As far back as 2004, there have been vulnerabilities announced which can successfully attack the underlying operating system even if different web browsers are interpreting the data.
Applying evolutionary biology to information security with respect to monocultures, it can be seen that relying on an environment of monoculture can be dangerous. Monoculture environments have little genetic variability which allows them to survive selection events, and they are vulnerable to invasion from diseases which can devastate the entire population. The implementation of a heterogeneous computing environment allows an information system more resistance and increases the likelihood of surviving an attack as an attack is not capable of exploiting an architectural or implementation flaw present entire population.
Looking at monocultures in information security from an evolutionary biology perspective, there are significant risks. In terms of evolutionary biology, a monoculture represents a large population which is composed of the same characters and utilizes the same strategies for survival. This represents either a lack of genetic diversity or genetic variability within the population. Genetic diversity represents the number of characters that are present within a population, while genetic variability represents the individual tendency of individual characters to vary from one another. Variation of characters within a population is one of the four conditions that is required for natural selection to operate (Evolution, 3rd Edition by Ridley and Evolutionary Biology, 3rd Edition by Futuyma). Without any variability in a population, it follows that when selection operates on a population it will either select against the entire population or select for the entire population. There is no intermediate state without variability. This does not mean that every selection event will cause the population to go extinct, but the potential for an event exists.
An entire population that is dependent on the same survival strategy is vulnerable to exploitation. If an entity is capable of finding a way to exploit the strategy used, then it has found a method which is capable of exploiting the entire population. If the population of hosts can either be easily accessed by the attacker or the hosts are in frequent contact with on another, the attacker leverages the exploit effectively such that it can spread rapidly through the entire population before a counter measure can be developed. As this entire population is employing the strategies, it can take a significant period of time before the entire population is inoculated against the exploit.
Currently the 'Cavendish' banana population is at risk from the fungus Fusarium oxysporum (i.e. Panama Disease or Agent Green) due the monoculture environment in which it is cultivated. Panama Disease already caused the collapse of the previous 'Gros Michel' crop in the 1960s. Originally the Cavendish banana population was resistant to the Panama Disease, but in 1993 a new strain (referred to as Tropical Race 4) emerged and has since contributed to the collapse of the Cavendish population of bananas in Southeast Asia. This is not the only case of a monoculture impacting a food crop. Previous to the banana monoculture, there was a potato monoculture in Ireland. In the early 1800s, Ireland was dependent on the potato crop to feed their population. Potatoes were essential clones of one another, and eventually the mold Phytophthora infestans exploited and destroyed a majority of the 1845 potato crop and one and a half million of people died from starvation.
Currently there exists a monoculture environment within computing associated with Microsoft Windows operating system; the dominant operating system in the market. A majority of the attacks on the Internet have focused on this operating system, as there is an abundant population which can be exploited.
The alternative to monoculture in information technology is a heterogeneous computing environment where there are different operating systems and applications are in use. The result is a diversified environment in which a single strategy is incapable of compromising the entire environment by exploiting the operating system or applications. Monocultures within the information technology are not just limited to the operating system. The heterogeneous computing environment associated with cell phones and mobile devices is seen as providing protection from malicious software despite their being 3x the number of mobile Internet-capable devices connected to the Internet as compared to computers.
The risks associated with a monoculture are present at all levels of computing where the same resources and standards are used. Monocultures can exist at other levels such as network architectures, office automation applications, email services/clients, web browsers, application/web servers, web application frameworks, and databases. In addition to the possible application level monocultures, hardware and standard/protocol level monocultures exists. Common protocol monocultures found in networking and the Internet include: IP, TCP, HTTP and DNS.
At BlackHat USA 2008, a DNS flaw which had been discovered earlier in the year was released to the general community. This flaw took advantage of the DNS standard and since most implementations followed all of the recommendations in the standard, they were vulnerable to exploitation from this flaw.
Although web applications can differ in their implementation, their reliance on the same back-end database technology (and a lack of input validation) allowed a large number of sites to be compromised by a SQL injection worm. The worm targeted websites which used Microsoft SQL Server as their database.
Monocultures pose a risk to information systems when they exist at any level. A system may have different web browsers deployed in its environment, but if the browsers are all running on the same operating system, exploits can target the operating system and bypass the heterogeneous browser level. As far back as 2004, there have been vulnerabilities announced which can successfully attack the underlying operating system even if different web browsers are interpreting the data.
Applying evolutionary biology to information security with respect to monocultures, it can be seen that relying on an environment of monoculture can be dangerous. Monoculture environments have little genetic variability which allows them to survive selection events, and they are vulnerable to invasion from diseases which can devastate the entire population. The implementation of a heterogeneous computing environment allows an information system more resistance and increases the likelihood of surviving an attack as an attack is not capable of exploiting an architectural or implementation flaw present entire population.
Friday, March 6, 2009
Evolutionary Costs and the Life/Dinner Principle
As illustrated previously, the time it takes to evolve strategies and/or the ability to exploit existing environments (or a population) is important. An additional factor that should be considered when examining exploits are the associated costs. Within evolution these items are referred to as the evolutionary costs.
There are costs associated with utilizing a strategy, evolving a new strategy, and neglecting the use of an existing strategy.
When dealing with the costs of employing strategies for survival, it should be noted that the costs for all entities involved are not shared equally. This potential asymmetry is summed up in the life/dinner evolutionary principle (as popularized in both the Selfish Gene and the Extended Phenotype written by Richard Dawkins, but originated by M. Slatkin in Models of Coevolution). Slatkin uses the rabbit and fox from one of Aesop's fables to illustrate the basic idea of the asymmetrical costs in association with life/dinner principle.
Consider the case when a rabbit is being chased by the fox. The rabbit is running for its life, while the fox is only running for its dinner. The cost of failing is different for those involved. For the rabbit, if it fails it looses its life, while for the fox; if it fails it only looses its dinner. So the rabbit is going to be willing to spend more to ensure its survival in a given race, because if it is unsuccessful there will not be another generation of rabbits produced (at least from this rabbit's germ line). The fox can afford to lose this specific race; as if it fails it will have an opportunity to pursue another rabbit in the future.
It could be argued that if after several of these races and the fox remains unable to catch a rabbit, then it could very well be facing its final race too. This is true, but if you compare the costs associated with a single race, the rabbit is still going to face the more severe cost of failure.
Within this co-evolutionary race, the rabbit/fox race can pursue a number of different strategies to ensure their survival. The simplest way to continue the race would be that the fox can attempt to run faster as well as the rabbit can attempt to run faster. It is important to consider that this is not the only strategy that the rabbit can pursue; it could also develop better camouflage, better sensory systems to learn of the foxes presence before he comes too close, or even become more maneuverable so that if the fox does pursue him he can out maneuver the fox and escape, or the rabbit can just produce so many rabbits that in general the likelihood of a single individual becoming dinner is small. In general which ever method becomes more prominent in the rabbit population, the fox will have to escalate his attacks to deal with these new strategies.
Although the co-evolution is occurring in the rabbit/fox competition, there are costs and trade offs associated with each of these potential advancements. Obviously as we do not see rabbits that can run arbitrarily fast (out side of cartoons and comics). In order to evolve a strategy, there are costs associated with this development. The development takes resources that could have been devoted to creating or even just maintaining something. In the security field there are trade offs which must be considered, and the penalties for not maintaining the proper balance of strategies can be just as severe for an information system as it is for a rabbit.
The penalty asymmetry is commonly seen in the development of an information system. When a system is designed, it has to address all of the threats that will be present in its environment, but an attacker only needs to find one successful strategy to compromise the system. An attacker also has additional advantages;
Although there are response lags to develop or deploy new strategies and it takes time to exploit other resources. There are costs for developing, maintaining and even using evolutionary strategies. These evolutionary costs are also not necessarily paid evenly by all involved in the red queen race.
There are costs associated with utilizing a strategy, evolving a new strategy, and neglecting the use of an existing strategy.
- In utilizing a strategy, an entity must pay the costs of maintaining that strategy. It should be recognized that in employing or retaining the capability of a strategy consumes resources that could have been spent elsewhere.
- Evolving a new strategy also consumes resources, and those resources have to be taken from another source. They are going to come from resources that could have been spent to refine another strategy, develop a different strategy or continuing the usage of a existing strategy (i.e. allowing a current strategy to atrophy).
- Lastly neglecting the use of an existing strategy could have the cost of preventing an organism from surviving from the fact the organism may have misspent resources. Not using an existing strategy could adversely affect an entity in that the resources consumed during development a new strategy could have been used elsewhere to form a necessary new strategy (and are considered to have been wasted in this effort).
When dealing with the costs of employing strategies for survival, it should be noted that the costs for all entities involved are not shared equally. This potential asymmetry is summed up in the life/dinner evolutionary principle (as popularized in both the Selfish Gene and the Extended Phenotype written by Richard Dawkins, but originated by M. Slatkin in Models of Coevolution). Slatkin uses the rabbit and fox from one of Aesop's fables to illustrate the basic idea of the asymmetrical costs in association with life/dinner principle.
Consider the case when a rabbit is being chased by the fox. The rabbit is running for its life, while the fox is only running for its dinner. The cost of failing is different for those involved. For the rabbit, if it fails it looses its life, while for the fox; if it fails it only looses its dinner. So the rabbit is going to be willing to spend more to ensure its survival in a given race, because if it is unsuccessful there will not be another generation of rabbits produced (at least from this rabbit's germ line). The fox can afford to lose this specific race; as if it fails it will have an opportunity to pursue another rabbit in the future.
It could be argued that if after several of these races and the fox remains unable to catch a rabbit, then it could very well be facing its final race too. This is true, but if you compare the costs associated with a single race, the rabbit is still going to face the more severe cost of failure.
Within this co-evolutionary race, the rabbit/fox race can pursue a number of different strategies to ensure their survival. The simplest way to continue the race would be that the fox can attempt to run faster as well as the rabbit can attempt to run faster. It is important to consider that this is not the only strategy that the rabbit can pursue; it could also develop better camouflage, better sensory systems to learn of the foxes presence before he comes too close, or even become more maneuverable so that if the fox does pursue him he can out maneuver the fox and escape, or the rabbit can just produce so many rabbits that in general the likelihood of a single individual becoming dinner is small. In general which ever method becomes more prominent in the rabbit population, the fox will have to escalate his attacks to deal with these new strategies.
Although the co-evolution is occurring in the rabbit/fox competition, there are costs and trade offs associated with each of these potential advancements. Obviously as we do not see rabbits that can run arbitrarily fast (out side of cartoons and comics). In order to evolve a strategy, there are costs associated with this development. The development takes resources that could have been devoted to creating or even just maintaining something. In the security field there are trade offs which must be considered, and the penalties for not maintaining the proper balance of strategies can be just as severe for an information system as it is for a rabbit.
The penalty asymmetry is commonly seen in the development of an information system. When a system is designed, it has to address all of the threats that will be present in its environment, but an attacker only needs to find one successful strategy to compromise the system. An attacker also has additional advantages;
- They do not have the expectation that they are not going to compromise every system they encounter. If they were unsuccessful in exploiting the initial target, they can move on to another system. It is built into their strategy, that they will not compromise every system they encounter only just enough to find dinner.
- They have time to attempt multiple strategies against the system and continue using different combinations of strategies until they find one that works.
- They do not have to play by the rules. Even more than that they have no expectation that they are going to stay within the design requirements of the system.
Although there are response lags to develop or deploy new strategies and it takes time to exploit other resources. There are costs for developing, maintaining and even using evolutionary strategies. These evolutionary costs are also not necessarily paid evenly by all involved in the red queen race.
Labels:
asymmetry,
evolutionary cost,
life/dinner principle,
red queen
Subscribe to:
Posts (Atom)