Security is hard; we are facing big challenges. At the same time, we are seeing that security strategy driven by dogma is failing. Acknowledge if your strategy isn't working, and accept defeat.
So said Adobe's CSO, Brad Arkin, during his keynote address at the Microsoft Security Development Conference, in San Francisco, this week.
"If your strategy is failing, ask yourself what you are trying to solve, and what your real problems are. Then ask how is your work getting you there? If it's not, then change tactics for a chance of success," he said.
Fixing and fuzzing
The first dogma Arkin discussed is that finding and fixing all vulnerabilities in a code base is effective. "This is a waste of time. Focusing on vulnerabilities is a distraction. Focus instead on mitigation."
He said attackers seek to minimise their exploit development costs. "If your product is no longer the easiest to attack, the bad guys will change targets."
Arkin advises to make the target less attractive. "Vulnerability reduction does not change attacker costs; mitigations do, and really drive up the costs for attackers. An attacker's first exploit represents the bulk of his investment. The initial work is the hard part. Tweaks to the initial exploit to support other attack vectors are cheap."
He cited the introduction of sandboxing technology in the rendering engine of Reader Version 10 as an example. "With Version 9, we had a lot of attacks. Version 10 added sandboxing, a mitigation layer that resulted in the attackers needing their privileges escalated to get out of the box. Ultimately, it wasn't worth the effort for them.
"In early 2009, we did a big security stand down with Reader, aimed at improving security. We found and fixed many, many bugs. Finding a bug takes minimal effort. Discovering whether that bug is exploitable takes a little more. Fixing the bug is the real work. We put too much effort into fuzzing and fixing, and at the end of the day, it made no real difference. Nothing changed, we still got attacked."
The Version 10 release saw attackers moving away from Version 9, but the mitigations in Version 10 made it an unattractive target. For the attackers, said Arkin, it wasn't worth investing in new exploits.
The takeaway here, explained Arkin, is to redirect resources from fixing to mitigation. There will always be another bug. The cost goes up for the defender, and down for the attacker: mitigation changes that cost equation.
"Change your assumptions. Admit if your current strategy isn't working. Decide what you are trying to achieve, and reframe the problem," he concluded.

