Bolting on security is the best we can [generally] do, so grab a wrench
We all know the adage that security should be built-in, not bolted on. This would work great if our threat models perfectly reflected reality, and adversaries never adapted. Sadly, the real-world doesn't fit into a neat specification and design document, and adversaries alter their tactics. When looking at cyber-security as a dynamic game, defenders must adapt to survive--bolting on security is the only way to circumvent new attacks or stymie adversaries.
Regardless of how much faith you put into the fear-mongering AI hype machine, we've all seen the world we work in shift, and designing for easier updates, changes, and enhancement without impacting UX is the way forward. My entire career has been spent adding in security after-the-fact, so join me as I:
- Explore the reasons security is hard and cannot be solved
- Highlight wins where security has been added after the fact
- Look at how designing for future security augmentation helps our future selves bolt-on security more quickly
- A few areas where security can be designed in, and how lumping those areas with general cyber-security harms their outcomes
As someone who's spent their career adding security after, it's time to push back. Software, AI, and the stacks they run on are too complex for anyone to understand. For the first time, humankind has built machines (software & AI) we cannot fully fathom, high-dimensional spaces beyond comprehension. Unconstrained by the laws of physics, software can realize M.C. Escher's most outlandish dreams. These bizarre spaces lack the grounding needed to fully "design-in" security from the get-go, so we have to design for ability to adapt down the road.
More hopefully, the areas of software where they have a real-world, physical impact can be re-grounded. These system are the most dangerous to get wrong, but thankfully can be one of the easiest to make safe. By splitting up cyber-security into those that need rapid adaptation (bolt-on security), and those that have physical grounding, we can design for better outcomes for both.
Join me as I reflect from various perspectives among the community, and where I think we should go next.
Jacob is the Head of Labs at Thinkst Applied Research. Prior to that he managed the HW/FW/VMM security team at AWS, and was a Program Manager at DARPA's Information Innovation Office (I2O). At DARPA he managed a cyber security R&D portfolio including the Configuration Security, Transparent Computing, and Cyber Fault-tolerant Attack Recovery programs. Jacob has been a speaker and keynote at conferences around the world, from BlackHat, to SysCan, to TROOPERS and many more.