The Need for Open Research in Software Security
breakingbits.net
breakingbits.net
https://news.ycombinator.com/item?id=9012051
http://www.cbsnews.com/news/darpa-dan-kaufman-internet-secur...
Dylan, seeing that you're in NY, I'd be happy to talk this over with you over a few beers at the next NYSEC: https://twitter.com/nysecsec
Also, I'll take you up on that offer. I've been meaning to make an appearance there for a while.
Second, investing in security R&D is not that risky if you know who to partner with. There are many organizations whose sole purpose for existence is to fund foundational->applied R&D across a variety of fields. You seem to have mentioned none of these opportunities in your blog post?
Third, if you're a software developer and you really care, the tools already exist to write secure code. However, there are few to no incentives to use them! I actually disagree somewhat that more R&D is needed on the security side. It's an inaccurate characterization of the state of the art in security and the degree to which people take advantage of it.
For exampleeeee, Mayhem has found and reported hundreds of bugs in Debian and did the work to submit bug reports with reproducible crashes and POCs. I think < 10 of the bugs they reported were fixed. I can't find the link right now, but the exact systems you referenced are being used out in the open to help people and no one is listening.
I can't address your first point because I agree with it - part of the reason I'm pessimistic is because there isn't a strong business model.
However, I think that it's hard to know who to partner with. For all the organizations that you can partner with to produce fruitful research, you have many who are trying to make a quick buck on the trendiness of security. We don't have a lot of Mayhems. We have a lot of Acunetixes.
I agree that the methodologies and tools required to write secure code already exist. However, I don't think it's fair to place all the onus on software developers. Even if they avoid C/C++, they still have modern pitfalls in just about any language.
I think more research should be done on security software of course, which is why I wrote this blog post. What my post doesn't address however is that I also believe more research should be done in educating developers. It doesn't matter if all the tools to help them exist if few of them bother to look for them. Research could help in this regard - education.
Finally, I think you're much more familiar with Mayhem than I am, but I call into question the bugs Mayhem found. How many were high severity and/or actually exploitable? (I'm actually asking because I've seen conflicting reports from both Mayhem and Michal Zalewski on the matter).
When I say being used in the open, I mean in a similar way to Project Zero's activities. Mayhem was used once on Debian as far as I'm aware, and to my mind it looks more like publicity than an ongoing effort to find bugs.
Exploitable? Every. Single. One. Each came with a unique PoC demonstrating control of execution.
> However, I think that it's hard to know who to partner with. For all the organizations that you can partner with to produce fruitful research, you have many who are trying to make a quick buck on the trendiness of security. We don't have a lot of Mayhems. We have a lot of Acunetixes.
This sounds like you simply haven't investigated where or how to get money for R&D!
[1]: https://github.com/programa-stic/barf-project
Fortunately, there's money to be had for open source and research projects that are willing to organize and look elsewhere for some cash. Look at projects like Bro and Suricata -- commercial security tools which are government and educator funded.
We need more security engineers, but the problem is I don't even know what that job title requires. The author pokes fun at CISSP, but how else can I figure out if someone is 'good' at security? They are already so rare and mostly employed by google (joke).
I'm the author.
If you are hiring a security consultant for your firm and you know how to judge infosec skill, use a work sample and check references.
If you're hiring a security consultant to perform a penetration test or audit for your (non-infosec) company, hire people who have a healthy mix of the following:
1. Public, verifiable work (e.g. bug bounties).
2. Solid references and past experience with clients who themselves understand what to look for in a security consultant. You obviously check these references. Alternatively, a solid reference that the candidate worked at NCC Group, Accuvant, Leviathan, etc.
3. Research in the field, such as discovering a new class of vulnerability, publishing vulnerabilities in ubiquitous software, etc.
Prioritize #2, because not all adept security folks like to conduct research or participate in publicly verifiable work.
Of the certifications you can have, the Offensive Security[1] certs are pretty rigorous. For example, the OSCP is a good indicator that a candidate knows what they're doing to offensively test a client's network. That's about it. Almost all other certifications are run by people who have, at best, textbook knowledge of information security. People who get the CISSP can probably accurately describe a cross-site scripting attack to you in an interview, but there is no guarantee they can practically find it or defend against it.
The other issue is that while some certifications are good, a lot of folks in infosec just don't care for them. They can find high paying jobs in prestigious companies without a degree or a certification of any kind, so they simply don't bother, even though they could pass it. This means that you can't reliably throw out candidates with no certifications...which circles back to my original recommendation. Work samples, references and public work are the best ways to judge a candidate's talent. I'm directly aware that this system is used at Matasano and Accuvant, and it's likely the norm at the other "quality" security consultancies.
'tptacek would have a lot of great advice to contribute on this matter as well.
[1]: https://www.offensive-security.com/information-security-cert...
That being said, Microsoft should open source MAGE. It's sounds cool.