The Cybersecurity Canon: Rise of the Machines: A Cybernetics History

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Bob Clark: Rise of the Machines: A Cybernetics History (2016) by Thomas Rid

Executive Summary

As cybersecurity practitioners we have a lot to read simply to stay current in our industry. However, after reading the latest threat reports, flash releases, CERT notifications, CVEs and products on emerging technology, we should seek to develop ourselves as complete practitioners. This is one of those books. Understanding our history, and how we got here, makes you a better practitioner with a broad base of knowledge. And hell, who doesn’t love a book that talks about the HAL9000, Arthur C. Clarke, Playboy articles, Omni magazine, AT-ATs, Terminator, Karel Čapek’s R.U.R. (the 1920 Czech play that gave us the word “robot”), Blade Runner, Whole Earth Catalog, Mary Pranksters and acid trips, the counterculture of San Francisco, and finally, finally, lets us all quote the real origins of that much-maligned term “cyber.” Rise of the Machines: A Cybernetics History covers it all, including the arts, literature, and trends in pop culture.

The author, Thomas Rid, is a professor in the Department of War Studies at King’s College London and the author of Cyber War Will Not Take Place and War and Media Operations. Professor Rid’s research is extensive as he takes us through the history of cybernetics, the merging of man and machine starting with cybernetics foundations in Norbert Weiner’s writings in the 1940s and moving through each subsequent decade, including the West Coast techno-libertarians’ addition to the theory, ending with an extensive look at what Rid calls the first cyberwar.

As Matthew Kirschenbaum states in his review:

Rise of the Machines is a sweeping intellectual history, engagingly written and brought to life by numerous details and anecdotes. Cybernetics and its progression of offshoots — cybernation, cyberculture, cyborgs, cyberspace, cyberpunk, cypherpunk, and finally cyberwar — are all disentangled and demystified in its pages.

Cybersecurity Canon candidate books are supposed to be essential to the cybersecurity practitioner, and it’s great to be steeped in your specific knowledge that makes you an expert. However, it is well-rounded practitioners who will distinguish themselves among their peers; reading this book will definitely accomplish that goal.

Review

I confess, any book that can properly define the word “cyber” – I’m all for it, especially with so many practitioners and policy wonks misusing the term. Rid recognizes this and, therefore, uses this historical look to help us all understand where, when and how to use the prefix “cyber.” Rid immediately helps the industry, correctly stating that “cyber” is a prefix being slapped onto anything to make it more techie or interesting. He goes on to answer the oft-asked question, “where did cyber come from?” He slams the door shut on that perpetuated myth we’ve all heard and repeated that cyber is the child of William Gibson’s Neuromancer. “Cyber” was first used as in “cybernetics” a general theory of machines from the early 1940s; it was about computers, control, security, and the ever-evolving interaction between humans and machines.

Rid builds the book’s narrative through eight main chapters that are organized chronologically: Automation, Organisms, Culture, Space, Anarchy and War. Cybernetics found its beginnings in Norbert Wiener’s foundational Cybernetics or Control and Communication in the Animal and the Machine (1949) that became improbable bestsellers. Using this as a launching point, Rid looks at cybernetics through the decades to include not only the technological advances but also the philosophical developments dealing with advances in merging machines with humans. Others mentioned, who come and go along the way, include John von Neumann, Gregory Bateson, Stewart Brand, Timothy Leary and Jaron Lanier.

Developed from the mind of MIT mathematician Norbert Wiener amid the devastation of World War II, the cybernetic vision looked at the merging of man with the future of machines. This need to combine man and machine to improve our defenses and man’s capability to fight looks at the early advances in war-fighting capabilities, not only man becoming engaged with various machines but also computer systems developed, such as our air defense system SAGE – one would say, the predecessor to NORAD.

The 50s and early 60s see the same focus, making technology that can increase man’s power and strength to include fighting devices developed for the war in Vietnam and walking machines that never got past prototypes but preceded the AT-ATs of Star Wars. Ultimately cybernetics finds two competing factions: some seeking to make a better world – Bay Area denizens/libertarians hoping for a new unregulated and uncontrolled digital space – and some seeking to control it (i.e., Washington, DC).

In the 60s and 70s the technology side of the cybernetics movements, changes with the Bay Area’s introduction into drugs, rock and computers. Rid details the rise of this movement including the numerous influencers from the West Coast, including the birth of the Electronic Frontier Foundation, a great organization for defending civil liberties in the digital world.

As the Bay Area movement subsides, the 80s did bring us Gibson’s cyberpunks and “Rid takes us back inside the green machine — the military, specifically the U.S. Department of Defense, aligning the precepts of the AirLand Battle that was supposed to defeat Warsaw Pact tank armies in the 1980s and the post-Desert Storm revolution of military affairs with cybernetic arts of war.” We also see the rise of unfulfilled promises of cool “virtual reality” devices, the prototypes of which were clunky at best and looked like “Dark Helmet” from Mel Brooks’Spaceballs. And let us not forget what the 90s brought us, of course: the crypto wars and introduction of cypherpunks.

Finally, Rid finishes up with a topic near and dear to his heart and extensively researched: moonlight maze, as many U.S. government folks called the first state-on-state cyberwar. (Cyber-espionage is what it should have been classified.) Ironically Matt Kirschenbaum compares Rid’s discussion on this subject with Fred Kaplan’s in Dark Territory, also reviewed by me and on the Canon website. Kirschenbaum believes Rid presents this information much more deeply than Kaplan. And while I know Rid’s research is extensive, I thought both covered it equally well with Kaplan painting the Russian’s actions much better. Then again, I think it fit better into Kaplan’s book and was treated appropriately in Rid’s.

Of course “the climax of the book is its discussion of the complex of public fears around an Electronic Pearl Harbor (the language is Hamre’s), a phrase whose staying power Rid sees as evidence of the machines at their apogee.”

Conclusion

Rise of the Machines: A Cybernetics History will not make you more proficient in your cybersecurity job, unless you’re a policy wonk. What this book will do is make you a better practitioner, well-versed in “the rise of the machine.” And if your promotion comes down to advancing an SME who can speak solely to his/her area of expertise or promoting one that, all things being equal, is more well-rounded then this book will definitely accomplish that and give you knowledge to be used as a cyber-professional. (See how I did that? I used “cyber” as a prefix before “professional.” Tom Rid would be proud – I think.)

[Palo Alto Networks Research Center]

Rejoice! Eight New Books Inducted into the Cybersecurity Canon

I am very excited today to announce the 2016 inductees into the Cybersecurity Canon: our hall of fame for cybersecurity books.

2016 March Madness Winner & Cybersecurity Canon Inductee

2016 Inductees selected by the Cybersecurity Canon Committee

The goal of the Cybersecurity Canon Project is to identify a list of must-read books for all cybersecurity practitioners — be they from industry, government or academia — where the content is timeless, genuinely represents an aspect of the community that is true and precise, reflects the highest quality and, if not read, will leave a hole in the cybersecurity professional’s education that will make the practitioner incomplete.

The Cybersecurity Canon Project is not simply a list of books you should read. Indeed, no book makes it onto the candidate list unless a security practitioner makes the case in a book review that we publish on the website, proving the case that this book should be read by all members of the cybersecurity community. Then, a committee of 10 security professionals decides which books make it into the Canon each year. Anybody can submit a book review for consideration. If the committee thinks you made the case, then we add the book to the candidate list.

The Cybersecurity Canon Project has been going on for three years now. The first year, 2014, we had approximately 20 books in the candidate list and selected one to be inducted into the Canon: “We are Anonymous” by Parmy Olson. The second year, 2015, we had approximately 30 books in the candidate list and selected four (See the 2015 list below). This year, we had 45 books in the candidate list and selected eight. We added a twist to the selection process this year by opening up the voting to the Internet in a March Madness type competition. After six rounds of voting, “Zero Day” by Mark Russinovich emerged as the clear and popular winner.

At the awards ceremony, some of the authors received their awards on stage, signed their books for the Ignite 2016 crowd, and shared details about their books in video interviews with members of the Cybersecurity Canon Committee (Stay tuned for videos from the interviews):

  • Dawn M. Cappelli
  • Richard Clarke
  • Marc Goodman
  • Jack Freund
  • Jack Jones
  • Andrew P. Moore
  • Kevin Poulsen
  • Randall F. Trzeciak
  • Liis Vihul

Winners From Previous Years

2015 Inductees selected by the Cybersecurity Canon Committee

  • “Countdown to Zero Day” by Kim Zetter
  • “The Cuckoo’s Egg” by Clifford Stoll
  • “Spam Nation” by Brian Krebs
  • “Winning as a CISO” by Rich Baich

2014 Inductees selected by the Cybersecurity Canon Committee

  • “We are Anonymous” by Parmy Olson

Get Involved

The Cybersecurity Canon Project is a worthy educational endeavor. If you know someone who is trying to learn about what it means to be a cybersecurity professional, consider pointing him or her to our list of books for professional development. If you have a book that guided you in your career, please consider writing a book review for it so that we might get it on the candidate list. Finally, the 2017 Cybersecurity Canon season begins in June. We have a couple of open slots left for the committee. If you are as passionate about cybersecurity books as we are, please reach out to the Cybersecurity Canon committee and tell them you want to volunteer.

[Palo Alto Networks Research Center]

The Cybersecurity Canon: Advanced Persistent Threat Hacking: The Art and Science of Hacking Any Organization

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Dawn-Marie Hutchinson: Advanced Persistent Threat Hacking: The Art and Science of Hacking Any Organization (2014) by Tyler Wrightson

Executive Summary 

In Advanced Persistent Threat Hacking, cybersecurity expert Tyler Wrightson reveals the instruments of attack needed to compromise any target in a well organized and easily digestible format. This book is a must read by both the technical cyber security professional and the board level executive seeking to further understanding of cyber security risks.

Review

The book discusses the strategic issues that make all organizations vulnerable, providing noteworthy empirical evidence and supporting technical detail. Wrightson artfully describes the motives, methodologies and weaknesses that allow an attacker access to an organization, shedding light on both the technical and non-technical methods of hacking. The singular theme of the book is to highlight the relative ease with which an attacker can gain the necessary skill to perpetrate an attack.

Wrightson defines threats, motives and attack methodologies that are arguably foundational components of hacking and as applicable today as they were when we first began combating threats. The unique five-phased tactical approach to advanced persistent threat (APT) hacking is presented with real-world examples and hands-on techniques that are well understood by the ethical hacker community. Wrightson also provides perspectives around the role, strategies, tools and limitations of the penetration tester versus that of the APT actor, explaining why the threat actor is more effective at leveraging what one could argue are the same toolset. This book serves as a strong resource guide for both technical and non-technical audiences in building and defining security programs and strategies.

Wrightson provides empirical data that point to the imbalance of the defensive and offensive maneuvering and the relative costs to both, demonstrating that the attacker has the advantage in almost every circumstance. Enemies assaulting organizations have reduced the cost of attacking so significantly that it requires very few resources, time or skill to compromise an organization. Wrightson goes on to debunk the economic argument behind the goal of impermeability and sets the stage for valuable content surrounding the risk management process. The core competency of a business is not often security, neither is security the key revenue driver; therefore, decisions must be made relative to the cost of controls and the mitigation of risk such that the core business functions are not impaired. This section alone makes the book a must-read for security leadership, executives and boards of directors.

The book’s organization enhances readability for all audiences. Each section provides a high-level business discussion followed by a technological overview, data and examples. Additional, highly developed technical content is available further into the book, allowing the author to take the content deeper and provide additional value for the advanced cybersecurity professional. This broad accessibility of the content enhances its value to the cybersecurity community and provides the greatest value to non-technical stakeholders, who must become conversant in security as a matter of business necessity, and advances the discipline of cybersecurity.

The book creates a common understanding of existing vernacular around advanced persistent threats. By defining the APT by threat class – motive plus capability – the author paints a clear picture of the attacker and, ultimately, illuminates elements of the dark web to enable organizational conversation. The time the author takes to ensure that all readers are operating with the same understanding may be arduous to some, but it solidifies the book’s value as a communication vehicle for a broader audience and, subsequently, enhances future risk management discussions from the board level down.

Conclusion

Advanced Persistent Threat Hacking provided challenging and thought-provoking content in an easily digestible and palatable manner. I liked Wrightson’s approach, the layout of information, and the ways that he challenged existing viewpoints on the subject. I’m recommending this book for the Cybersecurity Canon because I think the vast majority of the strategies, tactics, techniques, tools and attacks defined in this book will remain effective instruments of compromise for the foreseeable future. Establishing the common language of advanced persistent threats and facilitating conversation among a broader audience make this book a must-read for the business executive and cybersecurity professional alike.

[Palo Alto Networks Blog]

The Cybersecurity Canon: Dragnet Nation

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Cybersecurity Canon Committee Member, Hannah Kuchler: Dragnet Nation (2014) by Julia Angwin

Executive Summary

Two tectonic shifts that helped create the data-rich Dragnet Nation where we live today both date back to 2001, argues Julia Angwin in her powerful treatise on privacy.

The U.S. government began its mass data collection efforts in earnest after the terrorist attacks of September 11, 2001, when traditional surveillance methods failed. Meanwhile, technology companies, reeling from the dotcom crash, turned to data as their hope for more sustainable revenue and profits.

In Dragnet Nation, the author, an award-winning investigative journalist, tackles both government and corporate mass surveillance, stressing that they are “deeply intertwined”. “Government data are the lifeblood of commercial data brokers. And government dragnets rely on obtaining information from the private sector,” she writes.

Review

Fifteen years on, we now live in a world where billions of dollars are made off the back of data collected from sites and apps where we read, chat and shop online, and hundreds of thousands of jobs depend on it. What would once have horrified – a newspaper filled with gay interest ads delivered only to a homosexual reader – is now expected on sites such as Google and Facebook.

Angwin excels at putting this new race for data dominance in historical context. She shows how even the most benign data collection tools, such as the census, were used for ill during both world wars, tracing draft violators and tracking down Japanese Americans.

She travels to Berlin to examine the records of the world’s most pervasive secret police, who had 1 in 4 East Germans working as informants for them. While there, she shows an administrator in the Stasi archives how easy it is to build a picture of an individual’s social connections using sites such as LinkedIn – far easier than it was for the Stasi.

The bulk of the book is a tale of Angwin’s journey to reduce her online footprints, to escape the dragnet by minimising tracking of her location, her contacts, and her shopping habits. She meets characters and companies trying to create technologies that could help her and others evade the data trawl of corporations and the government.

For a reader with little knowledge of the privacy tools she describes, the book could almost function as a how-to guide. In particular, the chapter where she finally manages to peak her children’s interest in privacy would be engaging for many parents struggling to make keeping safe online as fun as sharing everything with friends on social networks.

But this is a guide accompanied with heavy doses of disappointment as Angwin finds even experts struggle to create effective technologies and make them usable.

This is a New York Times bestseller aimed at making privacy accessible, not providing in-depth knowledge for cybersecurity professionals. Angwin’s descriptions of her debates about using PGP and other encryption types may not be particularly relevant within the industry.

However, for those wishing to better understand the behaviour of people who profess to care deeply about privacy but struggle to act, Angwin is bracingly honest. She explains how frustration led her to bad passwords, her struggle to balance disconnecting with having to be available for work and childcare emergencies, and how she felt she lost more than she gained when she took herself off major social networks, even having to cancel a birthday party when few bothered to decrypt her invite.

Dragnet Nation is also worth reading for its conclusion. After a year investigating how to keep away from ever-watching eyes as an individual, Angwin concludes that collective action is necessary to rewrite the rules of the digital data game.

She believes that mass efforts to evade surveillance could spark a conversation and a campaign akin to the protests that helped lead to a reduction in pollution in the U.S. Comparing better rights to privacy to improved air and water quality, she tries to give hope that using the Internet will not always have to mean giving up the right to a private life.

Angwin points to the idea of “sousveillance”, or surveilling the surveillors, as one nascent movement that has changed the balance of power in some situations, for example, with more police violence caught on video by cell phones.

Conclusion

Dragnet Nation is a fair and even-handed look at the problems of living in a state and a market where data has become the primary currency. Angwin does not even completely dismiss the idea that mass surveillance can sometimes be necessary; instead she encourages readers to question each “dragnet” they encounter, asking questions such as, “Can it withstand public scrutiny?” and “Are the operators held accountable for the way it is used?”

I would recommend Dragnet Nation for the Canon as an early stop on the journey for any cybersecurity professional to understand the challenges posed by mass data collection.

[Palo Alto Networks Blog]

The Cybersecurity Canon: Cyberdeterrence and Cyberwar

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Brian Kelly: Cyberdeterrence and Cyberwar (2009) by Martin C. Libicki

Executive Summary

My interest in the Cybersecurity Canon project and appreciation for a common body of knowledge shared amongst professionals can be traced back to my time as an Officer in the Air National Guard.

Each year the Air Force Chief of Staff would issue a “reading list”; in 2010 Cyberdeterrence and Cyberwar by Martin C. Libicki was on the list under Mission, Doctrine and Profession. Back in 2008 Lt. Gen. Robert Elder, Jr., then Commander of Eight Air Force (8AF/CC), sponsored the study “Defining and Implementing Cyber Command and Cyber Warfare.” This book represents the results of that study. The reading list and, more specifically, this book were meant to inform senior Air Force leaders and decision-makers. The basic message of Cyberdeterrence and Cyberwar is: Cyberspace is its own medium with its own rules; thus, deterrence and warfighting tenets established in other media do not necessarily translate reliably into cyberspace.

Review

On June 23, 2009, the Secretary of Defense directed the Commander of U.S. Strategic Command to establish a sub-unified command. The United States Cyber Command (USCYBERCOM), as we know it today, is located at Fort Meade, Maryland. The establishment of U.S. Cyber Command marked the ascent of cyberspace as a military domain. This book focuses on policy dimensions of cyberspace and cyberwar: what it means, what it entails, and what threats can defend or deter it.

Libicki’s background is non-cyber national security history and policy, and that knowledge and background will benefit readers unfamiliar with Cold War era concepts as they relate to cyber.

Cyberdeterrence and Cyberwar is divided into nine chapters. Chapter One covers the introduction and purpose of the book, which clearly is to focus on military policy as it relates to cyberwar. Chapter Two introduces readers to a conceptual framework for cyberdeterrence and cyberwar. It explains external and internal threats and defines cyberattack and cyberdeterrence. Cyberattack is the deliberate disruption or corruption by one state of a system of interest to another, and cyberdeterrence is the capability in cyberspace to do unto others as they would do unto us. Chapter Three asks, “why is cyberdeterrence different?” and focuses on analogies to game theory and nuclear deterrence. Foundationally knowing “who did it” is critical; today we think of it terms of attribution. All decisions, policy or operational, are based on attribution. Chapter Four considers cyberattack and the purpose of the attack. Potential purposes range from “oops” to rogue operators and the implications of each. Chapter Five offers a primer for a strategy of response. This chapter has relevance today as the idea of “hacking back” or “active defense” has become a popular concept in the strategy of response. Chapters Six and Seven outline “strategic” and “operational” cyberwar and offer conclusions on both. Chapter Eight is dedicated to cyberdefense and concludes that deterrence in cyber terms may be too problematic to offer much surcease from cyberattacks. It outlines the goal of cyberdefense to include architecture, strategy and policy. Chapter Nine is simply titled “Tricky Terrain” and offers the defend, disarm or deter triangle as an illustration of approaching a threat that cannot be denied. We know now that cyberattacks are a threat that cannot be denied.

Conclusion

Much has changed since this monograph was published back in 2009; and, while some cybersecurity experts may not agree with Libicki’s conclusions, we can’t argue the significance this work has as a historical text in the cybersecurity professional’s education. I would recommend Cyberdeterrence and Cyberwar for the Cybersecurity Canon. Reading this book in 2016 allows the reader to both compare and contrast Libicki’s conclusions against the backdrop of cyber events that have occurred over the last decade.

[Palo Alto Networks Blog]

English
Exit mobile version