Prohibition For 0-Day Exploits

The monetization of exploits has been a divisive discussion in the security community for years. Now as governments emerge as the largest market for attack code, will there be a move to regulate the sale of 0-day attacks?

Mike Rothman, Analyst & President, Securosis

August 19, 2013

4 Min Read
Dark Reading logo in a gray background | Dark Reading

Unless you've been playing Rip Van Winkle, the ability for security researchers to monetize exploits is nothing new -- it arguably was started by TippingPoint's ZDI group buying 0-days in 2005 so it could build IPS signatures ahead of everyone else. The idea of buying exploits then branched to a different path where software vendors would offer a "bug bounty" to learn of holes in their products. Google has paid big money during the past few years on its bug-bounty program, and recently announced a large increase in what it'll pay for each bug. Microsoft and a number of other vendors also have spent on their bug-bounty programs to broaden their efforts to protect their software. This has been a net positive, both allowing researchers to pay their bills, as well as improving vulnerable software.

But according to The New York Times, no one is spending bigger than governments to acquire and control attacks they can then use as part of offensive, intelligence-gathering campaigns. Pollyannas may welp at this reality, but it's not really different than advanced arms research or any other investments made to advance military activities.

The U.S spends billions on advanced military research and on shiny toys like ray guns and scanners for bioweapons, among other programs. Why wouldn't governments spend some money on tools that could result in a game-changing attack such as Stuxnet? Of course they would, and they do. Many may dispute the concept of "cyberwar," but clearly the folks holding military purse strings believe their is a cybercomponent to future warfare ,and they are investing to gain that advantage.

Moreover, you don't have to read the latest Vince Flynn novel to see how cyber-\intel improves the effectiveness of spycraft, and any advantage can save military and intelligence lives. At least, that's how the power brokers are going to justify it.

Yet, would governments at some point decide the best approach would be to regulate the market for exploits? Maybe trying derail it? Chris Borgen wrote about the issues of regulating the purchase of these 0-day exploits, and it's a fascinating read. He goes through a history of how governments got involved in the trade and how they are using the exploits. But then he gets into how some regulators are trying to figure out how to regulate the sale of these munitions, given that evil regimes can buy 0-days and wreak havoc. OK, maybe not havoc, but can certainly cause heartburn.

Chris' points revolve around the perverse incentives developing on the regulatory front. Initially, there was a disincentive to regulating the exploits, since governments like to buy things out of the public (and regulators') visibility. But as these governments continue to invest in their own research capabilities to develop their own attacks, the need for externally sourced exploits wanes. At that point, they may be more interested in regulation, if only to take these alternative sources of exploits, potentially selling exploits to adversaries, out of play. Or at least make it harder for them to do business. So Chris hopes for no regulation because he wants to "keep the world safe for exploits." Yes, it's very counterintuitive, but so is most of the security business.

Personally, I don't think regulatory efforts on 0-day attacks will go very far because folks are equating software code to free speech -- even code intended to steal something from you. You have to love lawyers. But all the same, even if something does get passed to regulate and/or try to prevent the sale of exploits, exploits will still be sold, most likely to the governments that have regulated their sale. Yes, that's a pretty cynical way of looking at things, but it's reality. There was a market for exploits before any regulation, and there will be a market should any regulation come into play.

If you don't believe it, just bust out your history books and go back to the 1920s. The U.S. government banned the sale of alcohol during Prohibition, but it certainly didn't stop the production or consumption of alcohol. What it did was create a thriving black market for booze. How does this situation end any differently? Yeah, it probably doesn't.

About the Author

Mike Rothman

Analyst & President, Securosis

Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and compliance. Mike is one of the most sought after speakers and commentators in the security business and brings a deep background in information security. After 20 years in and around security, he's one of the guys who "knows where the bodies are buried" in the space.

Starting his career as a programmer and a networking consultant, Mike joined META Group in 1993 and spearheaded META's initial foray into information security research. Mike left META in 1998 to found SHYM Technology, a pioneer in the PKI software market, and then held VP Marketing roles at CipherTrust and TruSecure - providing experience in marketing, business development, and channel operations for both product and services companies.

After getting fed up with vendor life, he started Security Incite in 2006 to provide the voice of reason in an over-hyped yet underwhelming security industry. After taking a short detour as Senior VP, Strategy and CMO at eIQnetworks to chase shiny objects in security and compliance management, Mike joins Securosis with a rejuvenated cynicism about the state of security and what it takes to survive as a security professional.Mike published "The Pragmatic CSO" in 2007 to introduce technically oriented security professionals to the nuances of what is required to be a senior security professional. He also possesses a very expensive engineering degree in Operations Research and Industrial Engineering from Cornell University. His folks are overjoyed that he uses literally zero percent of his education on a daily basis.

He can be reached at [email protected]. Follow him on Twitter @securityincite

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights