Jeremiah Grossman and I wrote a book called “The End of Guessing.” In that same spirit, rather than leave you to guess what it’s about, let me tell you a little bit about it and why we wrote it.
As the Epoch Theory of Infosec explains, decades ago the vulnerability management (VM) industry started off doing something useful and indeed valid: finding the handful of threats facing any given set of machines. That worked just fine at the time, and vendors differentiated themselves based on how many vulnerabilities they could surface to the end user. It was the time of “more is more” or, said another way, if you find more vulnerabilities than other vendors, customers will buy your product.
But vulnerability counts grew, asset counts exploded, and the VM industry never got a refresh. It never grew past its own constraints of having to find every vuln. Now VM scanners are littered with ancient vulns that never mattered to anyone, theoretical issues for CVEs, minor information leakages, weak cookies, slightly old cipher suites, etc. It’s a hot mess, and customers are drowning in these results. It has also driven the per-scan cost up enormously, leaving customers with having to choose a small slice of their attack surface to scan.
Add the fact that all of this assumes these scans will be properly configured and launched. We are finding that this almost never happens. The more likely scenario we see is a customer purchasing five scan slots, for instance, to be scanned by their vulnerability management vendor, but they’ll end up only using one. This is actually happening en masse. That means 80% of their assets have no VM visibility, which brings us to the next topic of the book.
External attack surface management (EASM) has gone through a different evolution. It once was an operation you did on a spreadsheet, then when I first wrote Fierce.pl things evolved because it allowed penetration testers for the first time to enumerate much of the attack surface. Later came Amass, and Shodan, and we started to see companies popping up that productized all of these tools and collected data from passive DNS sources, and other places to build a pretty comprehensive list of devices on the Internet.
But one thing the industry did not understand at the time was that EASM tools were built to create attack surface maps; they were not attack surface maps themselves. People believed if they had a list from Shodan, or a list from Amass or Fierce that they had an attack surface map. In reality they had only a partial list of assets on one domain at best, not all the subdomains and definitely not all the other domains a customer owned.
This is a distinction with an important difference because it implies that the average customer knows what a complete inventory of assets looks like, and in my experience that is not at all likely. This leaves a major gap because you cannot know what you are vulnerable to until you map every asset that needs a scan. If your EASM leaves out assets, those misses can produce catastrophic results.
EASM and VM have failed in their promises. They aren’t finding all assets, nor are they scanning for the issues that ultimately reduce risk. This is because we never knew, until very recently, what vulnerabilities mattered. The VM market lacked the measuring stick to decide what product decisions should be made, and that in turn made it impossible for any vendor to guarantee their EASM or VM results. They simply didn’t work. We have now figured out how to fix all that without guessing.
“The End of Guessing” explains how we get there.
You can buy it on Amazon here, we would love to hear what you think. If you plan to be at Black Hat this week in Las Vegas, swing by the Nucleus Security booth (#5533) for a signed copy on Wednesday, August 5 at 2:00 p.m. or Thursday, August 6 at 10:00 a.m.