Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - If Mother Nature Was A CISO
Articles

If Mother Nature Was A CISO

ISBuzz TeamBy ISBuzz TeamMay 30, 20148 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
How To Avoid Mother's Day Scam By Protecting Your Purse And Heart
How To Avoid Mother's Day Scam By Protecting Your Purse And Heart
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

People describe the Internet as a hostile network—which is true—and that got me thinking about other hostile environments where a successful strategy results in resiliency and continuity. What if Mother Nature was the CISO? What would her strategy be? What strategy could she give the prey species so they could survive in the presence of many predators? Albert Einstein was quoted as saying, “Look deep into nature, and then you will understand everything better.”

I’m specifically interested in prey species because, like most organizations on the Internet, they have no real offensive measures, yet they are expected to adapt to a hostile environment. It is the continuity of the business that matters most and such is the case with the continuity of the species.

The Patterns of Predator Species

To get a better understanding of the defensive tactics of prey species, it is worth spending a minute talking about the dominant strategies of the predators. The three that I’ll highlight are cruising, ambush, and the blend of these, which we will call cruising-ambush. All of these offer similarities to the threat landscape we have been experiencing on the Internet.

Cruising

Cruising is where the predator is continually on the move to locate prey. This strategy is effective when the prey is widely dispersed and somewhat stationary. This is a pattern we can see reflected when the adversary broadly scans the Internet for targets, and these targets are stationary in the sense that once a target is found, a connection can be made repeatedly. This was the dominant strategy for attackers in the early days of the Internet, mainly because it was all about compromising servers and “pushing” the exploit to the victim. While still prominent, it is noisy, and the predator, as in nature, must consider the consequence of being a victim him/herself while cruising.

Ambush

Ambush is where the predator will sit and wait. This strategy relies on the prey’s mobility to initiate encounters. Two factors account for a rise in the frequency of this pattern on the Internet: 1) cruising and attacking the stationary targets like servers got much more expensive with firewalls, IDS/IPS, etc., all increasing the protection of the prey and the detection of the predator; and 2) there has been explosive growth of mobile prey via browsers and clients in general. Another obvious fact to the predator is that there is way more client-prey than server-prey just by the ratio of client-server design. On the Internet today, we see this ambush pattern in a compromised web server sitting and waiting for prey to connect and “pull” down the exploits. The majority of malware is distributed in this ambush pattern.

Cruising-ambush

The blended cruising-ambush is by far the most effective predator pattern. The idea is to minimize exposure when cruising and employ effective ambush resources which in turn cruise, causing a loop in the pattern. A few threats exhibit this, such as a phishing campaign that broadly cruises for prey. Once the victim clicks on the phishing link, it quickly shifts to the ambush pattern, with a compromised web server sitting and waiting for the connection to then download the malware. This can continue again with that malware-infected host then cruising the internal networks looking for specific prey like DNS servers, file servers, yet another place to set up an ambush pattern, and so on.

The Patterns of Prey Species

Now that we know the predators’ strategy, let’s look at anti-predator patterns. There are many documented defensive patterns for prey species, and I’d like to explore the ones that can be applied to Internet security. In all of these cases, Mother Nature’s common pattern is one of making the prey marginally too expensive to identify and/or pursue. There is always a fundamental cost/benefit analysis performed by the predator; years of evolution ensure that the effort spent or the risks taken to acquire the prey are less than the calories offered by the prey when eaten.

Certain prey species have raised the cost of observation and orientation so much that they are operating outside their predators’ perceptive boundaries. Camouflage is one technique, and another is having parts of the organism be expendable, as in a gecko’s tail or a few bees in the colony. With the former, camouflage is another term for costly observation, and we can do this either with cryptography or in the random addressing within a massively large space like IPv6. For the latter, where parts are expendable—one can imagine a front-end system where there are 100 servers behind an Application Delivery Controller (ADC). When one of these servers is compromised, it communicates these specifics to the other 99 such that they can employ a countermeasure. The loss of the single system is an informational act and the system adapts or evolves as one species.

An effective countermeasure to cruising is the dispersion of targets or the frequent changing of non-stationary targets, raising the observation and orientation requirements of the predator. While in nature, we can measure cost/benefit by kcals spent versus eaten; the information space of the Internet must be measured in information and knowledge. If the predator has to do more probing and searching in the reconnaissance phase, it becomes more easily detected, so raising the cost of discovery in turn raises the predator’s risk of being discovered and caught during these early phases of the attack.

The last prey species pattern I find useful is one of tolerance to loss. Some species have found a way to divert the predator to eat the non-essential parts and have an enhanced ability to rapidly recover from the damage. Here, the loss is not fatal but informational. As we build highly tolerant information systems I think this is a very useful pattern; subsystems should be able to fail and this failure information be used as inputs to the system for recovery processes. In some cases, entire organisms die in order for the species to survive and evolve, so I’ll spend some time talking about these two very different logical levels and how they apply to Internet security strategies.

The Resiliency of the Species

The game of survival and resiliency is at the level of species and not at the level of organism. Diversity, redundancy, and a high rate of change at the organism level provide stability at the species level. Loss at the organism level may be fatal, but it is also information to the species level.

When we look at this pattern in information technology we can quickly see the need for abstractions. We can draw a parallel between server and organism and between service and species, for example. A web server farm of 10 servers (10 organisms) sits behind a load balancer that offers a service (the species). We can also see this pattern in the highly resilient DNS top level domain service, where the operating systems, locations, and even CPUs are diverse at the server level (the organism) but deliver the same service (species).

Abstractions are available to us in our design of these systems and we need to leverage them in the same way Mother Nature has over the past 3.8 billion years. Virtual servers, SDN (software-defined networking), virtual storage—all the parts are at our disposal to design highly resilient species (services).

CISO

By leveraging the virtual abstractions from the physical on the hosts and networks, we can build highly resilient services at the species level that co-evolve at the organism level as it adapts to the changing threat.

Conclusion

We are in an age where virtualization of endpoints and networks offers us the abstraction required to mimic these patterns in nature, yet we continue to design systems where loss is fatal and not just an informational event. Every organism in an ecosystem has a perceptive boundary—a natural limit to what it can observe and understand. It is their observation and orientation to the environment. It is on this plane that a hierarchy is naturally formed, and within it is the playground for survival.

Prey species have found a way to establish a knowledge margin with their environment, and this is what we must do with our information systems. The systems you protect must continuously change based on two drivers: 1) how long you think it will take your adversary to perform its reconnaissance, and 2) the detection of the adversary’s presence. Each time your systems change, the cost for the adversary to infiltrate and, most importantly, to remain hidden is raised substantially, and this is the dominant strategy found in nature. The patterns in nature are all about loops, so start to design with this in mind and you will live to compute another day.

TK Keanini, CTO at Lancope

Tim KeaniniLancope, Inc. is a leading provider of network visibility and security intelligence to defend enterprises against today’s top threats. By collecting and analyzing NetFlow, IPFIX and other types of flow data, Lancope’s StealthWatch® System helps organizations quickly detect a wide range of attacks from APTs and DDoS to zero-day malware and insider threats. Through pervasive insight across distributed networks, including mobile, identity and application awareness, Lancope accelerates incident response, improves forensic investigations and reduces enterprise risk. Lancope’s security capabilities are continuously enhanced with threat intelligence from the StealthWatch Labs research team. For more information, visit www.lancope.com.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}