TOC
- Introduction
- Updates
- Attacker Classes
- Attacker Pyramid
- Q&A
Updates
- 24.10.2011 - Renamed "Business Asset" to "Typical Targeted Asset", added Sophistication Pyramid
- 24.10.2011 - Added Q&A section
- 17.05.2012 - Added my OWASP BeNeLux presentation, which is inline with the overall context and further explains the rationale
- 17.05.2012 - Renamed "Targeted" to "Professional" in the pyramid for consistency
Introduction
At OWASP BeNeLux 2011 I presented The Rise of the Vulnerability Markets - History, Impacts, Mitigations, which sets out the reasoning behind the attacker-centric model and the impacts and motivations that follow from it - the pieces that make it useful as an input to threat modelling.
Attacker Classes
The model distinguishes four classes:
- Opportunists
- Targeting Opportunists
- Professionals
- State-Founded
Opportunists
This class covers bots, worms, mass malware, and script kiddies. They are opportunistic in the sense that they move on if they don't find a particular known vulnerability. Sophistication is relatively low, and to compensate they operate at scale.
Keywords: large scale, low-hanging fruit, low sophistication.
Targeting Opportunists
A more focused subset of Opportunists. They don't scan the internet at random and stop at whatever they stumble across; they pick a single organisation and probe it continuously, looking for weak spots.
Keywords: targeted at a specific organisation, continuous probing, more sophistication, more motivation.
Professionals
Digital mercenaries. Sophisticated attackers targeting specific organisations and assets over extended periods. This class does not stop at low-hanging fruit or a single attack vector - they pursue the objective by whatever means it takes. They are funded to some degree, and their skill level lets them develop new attack techniques and bypasses for exploit mitigations.
Keywords: targeted, motivated, sophisticated.
State-Founded
This class represents very well-funded and sophisticated attackers acting in the interests of nation states. Their targets are intellectual property, strategic assets, and classified information.
Keywords: targeted, specialised, Stuxnet.
Attacker Pyramid
The diagram below shows what I call the Attacker Pyramid. The left-hand pyramid shows the four attacker classes; the surface area of each layer indicates the relative number of threat agents in that class. The right-hand pyramid shows the assets each class is after, with the surface area indicating the relative value those assets represent to the business.
Attacker Classes and Sophistication
The pyramids above can be complemented by an inverse pyramid representing motivation, sophistication and funding.
Attacker Class Triad
The complete triad looks like this:
Q&A
What is the difference between this and Veris?
Veris is post-mortem - essentially an incident classification framework. There's no real link between Veris and the Attacker Pyramid. What's presented here is the concept of adjusting your defences to the highest attacker class expected (HAE). It serves as a framework to classify data and assets into buckets so you can zone and protect them accordingly.
Why "Attacker Class" and not "Threat Agent"?
The concept centres on malicious intent, not natural hazards or the other general categories that fall under "threat agent." I like the term "threat agent" and might swap "attacker class" for something else at some point, but I still think it captures motivation and intent more directly than the more generic label.