Getting to Zero allowed threats
Idea shared by Douglas Foster - Today at 9:20 AM
Proposed
Quality is Free
This profound book by Philip B Crosby has relevance for spam filtering.   He noted that Quality means “conforms to specifications”.    Defects are a failure to conform, and require rework.   For example, a new car must have a beautiful paint job.   Vehicles with paint flaws are reworked until the paint is beautiful.  Reworks are the result of defects, and defects have causes.   One should find and fix the root cause once, rather than perform rework endlessly.   Some processes can tolerate defects, while others cannot.   In a hospital’s newborn nursery, there is no “acceptable” rate of dropped babies.   Hospitals do not plan a rework process for broken skulls, instead they implement many measures to ensure that tragedies do not happen.
Email Filtering Quality Specification
What are the specifications to which email filtering must conform?    I suggest these, but only the first is important for the purposes of this document:
  1. The filtering system must block all malicious threats.
  2. The filtering system should block messages that are contrary to organization policy.
  3. The filtering system should limit unimportant messages, such as nuisance advertising, so that the recipient can read and respond to important messages without hindering his productivity.
Email filtering is an environment where rework is not an option, and everybody knows it.   I have never had a vendor brag, “We will block 85% of all ransomware attacks against you.”  Similarly, I doubt that anyone has ever written an RFP that says, “Product must block at least 80% of all ransomware attacks.”   The expectation is 100%, because one defect can destroy a company.     
Email Filtering Quality Results
How is the filtering industry doing?   Very badly.    I did a simple web search for “What percentage of major network breaches are caused by email?”    The returned headlines varied between 66% and 91%, with AI Overview choosing the 91% figure.   Most network breaches are caused by email.
The problem is also pervasive.  How many times have you received a “Sorry we lost your data” notice from a major corporation?   In my house, it feels like an annual ritual.    From another perspective, a cybersecurity sent me an email claiming that 40-60% of all companies were breached in each of the previous four years.  If those numbers are to be believed, only 6% of companies had gone free of breaches for four continuous years.
The Root Cause of Email Filtering Defects
We know how to control access to sensitive physical environments and sensitive technical environments, but we choose to ignore them for email.   Normal security controls have these characteristics:
  1. Identity verification.   Do we really know who this is?
  2. Reputation assessment.   Based on available information, is this applicant expected to be trustworthy?
  3. Justification Review.   Is this access request necessary to support an objective of the authorizing organization?
  4. Audits.   The authorized person is monitored to document correct behavior and detect incorrect behavior.   The authorized person knows that he is accountable for his actions.
All of these principles are discarded because of the false belief that email should operate on the basis of “Allow by Default.”
  • Authentication is optional.   Absence of email authentication is considered acceptable.   Even “soft” failures are ignored.  Only “hard” authentication failures are considered actionable.
  • Reputation is optional.   An unknown sender, with consequently unknown reputation, can send a message to any valid email address, whether it was acquired legitimately, acquired from the dark web, or merely guessed.
  • Justification is difficult to assess, so it is bypassed.    Having assumed that most senders are trustworthy, we further assume that their messages are important to the organization and the recipient, and therefore must be delivered.
  • Auditing is limited because the message volume is high and the labor effort is inconvenient.
An email filtering system that operates under these constraints has to be omniscient.   We are no longer looking to buy a product, we are looking to buy a god-in-a-box.   False gods always disappoint.     
The Fix
The fix for email security is to enforce normal security measures
  • Authentication must be mandatory.    Messages that arrive without authentication are reviewed.   Acceptable messages are given local policy authentication based on a verifiable identifier, or blocked as unacceptable.
  • Reputation must be mandatory.    Messages from senders with unknown reputation must be reviewed.   Review serves the dual purpose of determining if the sender is safe and whether the sender’s messages are useful.    In my data stream, messages from unknown domain names are 95% unwanted or harmful.   After the sender has been reviewed and judged to be both safe and useful, the sender reputation is declared acceptable.
  • Auditing becomes particularly important whenever these principles are bypassed.   If an unknown or unauthenticated message is delivered without prior review, it should be reviewed after delivery, and extracted from the user’s mailbox if dangerous.
Getting to zero spam is possible, but it has rarely been tried.   Vendors clearly believe that no one actually wants to endure the inconvenience that will come from securing email correctly, so instead we are being sold pipe-dreams.   This will not change until customers begin to demand change.  Until vendors offer better products, customers who want real protection from ransomware will have to build their own security structure around those vendor products.

Reply to Thread

Enter the verification text