Searchable transcript of An Ancient Guide to Cybersecurity: 8 Lessons from The Art of War — IBM Technology (14:03). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 What if I told you that an ancient Chinese military book written 2,500 years ago contained the keys to better cyber security? The guy that wrote it predated AI, the internet, computers, and even electricity, but he had already figured out what it took to defend your network. Sounds kind of crazy, right? Well, that guy was Sun Tzu, and his book, The Art of War, has been studied by military leaders for centuries.
00:26 For this video, I've picked out eight principles that we can glean from that historical text and apply them to the way that we defend our most high-tech infrastructures today. Why eight? Well, because in China, eight is considered the luckiest number, and that's because in Mandarin, it sounds similar to the word for prosperity or wealth. I learned when I lived in China years ago that a phone number with an eight in it cost you more than one that didn't have it.
00:55 And a number with lots of eights, well, that's gonna cost you a lot more. Here's one more fun fact. When the Summer Olympics were held in Beijing, they started on the eighth day of the eighth month of the year 2008. And guess when they started? Yep, 8.08 p.m. So they really like their eights in the Middle Kingdom. So let's honor that tradition and look at eight lessons Sun Tzu taught us about cybersecurity.
01:26 Sun Tzu wrote, if you know the enemy and know yourself, you need not fear the result of a hundred battles. So what is he talking about here? He says, basically this is a game of knowledge. It's about knowing yourself and knowing your enemy. So let us start with the knowing yourself part. So from a cybersecurity standpoint, Basically, we're going to map our own attack surface before the adversary does.
01:52 Because if we know where our weaknesses are, we can fix them. If they find them first, they'll exploit them. Then I need to know the enemy as well, the attacker. I need know who the threat actors are and study them. I need what their tools, what their tactics and procedures and techniques and things of that sort, all the things we call the TTPs. What are they going to do?
02:17 What are their motivations? Why are they doing all of this stuff? So I take all of that information, that becomes my knowledge, and we refer to that in cybersecurity, modern terms, as threat intelligence. So this is how we're going to be smarter and be able to fight a better battle. And again, 2,500 years ago, a guy had already figured out just in fact how important that was.
02:41 The next thing he wrote was, the victorious warrior wins first. Then goes to war, while the defeated warrior goes to war first and then seeks to win. So this seems counter-intuitive, but the idea is that you win first, then you go to war. It seems like it should be the other way around. So you fight and then you win? No, he says it's the other way around, you win before you fight.
03:09 So the best security basically stops attacks before they ever land in the first place. So what does that mean? How do we translate that into cybersecurity terms? Well, we're gonna do things like patching. If I patch my systems, then I'm not vulnerable. If I harden those systems, then I've removed all of the back doors that might be in them, all the other kinds of capabilities someone might use, changed all the defaults and things like that.
03:36 The system is a lot more difficult to break into. I'm gonna use preventative capabilities like multi-factor authentication. And passkeys. I'm gonna adopt things like a zero trust principle for developing the architecture of this environment where I assume breach and then I build my defenses around that. So the bottom line is in security, what we do is about prevention, detection and response.
04:03 And what 2,500 years ago had already been figured out is that prevention is better than detection and respond. And the way to look at it this way is if you're doing incident response, you've already lost round one. So Luther wrote, all warfare is based on deception. Hold out baits and entice the enemy. Deception. Now, what is that about? Well, he says deception is everything.
04:29 What are examples of this though that we could do in cybersecurity? Well, one example is a thing we call a honeypot. It's basically a decoy system that draws the attention of attackers. They're attracted into our system, but we're sitting over here watching what they're doing. So we can see what kinds of things they're going after and how they're gonna after them.
04:49 And then we can modify our defenses by learning from their particular attacks. Another example of this are things called honey tokens. And honey tokens are essentially credentials. These could be passwords, these could be API keys. So an example might be a fake AWS key in a config file. And we put that out there. And see who tries to use that. Because whenever they use it, we know it was never legitimate, so then we'll know that they picked that up and where they picked it up from.
05:19 Another example of this kind of deception is something we call a canary file. So these are bogus files that serve as early warning systems, sort of like the canary in a coal mine, if you're familiar with that reference. So these could be things like a file called password.xls or salaries.csv. And that's the kind of goal that an attacker is going to see and go for.
05:41 And once they do, then we've attracted them and we can figure out what they're doing. So this is pure Sun Tzu, lure attackers into revealing themselves while wasting their time on fake targets. That's bad for them and good for us. So another thing he wrote was speed is the essence of war. Speed and I'll add to it adaptability because he also talked about that.
06:04 But let's first talk about speed. Attackers move fast, and now with AI, they're going to move even faster. They're gonna operate at machine speed. Our defenses can't be operating at human speed. We've got to up the clock speed of the way we do response. AI is gonna make this worse, so why don't we use AI to defend against as well? Because detection and response are going to have to be faster.
06:32 Here's a way to look at this. If you consider that an attack... Occurs here, X marks the spot, then there's some amount of delay time that it takes before we're aware of what's happened. And we call that amount of time the mean time to identify. It's the average time that it takes us to do something like that. Well, once we've identified, now we're going to respond and ultimately try to contain this.
06:59 We call that average that it takes us the mean to contain. Well... This is actually fairly long for most organizations. It's almost two thirds of a year for the average data breach we've learned. And it's been that way for a decade. That is going to need to compress. We're going to be able to operate only as fast as our tools allow us. And the bad guys will be operating quickly.
07:24 We're gonna have to be adaptable. And our ability to adapt. Means we can't just rely on the rigid checkbox compliance kind of stuff, because those security situations will fail against the adaptive adversaries who are trying new attacks all the time. So do compliance, but don't think that's going to be the full answer. The supreme art of war is to subdue the enemy without fighting.
07:51 So in other words, pick your battles. One sure way to never lose a fight is don't be there when it happens. So find a way to not be there. Find a way. To defend the things that are most important to you because you can't defend everything, which means you need to prioritize. You're gonna pick what are the most important things in your organization, which means you need understand what are your crown jewels and prioritize those.
08:16 These are the data and systems that actually matter, that are the lifeblood of the organization. You wanna protect everything, but you probably can't protect everything equally. So make sure that you understand what those are. And how do you decide what these priorities are? Well, it's through risk analysis. You understand what is the relative risk if any of these things are compromised, and then that way, you're basing it on real data and real understanding.
08:43 So it's risk-based security instead of security theater. The next thing he said was, he who occupies the field of battle first and awaits his enemy is at ease. He who comes later and rushes into battle is weary. Another way to say that is you need to control the terrain, you need control the positioning, you wanna seize the high ground so that you can see the incoming attacks when they're coming in.
09:11 So how could you do this? Well, extensive monitoring is a big part of this. You wanna be able to see all the things that are happening in all the corners of your environment. Well, that's gonna be too much data. So what do you do about that? Well, you could use something like AI to help filter out the signal from the noise. So that you understand when the real attacks are coming and you're in a position to see all of that.
09:34 So you're going to protect your network with network segmentation and DMZs. What are those things? Well if you think about if this is a public internet and this is your internal network, well put a zone in between that we call a DMZ, demilitarized zone. Again, borrowing from military terminology, but this is an untrusted zone so I don't know what's going on there.
09:59 This is my relatively trusted zone. If you believe in zero trust, there's no such thing as real trust until you've verified every single thing there. But this is relatively verified. And this is where we have the big questions. So that's, and the advantage of this kind of network segmentation is an attack that happens here is not an attack that happens hear.
10:19 And hopefully we have choke points that make it harder. We're gonna force the attacker through these choke points where we then have eyes in the sky looking down and we can monitor those things heavily and know what to be looking for. The general is the fortress of the state. If the fortress is complete at all points, the state will be strong. So, in other words, the defender, the shield, the bulwark of the state.
10:46 So leadership basically decides the outcome is what Sun Tzu is saying. Another way of saying this is where there's no vision the people perish. That's from another ancient text. So the job of the leader is to convey that within the team. They need to rally the forces and get all the people bought in. The morale of the forces that are fighting, they need to be all in unison on this.
11:12 Equally important though, if we're talking in cybersecurity terms, a chief information security officer here, who would be the leader in this case, they need have the buy-in from the top as well. So they're not running everything, and the military general is not the king. So it's just as important that we get buy-in from the people above. Security culture flows from the top to the bottom.
11:37 So, and you could make the argument that untrained leadership is a bigger vulnerability than unpatched software, because bad decisions and poor funding are going to follow from that. So we really have to, if you're the leader, if you are the general in this example, You've gotta both manage up and down so that you get buy-in for the whole team. Then another thing that Sun Tzu wrote was, he will win who knows how to handle both superior and inferior forces.
12:08 Another way of saying that is preserve your resources. Don't waste anything because if you do, then the bad guys will have the advantage because you'll spend all of the resources, scarce resources you have on those particular attacks. The bottom line is ... That the defenders have limited budgets and limited amount of time and limited resources. Attackers, well, they don't suffer from those same constraints.
12:35 Collectively, they have unlimited budgets and unlimited time and unlimited creativity. So they actually have an advantage in that regard. That's why you have to be very cautious about how you're preserving your resources and using them very wisely. So. And the bottom line is, the defenders have to be right all the time, and the bad guys only have to right once.
12:57 So there's an asymmetry to all of this, which again means we need to be able to conserve. How are you gonna be able accomplish and overcome that asymmetry? Well, one way is every chance you get, you want to automate or leverage AI in order to do some of the routine stuff that humans would normally be focusing on, but then that frees them up. To be able to look at other things and do more creative work.
13:23 What can you learn about cybersecurity from a Chinese military leader who lived 2,500 years ago and never once even touched a keyboard? Turns out quite a lot. Some things never change and classic warfare wisdom is just one example of that. But now you've got eight timeless lessons to help you design better defenses for your modern infrastructures. And to Sun Tzu, I say xie xie. That means thank you.