Suppose there is a set of components connected by a communication network. Each of the components has a configuration, for example, an operating system configuration. Suppose a vulnerability is discovered on a certain date, DD the discovery date. It takes P days to develop a patch. So the patch is available at DD plus P. If the set of components is large, it can take a number of days between when the patch is available and when the patch is installed, mitigating the vulnerability. So each component C_i is “repaired” at DD plus P plus C_i.
For example, a self propagating “worm” is effectively unmitigated for P days after DD. How fast it can replicate during those P days is an important question. For fast replicating worms, it may be that P has to be low, even zero, to kill the worm. But the important point is that on day zero after discovery no one is protected against the worm. If you seek to have a sense of confidence about the security of your subnetwork, a “zero day“ vulnerability is the sum of all fears. To rebuild your confidence, you must rebuild your subnetwork, which is expensive.
An attacker then seeks out zero day vulnerabilities, exactly because no one can be certain that they are protected against it—even the most well funded adversaries. Additional resources can bring P arbitrarily close to zero, and in the common era AI security defenders can make that cost many orders of magnitude below what it once was. Nevertheless, the zero day vulnerability keeps some of its power when an attacker can discover multiple of them on the same day. Again, in particular, the treasured sense of security is lost.
This is mostly how language works? Language is semi-arbitrary phonemes that are assigned meanings based on historical usage and mutual understanding. This jargon is long standing and widely understood by practitioners.
“Zero day” actually means something different from “previously unknown”. Many “zero day” vulnerabilities are actually previously known to someone. For example, the NSA is presumably sitting on a pile of “zero day” vulnerabilities, judging from what was revealed about their Tailored Access Operation programs in the past. Similarly, I have heard from pentesting people claim that some pentesting companies supposedly keep a “zero day” or two in their back pocket to ensure that their important pentests produce some results. In general, attackers have a strong incentive to stockpile “zero days,” and to selectively deploy them against high value targets when needed.
So “zero day” is actually a shorthand for something like “vulnerability previously entirely unknown to vendors/maintainers and defenders at large, but potentially privately known to one or more attackers.” It might, in limited circumstances, even include vulnerabilities that have been previously used against low-awareness defenders, if the attacker successfully evaded any recording mechanisms or post-motem detection.
Better, but it’s still glossing over the critical bit, which is “previously unrevealed to who?” Specifically, “zero day” implies both that:
The vendor or maintainers had no idea of the vulnerability’s existence.
A diligent defender would have zero days to prepare, hence the name.
Meanwhile, it’s entirely possible that the attacker has known for months or years.
Words like “unknown”, “unreleased”, etc., are all imprecise about this asymmetry. For example, if Microsoft knows about a vulnerability in Windows but hasn’t shared that information with the public, that’s “unrevealed” to the public. But most people would not consider it a zero day.
“Zero day” is an established term that is widely understood by practitioners and the relevant professionals. It might not be an ideal choice of terminology when writing a newspaper article for a non-technical audience.
situating the vulnerability in the context of the mathematical model of network connected components, reminding you that you are (inevitably) part of a security community (weakest in the whole due to it’s weakest links, etc); and
a nostalgic recall to the youth of the industry where a “zero day” was rare and valuable rather than manufactured multiple times per day on demand.
Given that it is the computer security community that will determine whether we recover from the first AI worm within days (annoying), weeks or else months (cross-industry phase change event), it likely behooves us to use their language. for example, this impossible situation immediately demands a security office at Anthropic and OpenAI that can help respond to AI worm emergencies. Do the facilities exist? if not, they have a higher chance of being established and effective if the frontier labs engage now with the security community and their language. the idea of multiple zero day vulnerabilities per day should make any security professional nauseous.
Suppose there is a set of components connected by a communication network. Each of the components has a configuration, for example, an operating system configuration. Suppose a vulnerability is discovered on a certain date, DD the discovery date. It takes P days to develop a patch. So the patch is available at DD plus P. If the set of components is large, it can take a number of days between when the patch is available and when the patch is installed, mitigating the vulnerability. So each component C_i is “repaired” at DD plus P plus C_i.
For example, a self propagating “worm” is effectively unmitigated for P days after DD. How fast it can replicate during those P days is an important question. For fast replicating worms, it may be that P has to be low, even zero, to kill the worm. But the important point is that on day zero after discovery no one is protected against the worm. If you seek to have a sense of confidence about the security of your subnetwork, a “zero day“ vulnerability is the sum of all fears. To rebuild your confidence, you must rebuild your subnetwork, which is expensive.
An attacker then seeks out zero day vulnerabilities, exactly because no one can be certain that they are protected against it—even the most well funded adversaries. Additional resources can bring P arbitrarily close to zero, and in the common era AI security defenders can make that cost many orders of magnitude below what it once was. Nevertheless, the zero day vulnerability keeps some of its power when an attacker can discover multiple of them on the same day. Again, in particular, the treasured sense of security is lost.
This seems like an explanation of the history of the term, not a positive argument for its use.
This is mostly how language works? Language is semi-arbitrary phonemes that are assigned meanings based on historical usage and mutual understanding. This jargon is long standing and widely understood by practitioners.
“Zero day” actually means something different from “previously unknown”. Many “zero day” vulnerabilities are actually previously known to someone. For example, the NSA is presumably sitting on a pile of “zero day” vulnerabilities, judging from what was revealed about their Tailored Access Operation programs in the past. Similarly, I have heard from pentesting people claim that some pentesting companies supposedly keep a “zero day” or two in their back pocket to ensure that their important pentests produce some results. In general, attackers have a strong incentive to stockpile “zero days,” and to selectively deploy them against high value targets when needed.
So “zero day” is actually a shorthand for something like “vulnerability previously entirely unknown to vendors/maintainers and defenders at large, but potentially privately known to one or more attackers.” It might, in limited circumstances, even include vulnerabilities that have been previously used against low-awareness defenders, if the attacker successfully evaded any recording mechanisms or post-motem detection.
How about, “previously unrevealed”?
Better, but it’s still glossing over the critical bit, which is “previously unrevealed to who?” Specifically, “zero day” implies both that:
The vendor or maintainers had no idea of the vulnerability’s existence.
A diligent defender would have zero days to prepare, hence the name.
Meanwhile, it’s entirely possible that the attacker has known for months or years.
Words like “unknown”, “unreleased”, etc., are all imprecise about this asymmetry. For example, if Microsoft knows about a vulnerability in Windows but hasn’t shared that information with the public, that’s “unrevealed” to the public. But most people would not consider it a zero day.
“Zero day” is an established term that is widely understood by practitioners and the relevant professionals. It might not be an ideal choice of terminology when writing a newspaper article for a non-technical audience.
yes, the advocacy mainly comes from the term:
situating the vulnerability in the context of the mathematical model of network connected components, reminding you that you are (inevitably) part of a security community (weakest in the whole due to it’s weakest links, etc); and
a nostalgic recall to the youth of the industry where a “zero day” was rare and valuable rather than manufactured multiple times per day on demand.
Given that it is the computer security community that will determine whether we recover from the first AI worm within days (annoying), weeks or else months (cross-industry phase change event), it likely behooves us to use their language. for example, this impossible situation immediately demands a security office at Anthropic and OpenAI that can help respond to AI worm emergencies. Do the facilities exist? if not, they have a higher chance of being established and effective if the frontier labs engage now with the security community and their language. the idea of multiple zero day vulnerabilities per day should make any security professional nauseous.