As shown by the numerous data breaches documented on Security Blueprints, many companies struggle to establish an effective security posture that prevents breaches or significantly reduces their impact.

Fortunately, there’s a powerful approach to substantially improve your security stance: Security Invariants . A security invariant is one of several types of constraints that once consistently enforced across a computing infrastructure, systematically reduces the attack surface without requiring the organization’s team members to make security decisions. Invariants are machine-enforceable policies that are automated to ensure consistent deployment and ongoing enforcement without granular human configuration or decision-making.

It is critical to note that security best practices are not necessarily security invariants - consider a best practice that mandates all default passwords must be removed before system deployment. Such a policy, without machine enforcement, requires humans to update and hand-verify each system, creating the likelihood of errors. In contrast, a security invariant would prescribe enforcement of this policy by deploying infrastructure that only allows properly blessed computer images (with default passwords removed), removing any ongoing human decision-making for correct implementation. Such enforcement ensures that the best practice is now “invariant” at both the time of deployment and during ongoing operation, immune to human mistakes or mischief.

Each security invariant, when properly enforced, impedes one or more steps of the attack kill chain (e.g., persistence, command and control, privilege escalation, lateral movement, data exfiltration), making it significantly harder for an attacker to succeed. Implementing multiple invariants compounds their effectiveness, further increasing the difficulty and cost of a successful attack. Incomplete or incorrect implementation of an invariant exposes a vulnerability on those systems where the invariant is not active, creating a weakness that attackers can exploit.

In the coming weeks and months, we will introduce various examples of security invariants and evaluate how they could have prevented known massive data breaches. We’ll maintain a leaderboard of security invariants ranked by their measured effectiveness. For those seeking an immediate takeaway: the combination of mandatory hardware second-factor authentication, positive execution control on endpoints, and egress control of services in production environments would have prevented most of the data breaches we’re documenting here.

Leaderboard for Invariants

While not all security invariants have been documented yet, here are some preliminary results showing their effectiveness. Each invariant and breach report has its own analysis on their respective impact.

Invariants Avg. Score Num Effective Percent Effective
Mandatory Hardware Second Factor 0.41 30 39%
Egress Control 0.38 32 42%
Positive Execution Control 0.31 24 32%
Supply Chain Aging 0.02 2 3%
Invariants: The security measures implemented. Avg. Score: The average effectiveness score of the invariant across all breaches. Num Effective: The number of breaches where the invariant would have been effective. Percent Effective: The percentage of breaches where the invariant would likely have prevented the breach.

Looking at the combination of two invariants, we can see that the coverage for breach prevention increases noticeably.

Invariants Avg. Score Num Effective Percent Effective
Egress Control, Mandatory Hardware Second Factor 0.56 45 59%
Mandatory Hardware Second Factor, Positive Execution Control 0.54 42 55%
Mandatory Hardware Second Factor, Supply Chain Aging 0.43 32 42%
Egress Control, Positive Execution Control 0.43 35 46%
Egress Control, Supply Chain Aging 0.40 34 45%
Positive Execution Control, Supply Chain Aging 0.33 26 34%
Invariants: The security measures implemented. Avg. Score: The average effectiveness score of the invariant across all breaches. Num Effective: The number of breaches where the invariant would have been effective. Percent Effective: The percentage of breaches where the invariant would likely have prevented the breach.