With the drama but not the bruises, hacking becomes a spectator sport
Loading...
| Las Vegas
Welcome to the future of hacking, where machines are the stars and the humans are in the audience.
The night before the DEF CON hacker conference began here, seven supercomputers went head-to-head in a kind of Olympics for听cybersecurity. The Cyber Grand Challenge, sponsored by the military鈥檚 futuristic research arm 鈥 the Defense Advanced Research Projects Agency 鈥 was the world鈥檚 first all-machine hacking tournament.
"Cybercasters" who channeled听Monday Night Football announcers delivered the play-by-play commentary for the crowd of 5,000 spectators. But these hosts came with serious geek credentials. Astrophysicist Dr. Hakeem Oluseyi teamed up with two star hackers: Hawaii John, who rocked a bushy hipster beard, and Invisig0th whose head was shaved except for a ponytail and sported a T-shirt from the cybersecurity cult classic movie "WarGames."听
Seven massive screens at the Paris Hotel ballroom showed the hosts interviewing members of the seven teams, from all over the US, that built the robots. Normally, it would take them up to a year to detect and months to fix bugs hidden in complicated computer code.听But as听techies relaxed on an array of leather couches munching Twizzlers, they watched visualizations showing their machines finding and vanquishing software flaws in minutes.听
This time, attacks were portrayed for all to see as lines of听bright, multicolored dots moving from one machine to another. There was a scoreboard, tallying points for each team, as icons marked how well the computers were defending themselves. Their arena: A huge stage built above 180 tons of water to keep the high-powered machines cool.
And the audience was loving it.
"To be quite honest, I got more excited watching #DARPACGC than the #Olympics,"听 Capture the Flag veteran and malicious software researcher Jonathan Racicot from his handle @InfectedPackets.听
Clearly, this wasn't your typical capture the flag tournament in which teams compete to quickly find and fix software bugs.听
As a hacker in the audience from Sweden who identified himself only as Jonas said, it's typically "guys just at computers." For DARPA, the biggest challenge was to bring some excitement of a live sporting event to hacking and Jonas said he was impressed.
Spectators were even placing bets on their favorite teams.听鈥淚 got $20 on Deep Red,鈥 Cris Thomas from Tenable Security who goes by his hacker name Space Rogue, referring to the team of researchers from the defense contractor Raytheon.
Even the robots听chimed in on social media. 鈥淚'm getting tired, already 40 rounds in the game and no end in sight. I wonder what my humans are doing鈥︹ Mechanical Phish, the robot built by the University of California Santa Barbara during the competition.
Computers that can find and repair security flaws on their own in real-time are a game-changer, especially when human hacking听talent听is in very short supply. There are an estimated more than one million jobs unfilled in security worldwide, at a time when companies and governments are grappling with increasingly serious breaches.
To DARPA, the agency that helped invent the internet, the $55 million spent on the competition in the last two years was worth it.
"This may be the end of DARPA鈥檚 Cyber Grand Challenge but it鈥檚 just the beginning of a revolution in software security,"听. "In the same way that the Wright brothers' first flight 鈥 although it didn鈥檛 go very far 鈥 launched a chain of events that quickly made the world a much smaller place, we now have seen for the first time autonomy involving the kind of reasoning that鈥檚 required for cyber defense."
In a sign of what鈥檚 to come, the crowd went wild when the supercomputer robots found flaws that the judges didn鈥檛 even know were there.
And the broader significance wasn鈥檛 lost on fans.
"It鈥檚 really going to change us as a society," said an audience member who identified himself as Baset. 鈥淚 can only think of how this will look in five or 10 years. This kind of technology is going to enable countries that aren鈥檛 superpowers to level the playing field. The theme of DEF CON is really the rise of the machines, and I鈥檓 getting that sense here.
"We will always need humans," he continued. "But this could enable humans to spend their time doing things they should."
Jeff Moss, who founded both the Black Hat and DEF CON hacker conventions, agreed.
"Boy, wouldn鈥檛 we rather put our human resources into doing things that humans do best? Teaching other humans, explaining the business risks to companies and working on the policies 鈥 instead of spending 20 hours on the latest 15 malware variants? Wouldn鈥檛 it be great just to have a computer that can deal with that, robot to robot?" he says.
That, he says, "will be the horseless carriage area of defense." And he鈥檚 "excited to see that era ushered in."
The winner of the $2 million prize: Mayhem, built by the ForAllSecure team with technology from Carnegie Mellon University. Second place with $1 million went to a program named Xandra by the TechX team from University of Virginia and GrammaTech Inc. Mechanical Phish collected the $750,000 third-place prize.
On Friday, Mayhem will battle the humans at the annual DEF CON Capture the Flag competition. It鈥檚 the first time in the history of the competition that a computer will compete.听
May the best man or machine win.
听