Keynote

Lance James (CEO · Unit 221B)

BSides NYC 2023 (0x04) · Day 1 · Keynote

Overview

In his compelling keynote at BSides NYC, Lance James, CEO of Unit 221B, delivered a provocative and insightful critique of the conventional cybersecurity landscape, urging the community to "reboot" its approach to emergent threats. James argues that the industry is trapped in an "emerging threats algorithm" – a cyclical, reactive pattern of identifying new threats, failing to solve old ones, and then adding more to an ever-growing list, often relying on vendor solutions that may not fundamentally address the core problem. This systemic complacency, he contends, is the true "emerging threat."

Watch on YouTube

Visual summary for Keynote by Lance James
Visual summary for Keynote by Lance James

Key moments

  1. 0:00 Introduction, speaker's background, and company mission
  2. 2:37 Why 'yet another boring emerging threats talk' isn't helpful
  3. 3:50 Unveiling the 'emerging threats algorithm' in cybersecurity
  4. 5:20 The definition of insanity applied to cybersecurity practices
  5. 6:00 Security researchers' role: problem solvers vs. marketeers

Rebooting Cybersecurity: Challenging the Status Quo and Turning the Tables on Emerging Threats

Speakers: Lance James, CEO, Unit 221B

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=IckRCRLYyJk

Overview

In his compelling keynote at BSides NYC, Lance James, CEO of Unit 221B, delivered a provocative and insightful critique of the conventional cybersecurity landscape, urging the community to "reboot" its approach to emergent threats. James argues that the industry is trapped in an "emerging threats algorithm" – a cyclical, reactive pattern of identifying new threats, failing to solve old ones, and then adding more to an ever-growing list, often relying on vendor solutions that may not fundamentally address the core problem. This systemic complacency, he contends, is the true "emerging threat."

James challenges the audience to embrace disruptive thinking, particularly in the context of rapidly evolving technologies like Artificial Intelligence (AI) and Large Language Models (LLMs). Rather than fearing these advancements, he advocates for leveraging them as powerful tools for defenders, enabling faster analysis, automated processes, and more creative problem-solving. Through a detailed breakdown of ransomware tactics, techniques, and procedures (TTPs), James illustrates how this disruptive mindset can be applied to even the most pervasive threats, proposing an innovative countermeasure that effectively turns ransomware into a self-serving backup system for the victim.

This talk is a crucial call to action for cybersecurity professionals, from students to CISOs, to question the status quo, reclaim their agency in driving market change, and foster an environment of creativity and hacker intuition. It emphasizes that by understanding the fundamental mechanics of attacks and thinking unconventionally, defenders can move beyond a losing zero-sum game and truly innovate against persistent adversaries.

Background

▶ Watch: Introduction, speaker's background, and company mission (0:00)

Lance James opens his keynote by framing the cybersecurity industry's current predicament as a self-perpetuating cycle of reactive defense. With over 25 years of experience in information security and counterintelligence, James has a deep-seated history of bridging the gap between hackers and law enforcement, having founded i2p (the dark web tool preceding Tor) and actively combating threats like Zeus malware and CryptoLocker since 2013. His company, Unit 221B, operates as an investigation and R&D think tank focused on defining and disrupting malicious actors, notably cracking Zeppelin ransomware during COVID-19 to assist small and medium businesses. This extensive background provides him a unique vantage point from which to critique the industry's default posture.

James expresses frustration with the perennial request for "emerging threats" talks, dubbing them "yet another boring emerging threats talk." He argues that such discussions, while entertaining, often fail to provide actionable solutions, leaving security professionals overwhelmed with a growing list of problems without practical application in their daily roles. This leads to what he terms the "emerging threats algorithm":

  1. Identify top threats (e.g., ransomware, email compromise, supply chain attacks, IoT device attacks).
  2. Determine if any have been solved (rarely).
  3. Add new groundbreaking technologies that scare us (e.g., AI/ChatGPT).
  4. Wait for vendors to sell solutions, often taking a gamble.
  5. Repeat, hoping for different results, which James equates to the common definition of insanity: doing the same thing over and over again and expecting a different outcome.

Beyond this algorithmic trap, James touches upon the collective trauma of the COVID-19 pandemic, highlighting how it forced a re-evaluation of personal and professional tempos. While acknowledging the tragedy, he posits that the experience offered "gifts"—an opportunity to find creative space and challenge the expectation of a return to the pre-pandemic, relentless pace. This context is crucial for his argument that the industry needs to slow down, reflect, and adopt new ways of thinking.

He further dissects the zero-sum game inherent in current security models:

  • Security as a Cost Center: For organizations, security is often viewed as an expense rather than a profit driver, leading to reluctant investment and negotiation over protection against inevitable breaches.
  • Vendor-Driven Market: The security vendor space, while offering valuable solutions, is a multi-billion dollar industry where the primary driver can shift from problem-solving to market share, sometimes pushing solutions for less than 1% effective use at full price.
  • Asymmetric Advantage for Threat Actors: An adversary needs only "one bad line of code in a few hours" (or minutes with AI) to defeat millions of dollars in defensive infrastructure and human effort. This stark imbalance mirrors the historical shift from static castles to dynamic gunpowder warfare, requiring a fundamental adjustment in defense strategy.

Ultimately, James concludes that the true "emerging threat" is not a specific piece of malware or attack vector, but rather our own systemic behavior: complacency, negotiation of essential security, being overwhelmed, high costs, and a fear of conflict that prevents challenging the status quo. This sets the stage for his call for disruptive thinking and a proactive, creative approach to cybersecurity.

Key Findings

▶ Watch: Why 'yet another boring emerging threats talk' isn't helpful (2:37)

Lance James's keynote pivots on several critical findings that challenge the foundational assumptions of modern cybersecurity defense:

  1. The "Emerging Threats Algorithm" is Insane: The industry's reactive cycle of identifying new threats, failing to resolve old ones, and then adding new technologies to an ever-growing list, while waiting for vendor solutions, is fundamentally flawed. This repetitive, ineffective pattern, confirmed by AI as the definition of insanity, highlights a deep-seated systemic problem.
  2. Our Systemic Behavior is the Real Emerging Threat: Beyond specific malware or attack vectors, the collective complacency, the framing of security as a cost center, the vendor-driven market, and a pervasive fear of conflict among defenders are the primary obstacles to effective cybersecurity. This internal "threat" prevents innovation and perpetuates a losing battle against adversaries.
  3. AI and LLMs are Disruptive Forces to be Leveraged, Not Just Feared: While AI can undoubtedly empower threat actors to generate malware faster, it also presents an unprecedented opportunity for defenders. LLMs can automate labor-intensive tasks such as risk model generation, malware analysis reports, and even low-level penetration testing, freeing security professionals for more creative and strategic work.
  4. Disruptive Thinking is Essential for Innovation: To break free from the "insanity" cycle, James advocates for a framework of disruptive thinking:
  • Questioning Assumptions: Challenging the status quo and established narratives.
  • Considering Unconventional Solutions: Moving beyond traditional defensive postures.
  • Openness to New Ideas and Perspectives: Fostering creativity and embracing novel approaches.
  1. Ransomware is Fundamentally a Backup System (Controlled by the Adversary): By dissecting the core mechanics of ransomware, James reveals its striking similarity to legitimate backup processes—encrypting files, sending them to a "cloud" (the attacker's control), and notifying the user. The critical distinction is merely who controls this "backup" process. This insight forms the basis for a disruptive countermeasure.
  2. Defenders Have the Power to Drive the Market: CISOs and security leaders, by virtue of their collective buying power and influence, can (and should) challenge vendors on pricing models, especially for threat intelligence feeds where only a fraction of the data might be utilized. This assertion of power can force the market to deliver more value and innovation.

These findings collectively underscore James's central message: the cybersecurity industry needs a fundamental "reboot" in its mindset, moving from fear and reaction to creative, proactive disruption.

Technical Deep Dive

▶ Watch: Unveiling the 'emerging threats algorithm' in cybersecurity (3:50)

James's technical deep dive begins by solidifying his critique of the industry's "emerging threats algorithm." He lists the perennial top threats: ransomware, email compromise, supply chain attacks, and IoT device attacks. The addition of AI and ChatGPT to this list in 2023 merely extends the problem, as no existing threats are systematically "solved." This leads to a vendor-driven defensive strategy, where organizations "take a gamble" on products hoping for a fix. This approach is likened to static castles facing dynamic gunpowder, emphasizing the need for a paradigm shift.

The speaker then elaborates on the transformative potential of AI and Large Language Models (LLMs) for defenders. Instead of succumbing to fear—a rational concern given AI's ability to accelerate threat actor capabilities (e.g., generating backup file encryption code quickly)—James highlights its utility:

  • Automated Risk Modeling: AI can generate comprehensive risk models in minutes, a task that traditionally takes months of training on platforms like TensorFlow.
  • Automated Intelligence Reports: Integration with tools like VirusTotal can allow LLMs to pre-prompt and generate full, human-readable malware analysis reports from a hash, significantly aiding junior analysts and speeding up initial triage.
  • Automated Penetration Testing: By feeding LLMs pre-defined playbooks and integrating them with Python OS command systems, low-level red teaming tasks like network scanning and vulnerability identification can be automated. This frees human pen testers to focus on advanced, creative attacks (e.g., side-channel attacks).
  • Deception Technology: AI can power dynamic honeynets that respond as genuine systems (e.g., a Linux environment), allowing defenders to troll, gaslight, or study adversaries in real-time.
  • Deliverable Acceleration: James demonstrates a custom copy-paste integration with ChatGPT that, upon copying text (e.g., a list of CVEs for an RCE botnet), automatically prompts for a summary and pastes the detailed report, streamlining documentation.

The core of James's technical solution lies in his disruptive approach to ransomware. He outlines why ransomware is so prevalent:

  • Ease of Development/Acquisition: It's trivial to develop or purchase on the dark web.
  • Cryptographic Equilibrium: The strength of 512-bit or higher encryption makes recovery without the key virtually impossible.
  • High ROI / Low Risk: Adversaries, often operating from jurisdictions like Russia, face minimal risk of incarceration, making attacks highly lucrative (e.g., Conti ransomware generating over $250 million in a year).
  • Cyber Insurance Enablement: Insurance companies paying ransoms inadvertently fuel the ecosystem, with some ransomware authors even targeting insured organizations.

James provides a detailed breakdown of common Ransomware TTPs:

  1. Recursive Directory Scan: Ransomware typically traverses directories, often using whitelists to avoid encrypting critical system files.
  2. File Read into Memory: Before encryption, the file is opened and read into memory. This critical pre-encryption state is a key vulnerability James exploits.
  3. Crypto Mode: A static key is often used initially, followed by the generation of an ephemeral symmetric key (e.g., AES) for each file or directory.
  4. Stripe Encryption: To achieve speed against petabyte-scale data, ransomware frequently employs stripe encryption, encrypting only sections of files, not the entirety.
  5. File Deletion/Renaming: The original file is deleted or renamed, and the encrypted version is written, preventing standard data recovery tools from working.
  6. Footer/Header Appendage: Encrypted files often have a footer or header appended containing metadata like offsets, original file size, and the public key necessary for decryption.
  7. Ransom Note Dropping: A note (text, doc, PDF, or even printed) is left in affected directories, explaining the situation and demands.
  8. Exfiltration/Double Extortion: Many modern ransomware groups (e.g., DoppelPaymer, LockBit, REvil, Maze) first exfiltrate sensitive data to cloud storage like MegaSync before encryption, threatening public release if the ransom isn't paid.
  9. Worming/Network Enumeration: Operators often escalate privileges and use the ransomware to scan and encrypt across network file shares, broadening the attack surface.

The pivotal insight comes from a comparative analysis: ransomware vs. a legitimate backup system. Both encrypt files, send data (to the cloud/attacker), and provide "notes" (alerts). The only difference is control: a threat actor controls ransomware, while a network admin controls a backup. This leads to the "right question": How can we turn the tables on ransomware and use its own technology to our advantage?

James proposes a theoretical ransomware vaccine or countermeasure based on these TTPs:

  • Hidden Hard Drive: Implement a hard drive partitioned or hidden from the operating system, potentially using UEFI or container-infused techniques, making it inaccessible to the ransomware.
  • Snapshot on Read/Delete: Every time ransomware attempts to read a file into memory or delete an original file (before encryption), a snapshot of that file is automatically created on the hidden drive. This effectively makes the ransomware perform a backup.
  • Entropy Change Detection: Monitor files for sudden, recursive changes in entropy. A normal Microsoft Word document might have an entropy of ~3 bits per unit, while an AES-encrypted file will show 7-8 bits. This significant shift indicates encryption.
  • Automated Counter-Action: Upon detecting a high-entropy change across multiple files, the system can automatically set the affected files to zero bytes and read-only. This prevents data exfiltration by giving the attacker empty files and stops further encryption.
  • Rapid Restore: Since the snapshots were taken before encryption, the restore process is significantly faster than decryption-based recovery.

This approach effectively turns the threat actor's tool against them, forcing them to perform the victim's backups and then leaving them with useless, zero-byte files for exfiltration.

Demo / Proof of Concept

▶ Watch: The definition of insanity applied to cybersecurity practices (5:20)

While the talk primarily focuses on theoretical frameworks and strategic shifts, Lance James provides a concrete demonstration of a proof of concept for his ransomware countermeasure. He describes developing a prototype using FUSE (Filesystem in Userspace), a module for Unix-like computer operating systems that lets non-privileged users create their own file systems without modifying the kernel code.

In this demonstration, the FUSE-based system acts as the "hidden file system." When ransomware (represented by a black-side process in the demo) attempts to read or delete files, the FUSE layer intercepts these actions. It automatically creates snapshots of the files before they are encrypted, effectively performing the backup operation. The system also actively monitors for changes in file entropy, detecting when a file's complexity suddenly jumps from a low value (like 3 for a text document) to a high value (like 7 or 8 for an encrypted file). This rapid, recursive change in entropy triggers the countermeasure, indicating that encryption is underway.

The demo visually illustrates how the ransomware, while attempting to encrypt, is inadvertently creating a recoverable backup on the hidden FUSE drive. This practical example underscores the feasibility of turning the tables on ransomware by exploiting its fundamental TTPs at the file system level, rendering its encryption efforts moot and providing a quick, non-decryption-based restoration path.

Defensive Implications

▶ Watch: Security researchers' role: problem solvers vs. marketeers (6:00)

The implications of Lance James's disruptive thinking are profound for cybersecurity defenders at all levels:

  1. Embrace Disruptive Thinking: Organizations must actively cultivate an environment that questions assumptions, considers unconventional solutions, and remains open to new ideas. This means moving beyond rigid playbooks and fostering a culture of innovation.
  2. Leverage AI/LLMs as Force Multipliers: Instead of fearing AI, security teams should actively explore and implement LLMs for automation. This includes:
  • Accelerating Malware Analysis: Automating initial analysis reports to free up senior reverse engineers for more complex threats.
  • Streamlining Red Teaming: Using AI to automate low-level reconnaissance and vulnerability scanning, allowing human red teams to focus on advanced TTPs and creative exploits.
  • Enhancing Deception: Deploying AI-powered honeypots that dynamically interact with adversaries, gathering intelligence and wasting their time.
  • Boosting Productivity: Integrating LLMs into daily workflows for tasks like summarizing CVEs or generating documentation, significantly reducing overhead.
  1. Challenge the Vendor Market: CISOs and security leaders must recognize their collective power to influence the market. This involves:
  • Demanding Value: Questioning the pricing of threat intelligence feeds and other services, especially if only a small percentage of the data is actionable.
  • Driving Innovation: Pushing vendors to provide solutions that fundamentally address problems, rather than just adding to a stack of costly, often redundant, tools.
  • Negotiating Assertively: Refusing to accept subpar offerings or unnecessary costs, using their influence to shape the market towards more effective and fairly priced solutions.
  1. Reclaim Control and Drive Internal Innovation: Leaders should stop negotiating security as a cost center and instead advocate for it as an essential investment. Empowering security teams with time and resources for hackathons, creative projects, and continuous learning can lead to groundbreaking internal solutions, potentially even new products.
  2. Implement Ransomware Countermeasures: The proposed technical solution—a hidden, snapshot-enabled file system with entropy detection—offers a novel, proactive defense against ransomware. Organizations should investigate and develop similar kernel-level or container-infused solutions that can:
  • Automate Pre-Encryption Backups: Utilize ransomware's file access patterns to create immutable snapshots.
  • Detect Encryption in Real-Time: Monitor for sudden, widespread entropy changes as a definitive indicator of an attack.
  • Neutralize Exfiltration: Respond by zeroing out or corrupting files intended for exfiltration, rendering stolen data useless to attackers.
  • Enable Rapid Recovery: Facilitate restores from pre-encryption snapshots, circumventing the need for costly and time-consuming decryption.

By adopting these defensive implications, the industry can shift from a reactive, losing battle to a proactive, innovative stance, turning the tables on adversaries and transforming cybersecurity from a cost center into a strategic advantage.

Key Takeaways

  • Our systemic behavior, not just external threats, is the primary challenge in cybersecurity. The industry's reactive "emerging threats algorithm" perpetuates a cycle of inefficiency and complacency.
  • Artificial Intelligence (AI) and Large Language Models (LLMs) are powerful tools for defenders, not just threats. They can automate mundane tasks, accelerate analysis, and free security professionals for creative, strategic work.
  • Embrace disruptive thinking to question assumptions and seek unconventional solutions. This mindset is crucial for breaking free from the "insanity" of repeating ineffective defensive strategies.
  • Ransomware can be turned into an unwitting backup system. By understanding its TTPs, defenders can implement countermeasures like hidden snapshotting and entropy detection to neutralize its impact and enable rapid recovery.
  • CISOs and security leaders possess significant power to drive market change. They must assert control, challenge vendors on value, and foster internal innovation rather than passively accepting the status quo.
  • Reignite hacker intuition and creativity within security teams. Creating environments for experimentation, collaboration, and out-of-the-box thinking is essential for generating truly effective and novel defenses.

About the Speaker(s)

Lance James is the CEO of Unit 221B, an investigations and R&D think tank dedicated to defining and disrupting malicious actors. With over 25 years of experience in information security and counterintelligence, James has a distinguished career focused on bridging the gap between the hacker community and law enforcement to combat cybercrime effectively. He is recognized for founding i2p, an early dark web tool, and his significant contributions to combating major cyber threats, including Zeus malware and the CryptoLocker working group he established in 2013. More recently, his team successfully cracked Zeppelin ransomware, aiding numerous small and medium businesses during the COVID-19 pandemic. Beyond his professional endeavors, James is a passionate mentor, offering free training through a collaborative creative school he founded during the pandemic. He is also a talented musician, playing the violin and piano, and enjoys karaoke.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Lance James brings genuine credentials and a clever core idea — using ransomware's own file-access patterns to snapshot before encryption — but the talk stays at the level of a well-argued blog post. The ransomware FUSE proof-of-concept is interesting, but the framing around AI, disruptive thinking, and industry behavior burns too much runtime on motivational scaffolding that the audience already knows.

Heather Calloway (CISO) — SOLID

Lance James brings real technical credibility and the ransomware-as-backup insight is genuinely clever, but the talk never closes the gap between a smart idea and an institutional decision. The governance layer is almost entirely absent, and the 'disruptive thinking' framing softens what could have been a sharper argument.

→ Top-rated talks at BSides NYC 2023 (0x04)

All talks from BSides NYC 2023 (0x04)