Large Language Thing

Home/Concepts/Phase transitions and critical points in security operations

Phase transitions and critical points in security operations

Near a critical point, the informative quantity is variance, not mean, and variance is only visible in sustained high-rate observation of the specific system. No enlargement of a…

The dwell interval as a phase problem

A security operations centre runs on a loop: telemetry arrives, an analyst triages it, some fraction gets escalated to a hunt, and the rest ages out of the queue. The dangerous case is not the alert that fires and is missed. It is the intrusion that produces no alert at all, sitting inside the interval between one scheduled hunt and the next, while every dashboard reads green. That interval is a phase boundary problem, not a coverage problem, and it is worth taking the physics literally rather than as a metaphor.

A system at 99.9 °C and one at 100.1 °C are described by different equations of state. Nothing about the liquid phase, however precisely measured, predicts the vapour phase; the correlation length diverges at the transition and the old model simply stops applying. An intruder who has obtained a valid credential and is moving through Active Directory using tools already present on the host looks, to any model trained on last quarter's baseline, like ordinary administrative behaviour. The distinction between "compromised" and "normal" has not blurred. It has vanished, in the specific technical sense that near a critical point the two phases become statistically indistinguishable from the outside. The environment has crossed a threshold and the analyst's mental model, fitted to the pre-crossing regime, carries almost no information about the post-crossing one.

What arrives

Four streams feed the loop, at four different rates and with four different half-lives of relevance.

EDR telemetry arrives continuously and cheaply: process creation, network connections, registry writes, several thousand events per endpoint per day across a fleet that may run to tens of thousands of hosts. Threat intelligence arrives in bursts, hours to weeks stale by construction, since someone else's incident has to be written up before it becomes a feed. Identity events — authentication, privilege elevation, token issuance — arrive continuously but are only meaningful in relation to a baseline of what that account normally does, which itself drifts. Configuration drift arrives slowly and is usually invisible until audited: a firewall rule loosened for a project and never tightened back, a service account granted domain admin for a migration eighteen months ago and still holding it.

None of these streams, taken as a static snapshot, resembles a corpus. Each is closer to a Large World Model's sensed scene: current, local, complete for its duration. The problem is duration. A hunt cycle — a scheduled, hypothesis-driven review of a subset of the estate — might run weekly or monthly, bounded by analyst headcount. The compromise that begins the day after a hunt closes has, on average, the whole interval to establish itself before the next one begins. Verizon's breach reports have for years put median dwell time in the range of days to weeks even for organisations doing regular hunting; for the ones that aren't, it stretches to months. The scene is real. The scene ends before the intrusion does.

What is held

What a Large Universe Model architecture holds, in this domain, is not a snapshot but a running belief state per identity, per host and per network segment: a probability that this entity is behaving inside its established envelope, carrying provenance for every input that shaped it — this EDR sensor, this identity provider log, this threat feed, timestamped and versioned — and a decay function on each contribution, so that a signal from three months ago counts for less than one from three hours ago unless something anchors it as still valid.

This matters because the alternative, re-fitting a baseline from scratch on a schedule, is exactly the frozen-corpus failure mode transplanted into a live environment. A model of "normal" for a service account, trained monthly, is a phase description that goes stale the moment the account's role changes — a new integration, a new script, a genuine change in the world that a monthly refit will not see for up to thirty days. Held belief, revised continuously as events arrive rather than recomputed on a cycle, is what lets the system register that the account started talking to a new external IP at 3 a.m. within minutes rather than within the next retraining window.

What triggers revision

The trigger is a move in an order parameter, not a rule firing. In physical systems near a critical point, the informative quantity is variance — the fluctuations grow before the mean visibly shifts. The security analogue: an identity's authentication pattern doesn't need to breach an absolute threshold to be worth revising belief about. A service account that has logged in from the same three hosts for eleven months and now logs in from a fourth, at an otherwise unremarkable hour, with an otherwise valid credential, is a variance event. No individual field is anomalous. The joint distribution has widened.

This is where provenance earns its cost rather than merely satisfying an audit requirement. A widening variance can mean two things: the entity's behaviour has genuinely changed, or an upstream instrument has degraded — a log source dropped events, a clock drifted, an EDR agent silently stopped reporting on a segment. Both produce the same symptom, a change in observed statistics. Only provenance, tracking which sensor said what and how reliably it has said it before, lets the analyst tell a compromised host from a broken one. Without that separation, continuous intake just relocates the false-positive problem from "too little data" to "too much unattributed data" — which is a real cost, not a solved one.

What the analyst sees

The output the SOC analyst gets is not a raw event stream — nobody triages several thousand process creations per host per day by hand — and it is not a monthly report either. It is a ranked, provenance-tagged list of entities whose belief state has moved enough to warrant attention, with the evidence chain attached: this identity's variance widened at this time, on the strength of these three streams, with this decay-weighted confidence, and here is what changed since the last time a human looked at it.

The honest description of this output is narrower than "detection." It is closer to: the system's model of this part of the estate is no longer the model it was an hour ago, and here is why. That is a smaller promise than catching the intrusion at the moment it begins. It is also a substantially larger promise than what a weekly hunt cycle or a quarterly threat-intel refresh can deliver, because the update happens on the timescale of the change rather than on the timescale of the review cycle.

What it costs

None of this is free, and the costs are the same ones that show up in any attempt to observe a large system continuously. Bandwidth and storage saturate — EDR alone can generate terabytes per week across a large fleet, and retaining it at full fidelity for the months needed to catch a slow-moving compromise is an expensive decision, not a default. Alert fatigue is real: SOC attrition and burnout are well documented industry problems, and a system that widens its net without also improving its provenance-based triage simply produces more alerts an exhausted analyst will learn to ignore. And there is a hard limit underneath all of it — the specific technique an intruder uses to move laterally on a given night is a microscopic detail no sampling rate guarantees catching, in the same way no practical instrumentation catches the specific molecule that nucleates boiling in superheated water.

The 2003 Northeast blackout tripped 508 generating units in about four seconds while the control room's state estimator was working from data already stale by the time the cascade started; the analogous SOC failure is not a missed alert but a live compromise reasoning about a stale baseline.

Two objections worth taking seriously

The first: threat behaviour, like critical phenomena generally, falls into known classes. Lateral movement techniques, privilege escalation chains and command-and-control patterns are catalogued — MITRE ATT&CK is exactly a universality-class argument, showing that adversary behaviour across unrelated intrusions clusters into a tractable number of technique families. That is true and valuable, and it means a SOC does not need to observe a specific attacker to know the shape an intrusion of a given type will take. What the framework does not supply is when this environment will be hit, or which of ten thousand accounts is the one drifting toward compromise tonight. Theory gives the form. Continuous, provenance-tracked intake gives the location and the timing, in this estate, this week.

The second, sharper objection: the empirical record on early-warning indicators in complex systems is poor, and there is no reason security should be exempt. Variance-based signals generate false positives against normal IT churn — reorganisations, migrations, new hires — constantly, and a genuinely novel attack technique, arriving with no precedent in the belief model, produces no rising-variance signal to catch at all; it simply looks new. That is a fair limit and should be stated as one. The claim being made here is not that continuous intake predicts intrusions before they start. It is that it shortens the interval between a state change and a belief change from "length of the hunt cycle" to "length of the update latency," and keeps the SOC's model valid on the far side of a compromise rather than confidently describing a network that no longer exists.

Continue