Research paper shows holes in security approaches
- 22 May, 2006 08:32
- Comments
In an academic paper to be presented next month at the University of Cambridge in England, a research team will make a compelling and somewhat surprising mathematical case for how enterprises should spend their IT security budgets.
The three researchers, from the Florida Atlantic University in Boca Raton, Florida, looked at how companies can evaluate their vulnerabilities, analyze the risk and calculate the potential for damage.
The paper, called "Economics of Information Security Investment in the Case of Simultaneous Attacks" breaks threats into two categories: distributed attacks, which come in the form of virus, spyware and spam, and targeted attacks from a hacker, said professor Qing Hu.
What the researchers found, through equations and risk analysis, contradicts seemingly intuitive computer security approaches.
Rather than spending evenly to guard against all attacks, it's not necessarily the right approach if one kind of breach could cause many times more damage than another kind. The loss of customer information by a financial company, for example, can be astounding, said C. Derrick Huang, assistant professor at Florida Atlantic.
"No matter how much they spend on security, the budget is always low relative to the potential loss," Huang said. "In that case, spending most of the money to protect against spam or viruses doesn't make any sense."
Hu said: "This whole model is based on the principle of minimizing a security risk, with the risk defined by probability of a breach, multiplied by a loss if that breach happened."
The "eggs in one basket" approach may trouble IT administrators, but the research paper shows that with limited budgets, shoring up defenses against one attack may be the most prudent path. Targeted attacks have generally been shown to cause more financial damage than distributed attacks.
"We're proposing that companies should look at vulnerabilities of a system, and if they are in high-vulnerability and high-loss scenario, they really, really should spend the most money on targeted attacks trying to prevent hackers," Hu said.
In a broad sense, the U.S. government employed this strategy following the devastating terrorist attacks on Sept. 11, 2001. Subsequently, the U.S. government has heavily invested in airport security, said Ravi S. Behara, an associate professor who also authored the study.
For enterprises, "we've gone past the time when people just attacked us as a game," Behara said. "It's serious business now."
Huang and Hu will present the paper at the University of Cambridge during the Workshop on the Economics of Information Security, which runs from June 26 to June 28.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Securing Vital Infrastructure
- Business Process Management, Service-Oriented Architecture, and Web 2.0: Business Transformation or Train Wreck?
- Beyond Dropbox: Requirements for Enterprise Secure File Sharing
- FIBRE CHANNEL SOLUTIONS GUIDE - state of the fibre channel industry
- Secure File Sharing in the Cloud: Maximizing the Benefits
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
MYOB Software for Dummies 6E Australian Edition
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
Microsoft Office












Comments
Post new comment