Computerworld
Research paper shows holes in security approaches
Three researchers are proposing that trying to fight all security threats, such hackers, viruses and spam, isn't necessarily the wisest approach.
Jeremy Kirk (IDG News Service)  22 May, 2006 08:32

In an academic paper to be presented next month at the University of Cambridge in England, a research team will make a compelling and somewhat surprising mathematical case for how enterprises should spend their IT security budgets.

The three researchers, from the Florida Atlantic University in Boca Raton, Florida, looked at how companies can evaluate their vulnerabilities, analyze the risk and calculate the potential for damage.

The paper, called "Economics of Information Security Investment in the Case of Simultaneous Attacks" breaks threats into two categories: distributed attacks, which come in the form of virus, spyware and spam, and targeted attacks from a hacker, said professor Qing Hu.

What the researchers found, through equations and risk analysis, contradicts seemingly intuitive computer security approaches.

Rather than spending evenly to guard against all attacks, it's not necessarily the right approach if one kind of breach could cause many times more damage than another kind. The loss of customer information by a financial company, for example, can be astounding, said C. Derrick Huang, assistant professor at Florida Atlantic.

"No matter how much they spend on security, the budget is always low relative to the potential loss," Huang said. "In that case, spending most of the money to protect against spam or viruses doesn't make any sense."

Hu said: "This whole model is based on the principle of minimizing a security risk, with the risk defined by probability of a breach, multiplied by a loss if that breach happened."

The "eggs in one basket" approach may trouble IT administrators, but the research paper shows that with limited budgets, shoring up defenses against one attack may be the most prudent path. Targeted attacks have generally been shown to cause more financial damage than distributed attacks.

"We're proposing that companies should look at vulnerabilities of a system, and if they are in high-vulnerability and high-loss scenario, they really, really should spend the most money on targeted attacks trying to prevent hackers," Hu said.

In a broad sense, the U.S. government employed this strategy following the devastating terrorist attacks on Sept. 11, 2001. Subsequently, the U.S. government has heavily invested in airport security, said Ravi S. Behara, an associate professor who also authored the study.

For enterprises, "we've gone past the time when people just attacked us as a game," Behara said. "It's serious business now."

Huang and Hu will present the paper at the University of Cambridge during the Workshop on the Economics of Information Security, which runs from June 26 to June 28.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Top 10 Ways to Increase IT ROI Without Adding Staff

Today, IT managers are looking for alternative strategies to increase their IT ROI. The first principle is: Simplify operations. Read this white paper for 10 specific strategies for increasing IT ROI.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.