Research paper shows holes in security approaches
- 22 May, 2006 08:32
- Comments
In an academic paper to be presented next month at the University of Cambridge in England, a research team will make a compelling and somewhat surprising mathematical case for how enterprises should spend their IT security budgets.
The three researchers, from the Florida Atlantic University in Boca Raton, Florida, looked at how companies can evaluate their vulnerabilities, analyze the risk and calculate the potential for damage.
The paper, called "Economics of Information Security Investment in the Case of Simultaneous Attacks" breaks threats into two categories: distributed attacks, which come in the form of virus, spyware and spam, and targeted attacks from a hacker, said professor Qing Hu.
What the researchers found, through equations and risk analysis, contradicts seemingly intuitive computer security approaches.
Rather than spending evenly to guard against all attacks, it's not necessarily the right approach if one kind of breach could cause many times more damage than another kind. The loss of customer information by a financial company, for example, can be astounding, said C. Derrick Huang, assistant professor at Florida Atlantic.
"No matter how much they spend on security, the budget is always low relative to the potential loss," Huang said. "In that case, spending most of the money to protect against spam or viruses doesn't make any sense."
Hu said: "This whole model is based on the principle of minimizing a security risk, with the risk defined by probability of a breach, multiplied by a loss if that breach happened."
The "eggs in one basket" approach may trouble IT administrators, but the research paper shows that with limited budgets, shoring up defenses against one attack may be the most prudent path. Targeted attacks have generally been shown to cause more financial damage than distributed attacks.
"We're proposing that companies should look at vulnerabilities of a system, and if they are in high-vulnerability and high-loss scenario, they really, really should spend the most money on targeted attacks trying to prevent hackers," Hu said.
In a broad sense, the U.S. government employed this strategy following the devastating terrorist attacks on Sept. 11, 2001. Subsequently, the U.S. government has heavily invested in airport security, said Ravi S. Behara, an associate professor who also authored the study.
For enterprises, "we've gone past the time when people just attacked us as a game," Behara said. "It's serious business now."
Huang and Hu will present the paper at the University of Cambridge during the Workshop on the Economics of Information Security, which runs from June 26 to June 28.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Email Encryption/Decryption and Signing integrated into a comprehensive content security solution
- Consolidating Applications with Oracle Solaris Containers
- Implementing Energy Efficient Data Centres
- Aberdeen Group Analyst Insight Report: Does Your Enterprise Have a “Dropbox Problem?”
- The Big Six: The CIO Executive Council’s Frameworks for IT Value and Leadership
-
The NBN, service providers and you... what could go wrong?
-
NBN build gaining momentum daily: Quigley
-
FTC chairman: Do-not-track law may not be needed
-
Kindle sales soar but Amazon mum on actual numbers
-
Wall Street Beat: IPOs, M&A, chip news stir tech optimism
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
MYOB Software for Dummies 6E Australian Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition
-
Teach Yourself Visually Windows 7
-
Windows 7 for Seniors for Dummies®









Comments
Post new comment