Friday | 5 September, 2008
Computerworld
Research paper shows holes in security approaches
Three researchers are proposing that trying to fight all security threats, such hackers, viruses and spam, isn't necessarily the wisest approach.
Jeremy Kirk (IDG News Service) 22/05/2006 08:32:48

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
  • +

    How to Get Real About Strategic Planning 04/02/2008 12:50:59

    Everyone agrees that having a strategic plan for IT is a good thing but most CIOs approach the process with fear and loathing. In fact, the majority of CIOs (and the enterprises they work for) are faking it when it comes to strategic planning. Isn't it time we all got real?
    Oh, it must be nice to be the CIO of a FedEx or a GE or a Credit Suisse. Places where IT and the business are so tightly aligned you can barely tell the two apart. Where corporate leaders understand that IT is a strategic asset and support it as such
  • +

    Doing Your Sums on . . . Build, Buy or Rent 05/11/2007 13:32:30

    You’re trying to build a world-class IT team, but everyone’s going after the same talent pool. What mix works best? Should you grow your own, draft your players or barter your way to the line-up you want to field?
    CIOs should never forget that while new technologies have a maturity cycle, the maturity cycle for human beings in IT is even longer
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

In an academic paper to be presented next month at the University of Cambridge in England, a research team will make a compelling and somewhat surprising mathematical case for how enterprises should spend their IT security budgets.

The three researchers, from the Florida Atlantic University in Boca Raton, Florida, looked at how companies can evaluate their vulnerabilities, analyze the risk and calculate the potential for damage.

The paper, called "Economics of Information Security Investment in the Case of Simultaneous Attacks" breaks threats into two categories: distributed attacks, which come in the form of virus, spyware and spam, and targeted attacks from a hacker, said professor Qing Hu.

What the researchers found, through equations and risk analysis, contradicts seemingly intuitive computer security approaches.

Rather than spending evenly to guard against all attacks, it's not necessarily the right approach if one kind of breach could cause many times more damage than another kind. The loss of customer information by a financial company, for example, can be astounding, said C. Derrick Huang, assistant professor at Florida Atlantic.

"No matter how much they spend on security, the budget is always low relative to the potential loss," Huang said. "In that case, spending most of the money to protect against spam or viruses doesn't make any sense."

Hu said: "This whole model is based on the principle of minimizing a security risk, with the risk defined by probability of a breach, multiplied by a loss if that breach happened."

The "eggs in one basket" approach may trouble IT administrators, but the research paper shows that with limited budgets, shoring up defenses against one attack may be the most prudent path. Targeted attacks have generally been shown to cause more financial damage than distributed attacks.

"We're proposing that companies should look at vulnerabilities of a system, and if they are in high-vulnerability and high-loss scenario, they really, really should spend the most money on targeted attacks trying to prevent hackers," Hu said.

In a broad sense, the U.S. government employed this strategy following the devastating terrorist attacks on Sept. 11, 2001. Subsequently, the U.S. government has heavily invested in airport security, said Ravi S. Behara, an associate professor who also authored the study.

For enterprises, "we've gone past the time when people just attacked us as a game," Behara said. "It's serious business now."

Huang and Hu will present the paper at the University of Cambridge during the Workshop on the Economics of Information Security, which runs from June 26 to June 28.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Email Archiving Implementation: Five Costly Mistakes to Avoid

Email Archiving is essential for managing email data, but is potentially expensive to implement. Read on to discover the five key areas where email archiving costs can be contained, including data capture methods and default configuration methods.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links