Issue No.03 - May/June (2011 vol.9)
Sal Stolfo , Columbia University
Steven M. Bellovin , Columbia University
David Evans , University of Virginia
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/MSP.2011.56
To become a legitimate science, computer security requires metrics. However, metrics are the one thing most lacking in our current understanding of computer security. Computer security metrics can be based on computational complexity or on economic or biological metaphors, or they can be empirical. Any successful metric must address multiple layers of security.
computer security, cybersecurity metrics, defense in depth, intrusion detection systems, adversary models
Sal Stolfo, Steven M. Bellovin, David Evans, "Measuring Security", IEEE Security & Privacy, vol.9, no. 3, pp. 60-65, May/June 2011, doi:10.1109/MSP.2011.56