Measuring Security
May/June 2011 (vol. 9 no. 3)
pp. 60-65
Sal Stolfo, Columbia University
Steven M. Bellovin, Columbia University
David Evans, University of Virginia
To become a legitimate science, computer security requires metrics. However, metrics are the one thing most lacking in our current understanding of computer security. Computer security metrics can be based on computational complexity or on economic or biological metaphors, or they can be empirical. Any successful metric must address multiple layers of security.

Index Terms:
computer security, cybersecurity metrics, defense in depth, intrusion detection systems, adversary models
