Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, February 16, 2013

Measuring and predicting cyber security

Cybersecurity is a hot topic these days as the number of attacks grows and governments try to defend against them. There are questions of policy as well as technology -- which policies work?

Aaron Kleiner, Paul Nicholas and Kevin Sullivan of Microsoft Research have tried to answer that question by looking at the results of scans using MSRT, Microsoft's malicious software removal tool. The MSRT reports back when it removes malicious software and, using this data, Microsoft estimates computers cleaned per mille (thousand) or “CCM,” the number of computers cleaned for every 1,000 times that the MSRT is run. For example, if 50,000 scans resulted in 200 cleans, the CCM would be 200/50 = 4.

The researchers gathered data during the fourth quarter of 2011 and published the results in a report entitled Linking Cybersecurity Policy and Performance. Here you see a visualization of CCM levels for countries in the fourth quarter of 2011.

Analyzing the data, they looked for correlation between policies and CCM. For example, countries signing the Council of Europe Convention on Cybercrime do better than countries that do not. In addition to policies, they looked at various indicators and found correlations as shown below.

Using a model based on demographic and policy variables, the were able to predict CCM well, as shown here.

The authors emphasize that correlation does not imply causation, but this is an interesting big data application. Microsoft provides a valuable service for free, and in return gathers massive amounts of data on incidents of malicious software detection and removal. It is a win-win situation.

Thursday, June 07, 2012

Cyberwarfare is in the air and it is frightening

Cyberwar is a trending topic. I just Googled "cyberwar caution" and got 604 news links and 2.6 million Web links. Here are a few examples:

I understand why people feel we have to transition our cyberwar effort from defense to offense (combatant command) and I also understand why others urge caution.

We have been fighting the spread of capital intensive nuclear arms that require large, visible facilities and tests for seventy years, with mixed results. How quickly will relatively cheap cyber weapons spread? What nation will not be able to afford them?

I have no bright ideas on this topic, only a sad feeling. When I was a graduate student, I was in the research directorate of the Systems Development Corporation and my work was funded by ARPA, but posters like the one shown here were all over the building.

What posters will be on the walls at Plan X sites?

Monday, December 26, 2011

James Fallows -- what happens when six years of Gmail is hacked and deleted?

James Fallows is a national correspondent for the Atlantic Monthly, who, in addition to award winning coverage of national and foreign affairs, has been using and writing about information technology for thirty years. (Check this 1982 article on WordStar and what word processing meant to a journalist).

This month in the Atlantic, Fallows recounts the hacking of his wife's Gmail account and the way Google dealt with it.

Everyone in her address book got one of those "I was mugged while in Madrid, please send money" messages and all of her email was deleted. After the account was restored, Fallows visited Google and interviewed security folks there. Here is one quote from the article:
At Google I asked Byrant Gehring, of Gmail’s consumer-operations team, how often attacks occur. "Probably in the low thousands," he said. "Per month?," I asked. "No, per day."
That should get your attention.

I recommend this article -- it is a harrowing story with some practical tips.

It is also a good introduction to James Fallows. If you have not read him, you should.