security audits


Membership is requiredMember Login Required

Due to the sensitive nature of this document, you must be logged in to access it.


Login      Register to become a site member (free)     Contact Us


Estimating a System's Mean Time-to-Compromise

February 2008


Article in: IEEE Security & Privacy, January/February 2008

 

The ability to efficiently compare differing security solutions for effectiveness is often considered lacking from a management perspective. To address this we propose a framework for estimating the mean time-to-compromise (MTTC) of a target system for use as a comparative security metric. This MTTC is calculated through a three step process.



Membership is requiredMember Login Required

Due to the sensitive nature of this document, you must be logged in to access it.


Login      Register to become a site member (free)     Contact Us


Comparing Electronic Battlefields: Using Mean Time-to-Compromise as a Comparative Security Metric

November 2007


D. Leversage and E.J. Byres, “Comparing Electronic Battlefields: Using Mean Time-to-Compromise as a Comparative Security Metric,Communications in Computer and Information Science - Computer Network Security, Proceedings of the Fourth International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, St. Petersburg, Russia, Springer, 2007, pp. 213-227.



Membership is requiredMember Login Required

Due to the sensitive nature of this document, you must be logged in to access it.


Login      Register to become a site member (free)     Contact Us


Finding the Security Holes before the Hackers Do

October 2005


E.J. Byres and M. Franz; “Finding the Security Holes before the Hackers Do”, ISA Technical Conference, Instrumentation Systems and Automation Society, Chicago, October 2005


Membership is requiredMember Login Required

Due to the sensitive nature of this document, you must be logged in to access it.


Login      Register to become a site member (free)     Contact Us


Why we need Security Audits

March 2005


Article in: InTech Magazine, March 2005
 
Corporations and PCN vendors are incapable of taking action to improve the security posture of the current or future process environments without specific solution requirements. Just saying "we need firewalls and encrypted SCADA protocols" is not enough.

Syndicate content