security audits
Estimating a System's Mean Time-to-Compromise
February 2008
Article in: IEEE Security & Privacy, January/February 2008
The ability to efficiently compare differing security solutions for effectiveness is often considered lacking from a management perspective. To address this we propose a framework for estimating the mean time-to-compromise (MTTC) of a target system for use as a comparative security metric. This MTTC is calculated through a three step process.
Comparing Electronic Battlefields: Using Mean Time-to-Compromise as a Comparative Security Metric
November 2007
D. Leversage and E.J. Byres, “Comparing Electronic Battlefields: Using Mean Time-to-Compromise as a Comparative Security Metric,” Communications in Computer and Information Science - Computer Network Security, Proceedings of the Fourth International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, St. Petersburg, Russia, Springer, 2007, pp. 213-227.
Finding the Security Holes before the Hackers Do
October 2005
Why we need Security Audits
March 2005
