The risks with security metrics

  • Authors:
  • Marco D. Aime;Andrea Atzeni;Paolo C. Pomi

  • Affiliations:
  • Politecnico di Torino, Turin, Italy;Politecnico di Torino, Turin, Italy;Politecnico di Torino, Turin, Italy

  • Venue:
  • Proceedings of the 4th ACM workshop on Quality of protection
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

A proper security metrics and measurement process is thus a means to automatize security decisions. Unfortunately, so far automatic security evaluation techniques have failed to achieve the performance of security experts. In this paper we argue security metrics are by nature highly unstable in time. Moreover, their effectiveness depends on specific target of evaluation. In this paper we elaborate this finding and we describe our experimental framework with its results.