Relationships between information security metrics: an empirical study

  • Authors:
  • Rodrigo Sanches Miani;Michel Cukier;Bruno Bogaz Zarpelão;Leonardo de Souza Mendes

  • Affiliations:
  • University of Campinas, Campinas, SP, Brazil;University of Maryland, College Park, MD;University of Campinas, Campinas, SP, Brazil;University of Campinas, Campinas, SP, Brazil

  • Venue:
  • Proceedings of the Eighth Annual Cyber Security and Information Intelligence Research Workshop
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Finding relevant metrics in information security is an important but difficult problem. In this paper, we propose to empirically investigate the relevance of different security metrics that could be derived from intrusion prevention system (IPS) alert events and computer security incident data. Based on the data provided by the University of Maryland, we show that IPS metrics are linked to security incidents, and also that different types of security incidents have different significant metrics. These results can be used for identifying possible candidates for security incident indicators, developing methods to improve incident prevention and helping organizations interpret their IPS's better in the future.