On the Brittleness of Software and the Infeasibility of Security Metrics

  • Authors:
  • Steven M. Bellovin

  • Affiliations:
  • Columbia University

  • Venue:
  • IEEE Security and Privacy
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

How secure is a computer system? Bridges have a load limit, but it isn't determined (as "Calvin andHobbes" would have it) by building an identical bridge and running trucks over it until it collapses. In amore relevant vein, safes are rated for how long they'll resist attack under given circumstances. Can we dothe same for software?