Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

Re: [Full-disclosure] emergent security properties

Subject: Re: [Full-disclosure] emergent security properties
Date: Tue, 26 Dec 2006 20:53:46 -0700
In terms of complexity/size helping security, there may be additional categories:
 
1.  Anomaly detection might be part of a broader category of knowledge-based approaches that work better at large scale.  For instance, expert systems to detect credit card fraud or identity theft detection tend to work better as the amount of data increases.
 
2.  A more controversial improvement with scale comes from "data mining," however folks want to define that.  It's a long debate about when data mining works or is just marketing hype for putting more hay on the haystack.  But more data gives the possibility of more knowledge.
 
3.  The open source approach to security believes that having many eyes on a vulnerability increases the likelihood of detecting and then creating a patch for the vulnerability.  So security may improve when there are many eyes looking at vulnerabilities.  (This last point suggests that a Full Disclosure list, for instance, might improve security as the size of the system increases.)
 
Peter

Prof. Peter Swire
C. William O'Neill Professor of Law
Moritz College of Law of the
Ohio State University
Senior Fellow, Center for American Progress
(240) 994-4142, www.peterswire.net


-------- Original Message --------
Subject: Re: [Full-disclosure] emergent security properties
From: Roland Dobbins <rdobbins@cisco.com>
Date: Tue, December 26, 2006 8:32 pm
To: full-disclosure@lists.grok.org.uk

On Dec 26, 2006, at 4:19 PM, coderman wrote:

> the only example that comes to mind is distributed / collaborative
> anomaly detection systems which become more robust with a larger
> number of entities and interactions to observe.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
<Prev in Thread] Current Thread [Next in Thread>