Towards operational measures of computer security: Experimentation and modelling

Tomas Olovsson (Institutionen för datorteknik) ; Erland Jonsson (Institutionen för datorteknik) ; Sarah Brocklehurst ; Bev Littlewood
Predictably Secure Computing Systems p. 555-572. (1995)

The two experiments described here were intended to investigate the empirical issues that arise from the probabilistic view of security assessment discussed in the previous paper. Specifically, they investigated the problems of measureing effort and reward associated with security attacks and breaches.

