Defining "The Weakest Link" Comparative Security in Complex Systems of Systems

TitleDefining "The Weakest Link" Comparative Security in Complex Systems of Systems
Publication TypeConference Paper
Year of Publication2013
AuthorsPieters W.
Conference Name2013 IEEE 5th International Conference on Cloud Computing Technology and Science, CloudCom, Bristol, United Kingdom
Date PublishedDecember
PublisherIEEE Computer Society
Conference LocationUSA
KeywordsAttacker utility, comparative security, induced risk, security metrics, security risk assessment, socio-technical security, weakest link.

Cloud architectures are complex socio-technical systems of systems, consisting not only of technological components and their connections, but also of physical premises and employees. When analysing security of such systems and considering countermeasures, the notion of "weakest link" often appears. Humans are then typically said to be the "weakest link" when it comes to security, but no proof is provided for this statement. One reason for this is the fact that there are no unified metrics of security that would apply to physical, digital and social components of complex systems alike. How does one compare the security of a room against the security of a piece of data, and how does social engineering an employee compare to exploiting a server vulnerability? Are we really comparing apples and oranges here, or would it be possible to present a comparative metric that would apply across the different domains? This paper explores the possibility of such a metric for complex systems, and proposes one in terms of the risk induced by an entity in the system. This also provides a foundation for the notion of "weakest link", in terms of the entity (set of entities) with the highest induced risk.