June 2009

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        
Blog powered by TypePad

« Simulated Assymetric Cyberwarfare | Main | Duopoly Is Not Security »

June 07, 2005

Even Minimal Diversity Accrues Benefits

Here's an interesting paper that says that while diversification as in portfolio management or pooling as in insurance does not usually reverse the expected risk, that diversification in information systems is different.

“Exploiting externalities unique to information systems, we show that diversification can not only reduce loss variance but also minimize expected loss.”
--Software Diversity for Information Security, by Chen, Kataria and Krishnan, Fourth Workshop on the Economics of Information Security, Kennedy School of Government, Harvard University, 2 - 3 June 2005.

The paper takes into account both positive effects of less exploits and negative effects of less ease of use because of less uniformity. It takes into accounts benefits to the firm that implements diversity, and benefits to society.

The paper concludes that benefit of diversity accrue even if a firm adds only one piece of software to its incumbent monoculture software, and even if the new software is not as secure as the incumbent software.

Of course, if we're talking operating systems, any of the alternatives to the incumbent OS have greater security, as the paper demonstrates.

So software diversity in information systems would be good even in a world of worse alternatives to incumbent software, and is even better in our actual world.

-jsq

Thanks to Dan Geer for pointing out this paper.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341cb65b53ef00d83512261653ef

Listed below are links to weblogs that reference Even Minimal Diversity Accrues Benefits:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

My Photo

Risk Reading