Spring, JM;
Moore, T;
Pym, D;
(2017)
Practicing a Science of Security: A Philosophy of Science Perspective.
In:
NSPW 2017: Proceedings of the 2017 New Security Paradigms Workshop.
(pp. pp. 1-18).
Association for Computing Machinery (ACM): New York, NY, USA.
Preview |
Text
spring-moore-pym_2017_practicing-science-of-security.pdf - Published Version Download (558kB) | Preview |
Abstract
Our goal is to refocus the question about cybersecurity research from 'is this process scientific' to 'why is this scientific process producing unsatisfactory results'. We focus on five common complaints that claim cybersecurity is not or cannot be scientific. Many of these complaints presume views associated with the philosophical school known as Logical Empiricism that more recent scholarship has largely modified or rejected. Modern philosophy of science, supported by mathematical modeling methods, provides constructive resources to mitigate all purported challenges to a science of security. Therefore, we argue the community currently practices a science of cybersecurity. A philosophy of science perspective suggests the following form of practice: structured observation to seek intelligible explanations of phenomena, evaluating explanations in many ways, with specialized fields (including engineering and forensics) constraining explanations within their own expertise, inter-translating where necessary. A natural question to pursue in future work is how collecting, evaluating, and analyzing evidence for such explanations is different in security than other sciences.
Type: | Proceedings paper |
---|---|
Title: | Practicing a Science of Security: A Philosophy of Science Perspective |
Event: | 2017 New Security Paradigms Workshop (NSPW 2017) |
Location: | Santa Cruz, California, USA |
Dates: | 01 October 2017 - 04 October 2017 |
ISBN-13: | 9781450363846 |
Open access status: | An open access version is available from UCL Discovery |
DOI: | 10.1145/3171533.3171540 |
Publisher version: | http://dx.doi.org/10.1145/3171533.3171540 |
Language: | English |
Additional information: | This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions. |
Keywords: | Security research; science of security; cybersecurity; history of science; philosophy of science; ethics of security |
UCL classification: | UCL UCL > Provost and Vice Provost Offices > UCL BEAMS UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science |
URI: | https://discovery.ucl.ac.uk/id/eprint/10041450 |




Archive Staff Only
![]() |
View Item |