Research story · Security, statistics & audit
The time
before discovery.
A security review records when a problem becomes visible. The problem may have begun much earlier. That gap affects what an organisation can learn from its records, how it compares controls and where it should spend its next unit of audit effort.
My work with Tanveer Zia on Modeling System Audit as a Sequential Test with Discovery as a Failure Time Endpoint brings the observation process into the security model. The public university record dates the conference publication to 2012.
Keep two times in the record
Consider a simple hypothetical example. A server is checked on Monday and a compromise is found on Friday. If Monday’s check reliably established that the server was uncompromised, the incident began somewhere in that interval. Friday supplies a discovery time. Further evidence is needed to locate the incident itself.
If Monday’s check could have missed an existing compromise, even that lower boundary is uncertain. A log of completed inspections needs the scope and sensitivity of each inspection alongside its date. Otherwise, two organisations with identical underlying exposure can appear different simply because one looks more often or looks more effectively.
Preserve what the observation actually tells you
Reliability analysis has an established language for incomplete observation. As the NIST statistical handbook explains, an exact event time, an interval containing the event and a period ending without an observed failure contain different information. Censoring methods retain those distinctions when estimating failure behaviour.
The relevant endpoint must still be defined. Time without a detected compromise measures something different from time known to be uncompromised. Treating the former as the latter adds an assumption about detection. An analyst should state that assumption and examine how results change when it is weakened.
Put the audit inside the model
The paper combines hazard and recurrent-event methods with a susceptible–infected–removed model. It relates detection to the audit sample, the interval between reviews and the spread of compromise across hosts. One stated assumption is that an infected host will be identified if it is inspected.
The analysis also considers false negatives caused by sampling and compares fixed with varying audit intervals. Audit costs and organisational constraints enter the choice; effort need not scale proportionally with the number of hosts reviewed. These are conditional modelling tools, rather than a measured universal audit schedule. The public manuscript record identifies the earlier 2011 text.
Connect the measurement to a decision
The wider programme appears in my 2017 doctoral thesis, The Quantification of Information Systems Risk. Its published abstract describes an integrated treatment of human, software and system risks, combining statistical and game-theoretic approaches. It connects system design and misconfiguration with survival modelling, resource allocation and the distribution of costs and liability.
That combination matters because a security budget buys several different things: reduced exposure, better observation and faster response. A review that finds more incidents may have improved detection. A fall in recorded incidents may reflect prevention, a change in what is inspected or a loss of visibility. Counts alone cannot choose between those explanations.
Make the comparison testable
A useful evaluation would preserve inspection dates, sampled hosts, detection methods and subsequent interventions. It would record changes in the population being monitored and distinguish observed outcomes from reconstructed incident times. Where detection is imperfect, that uncertainty belongs in the comparison.
The historical research provides a starting framework. Applying it to a present-day environment requires current evidence about that environment and validation of the selected model. The practical question is how much additional risk reduction or useful information an extra review buys, given what the organisation can actually observe and change.