Individual Submission Summary
Share...

Direct link:

Sometimes Three Rights Really Do Make a Wrong: Measuring Cybersecurity and Simpson’s Paradox

Sat, Nov 18, 11:00am to 12:20pm, Marriott, Room 304, 3rd Floor

Abstract

Many of the over-time trends in available cybersecurity indicators appear to show that things are getting decidedly worse online. Yet many of these negative trajectories might actually be based upon underlying trends that paradoxically show the situation in online security to be improving over time. This peculiar reversal is known as ‘Simpson’s Paradox.’ Using a Monte Carlo simulation involving 1,001 iterations of randomly simulated data, I show that a variant of Simpson Paradox could easily be clouding our view of cybersecurity. Simpson’s Paradox emerges in the data when three conditions obtain: 1) the aggregate numbers are based upon data from definable subgroups; 2) these subgroups have differential propensities towards being hacked; and 3) the rate of expansion of these groups over time is mirrored by their propensity towards being hacked, with the most vulnerable groups expanding fastest. The near exponential growth of the IoT almost ensures that these conditions exist online. The possibility of a Simpson’s Paradox in cyberspace entails that the overall state of online security might not be as bad as many people think and that radically disjunctive policy reform to ‘fix’ the perceived problems of cybersecurity might not be warranted by the available evidence.

Author