Learning How To Quantify Cyber Risk Using Bayes | by Stephen Shaffer | Medium
Mitigating risks in cloud environments like AWS is a challenging yet crucial task. A commonly proposed control is to remove specific ports like 22 (SSH) and 3389 (RDP) from all security group ingress rules to prevent unwanted access and reduce the probability of instance compromise. But how can we measure the effectiveness of such a strategy? Bayes’ theorem is a fundamental concept in probability theory and statistics, providing a mathematical framework for updating probabilities based on new evidence. In the context of cybersecurity, it can be used to calculate the probability of an event (like an instance compromise in AWS) given that a control (like removing port 22 and 3389) is in place. Bayes’ theorem is typically represented as: In this context: To use Bayes’ theorem, we need to understand and quantify these probabilities. By plugging these values into the Bayes’ theorem formula, we can calculate P(A|B), the updated probability of an instance compromise given the control is in pl
Cybersecurity Risk Management Cyber Risk Quantification Learning How To Quantify Cyber Risk Using Bayes Stephen Shaffer 4 min read · May 24, 2023 -- Listen Share Press enter or click to view image in full size Generated by Midjourney A Case Study on Instance Security Groups in AWS Mitigating risks in cloud environments like AWS is a challenging yet crucial task. A commonly proposed control is to remove specific ports like 22 (SSH) and 3389 (RDP) from all security group ingress rules to prevent unwanted access and reduce the probability of instance compromise. But how can we measure the effecti
Explore this link on the map →related reading
- Beyond P(doom) for AI Risk: Quantifying Uncertainty Without Probability | Center for Security and Emerging Technology Georgetown AIcset.georgetown.edu
- 2312.06942arxiv.org
- Cybersecurity Looks Like Proof of Work Nowdbreunig.com
- Bayes' rule — LessWrongarbital.com
- AWS Security Profile: Byron Cook, Director of the AWS Automated Reasoning Group | AWS Security Blogaws.amazon.com
- Thoughts on the conservative assumptions in AI controlblog.redwoodresearch.org
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- 8 Bayes’ Theorem | Odds & Endsjonathanweisberg.org
- The Letter - Stop Hacklore!hacklore.org
- Rethinking Cyber Insurance Underwriting Through Technologyforbes.com
- Bayesian programming - Wikipediaen.wikipedia.org
- 8 Top Cybersecurity Industry Trends (2024)explodingtopics.com