4th Workshop on
Quality of Protection
Workshop co-located with CCS-2008

Mon. Oct. 27, 2008 - Alexandria VA, USA



Speaker: Gunnar Peterson - Arctec Group, Minneapolis, MN (USA)
Title: The Economics of Finding and Fixing Vulnerabilities in Distributed Systems

Abstract: Robert Morris Sr. has noted that “security and especially cryptography are essentially economic issues.” This talk describes the tradeoff analysis that occurs on a daily basis in enterprise information security and software development groups: what bugs and flaws are uncovered, what security capabilities exist, and what is—in fact—the response to security problems. We will explore the patterns that emerge to see where the software security industry is going and why.

CV: Gunnar Peterson is a Managing Principal at Arctec Group. He focuses on distributed systems security for large, mission-critical systems in the financial, healthcare, manufacturing, and insurance industries, as well as emerging start-ups. Mr. Peterson is an internationally recognized software security expert, frequently published and also serving as the Associate Editor for the IEEE Security & Privacy Journal on Building Security. He is also an Associate Editor for the Information Security Bulletin, a contributor to the SEI and DHS Build Security In portal on software security, and an in-demand speaker at many security conferences.