EvoSec 2025W Lecture 11

From Soma-notes
Revision as of 17:58, 6 February 2025 by Soma (talk | contribs) (Created page with "<pre> Lecture 9 --------- What is entropy? (G1) - least diverse -> least entropy So maybe increasing entropy (disorder) would increase security? - multiple kinds of software, hosts, etc But that seems chaotic and thus insecure? Entropy on a specific graph - hosts can have some number of vulns - edges represent the vulns a host has - cannot remove all edges by assumption - hosts always have some - increase entropy -> more disorder in edges Adding new kinds of s...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Lecture 9
---------

What is entropy? (G1)
 - least diverse -> least entropy

So maybe increasing entropy (disorder) would increase security?
 - multiple kinds of software, hosts, etc

But that seems chaotic and thus insecure?

Entropy on a specific graph
 - hosts can have some number of vulns
 - edges represent the vulns a host has
 - cannot remove all edges by assumption - hosts always have some
 - increase entropy -> more disorder in edges

Adding new kinds of systems => increase the space of vulnerabilities
 - attack surface goes up!

If diversity is the answer, what is the question?
 - consider for Thursday