{"id":{"repo_id":"carleton","oai_identifier":"oai:carleton.scholaris.ca:20.500.14718/43041"},"canonical_url":"https://search.dev.ndltd.org/etd/carleton/oai:carleton.scholaris.ca:20.500.14718/43041","repository":{"repo_id":"carleton","name":"Carleton University","base_url":"https://carleton.scholaris.ca/server/oai/request"},"display":{"title":"Knowledge Reuse as a Foundation for Security Metrics","abstract":"The recurring question within the cybersecurity landscape is---why do systems keep getting successfully attacked? This relative ease of system breaches necessitates a reevaluation of what it means for attacks to be ``hard&apos;&apos;. Existing security metrics quantify narrow aspects of attack difficulty but do not give insight into why attacks remain feasible. Diversity is frequently discussed as a strategy to mitigate the risks associated with cybersecurity monoculture. However, determining the optimal level and type of diversity in security presents complex challenges for which we have little basis. We propose a new way of conceptualizing attack difficulty in terms of knowledge reuse. To this end, we present two models---one abstract model inspired by artificial intelligence search and another model, product family algebra, inspired by software components. Using these models we propose three new metrics: knowledge obfuscation (KOSM), defense evolution (DESM), and population fragility. We then analyze the practical implications of our proposed models for an information security analyst. By adopting these models, information security analysts can better navigate the complexities of the cybersecurity landscape, tailor security measures more precisely to their organization&apos;s needs, and ultimately contribute to a more resilient and secure digital environment.","abstract_html":"The recurring question within the cybersecurity landscape is---why do systems keep getting successfully attacked? This relative ease of system breaches necessitates a reevaluation of what it means for attacks to be ``hard&amp;apos;&amp;apos;. Existing security metrics quantify narrow aspects of attack difficulty but do not give insight into why attacks remain feasible. Diversity is frequently discussed as a strategy to mitigate the risks associated with cybersecurity monoculture. However, determining the optimal level and type of diversity in security presents complex challenges for which we have little basis. We propose a new way of conceptualizing attack difficulty in terms of knowledge reuse. To this end, we present two models---one abstract model inspired by artificial intelligence search and another model, product family algebra, inspired by software components. Using these models we propose three new metrics: knowledge obfuscation (KOSM), defense evolution (DESM), and population fragility. We then analyze the practical implications of our proposed models for an information security analyst. By adopting these models, information security analysts can better navigate the complexities of the cybersecurity landscape, tailor security measures more precisely to their organization&amp;apos;s needs, and ultimately contribute to a more resilient and secure digital environment.","abstract_has_math":false,"creators":["Mansourzadeh, Nilofar"],"institution":"Carleton University","degree_name":"Doctor of Philosophy (Ph.D.)","degree_level":"Doctoral","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024","date_published":"2024","updated_at":"2026-07-24T01:34:34Z","subjects":[],"languages":["en"],"rights":["Copyright © 2024 the author(s). Theses may be used for non-commercial research, educational, or related academic purposes only. Such uses include personal study, distribution to students, research and scholarship. Theses may only be shared by linking to the Carleton University Institutional Repository and no part may be copied without proper attribution to the author; no part may be used for commercial purposes directly or indirectly via a for-profit platform; no adaptation or derivative works are permitted without consent from the copyright owner."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.doi","label":"DOI","values":["10.22215/etd/2024-16196"],"render_values":[{"text":"10.22215/etd/2024-16196","href":"https://doi.org/10.22215/etd/2024-16196","code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/20.500.14718/43041","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Mansourzadeh, Nilofar"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-04-08T20:48:29Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-04-08T20:48:29Z"]},{"key":"dc:date.issued","label":"Date","values":["2024"]},{"key":"dc:publisher","label":"Institution","values":["Carleton University"]},{"key":"dc:type","label":"Dc Type","values":["thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Doctoral"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy (Ph.D.)"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright © 2024 the author(s). Theses may be used for non-commercial research, educational, or related academic purposes only. Such uses include personal study, distribution to students, research and scholarship. Theses may only be shared by linking to the Carleton University Institutional Repository and no part may be copied without proper attribution to the author; no part may be used for commercial purposes directly or indirectly via a for-profit platform; no adaptation or derivative works are permitted without consent from the copyright owner."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.doi","label":"DOI","values":["10.22215/etd/2024-16196"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/20.500.14718/43041"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The recurring question within the cybersecurity landscape is---why do systems keep getting successfully attacked? This relative ease of system breaches necessitates a reevaluation of what it means for attacks to be ``hard&apos;&apos;. Existing security metrics quantify narrow aspects of attack difficulty but do not give insight into why attacks remain feasible. Diversity is frequently discussed as a strategy to mitigate the risks associated with cybersecurity monoculture. However, determining the optimal level and type of diversity in security presents complex challenges for which we have little basis. We propose a new way of conceptualizing attack difficulty in terms of knowledge reuse. To this end, we present two models---one abstract model inspired by artificial intelligence search and another model, product family algebra, inspired by software components. Using these models we propose three new metrics: knowledge obfuscation (KOSM), defense evolution (DESM), and population fragility. We then analyze the practical implications of our proposed models for an information security analyst. By adopting these models, information security analysts can better navigate the complexities of the cybersecurity landscape, tailor security measures more precisely to their organization&apos;s needs, and ultimately contribute to a more resilient and secure digital environment."]},{"key":"dc:title","label":"Title","values":["Knowledge Reuse as a Foundation for Security Metrics"]}]}],"canonical_facts":{"dc:creator":["Mansourzadeh, Nilofar"],"dc:date.accessioned":["2025-04-08T20:48:29Z"],"dc:date.available":["2025-04-08T20:48:29Z"],"dc:date.issued":["2024"],"dc:description.abstract":["The recurring question within the cybersecurity landscape is---why do systems keep getting successfully attacked? This relative ease of system breaches necessitates a reevaluation of what it means for attacks to be ``hard&apos;&apos;. Existing security metrics quantify narrow aspects of attack difficulty but do not give insight into why attacks remain feasible. Diversity is frequently discussed as a strategy to mitigate the risks associated with cybersecurity monoculture. However, determining the optimal level and type of diversity in security presents complex challenges for which we have little basis. We propose a new way of conceptualizing attack difficulty in terms of knowledge reuse. To this end, we present two models---one abstract model inspired by artificial intelligence search and another model, product family algebra, inspired by software components. Using these models we propose three new metrics: knowledge obfuscation (KOSM), defense evolution (DESM), and population fragility. We then analyze the practical implications of our proposed models for an information security analyst. By adopting these models, information security analysts can better navigate the complexities of the cybersecurity landscape, tailor security measures more precisely to their organization&apos;s needs, and ultimately contribute to a more resilient and secure digital environment."],"dc:identifier.doi":["10.22215/etd/2024-16196"],"dc:identifier.uri":["https://hdl.handle.net/20.500.14718/43041"],"dc:language.iso":["en"],"dc:publisher":["Carleton University"],"dc:rights":["Copyright © 2024 the author(s). Theses may be used for non-commercial research, educational, or related academic purposes only. Such uses include personal study, distribution to students, research and scholarship. Theses may only be shared by linking to the Carleton University Institutional Repository and no part may be copied without proper attribution to the author; no part may be used for commercial purposes directly or indirectly via a for-profit platform; no adaptation or derivative works are permitted without consent from the copyright owner."],"dc:title":["Knowledge Reuse as a Foundation for Security Metrics"],"dc:type":["thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Doctoral"],"thesis:degree_name":["Doctor of Philosophy (Ph.D.)"]},"updated_at":"2026-07-24T01:34:34Z"}