On the Brittleness of Software and the Infeasibility of Security Metrics
Steve Bellovin · IEEE Security & Privacy · 2006
How secure is a computer system? Bridges have a load limit, but it isn't determined (as "Calvin and Hobbes" would have it) by building an identical bridge and running trucks over it until it collapses. In a more relevant vein, safes are rated for how long they'll resist attack under given circumstances. Can we do the same for software?