Defining "The Weakest Link" Comparative Security in Complex Systems of Systems

Wolter Pieters

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    9 Citations (Scopus)
    8 Downloads (Pure)


    Cloud architectures are complex socio-technical systems of systems, consisting not only of technological components and their connections, but also of physical premises and employees. When analysing security of such systems and considering countermeasures, the notion of "weakest link" often appears. Humans are then typically said to be the "weakest link" when it comes to security, but no proof is provided for this statement. One reason for this is the fact that there are no unified metrics of security that would apply to physical, digital and social components of complex systems alike. How does one compare the security of a room against the security of a piece of data, and how does social engineering an employee compare to exploiting a server vulnerability? Are we really comparing apples and oranges here, or would it be possible to present a comparative metric that would apply across the different domains? This paper explores the possibility of such a metric for complex systems, and proposes one in terms of the risk induced by an entity in the system. This also provides a foundation for the notion of "weakest link", in terms of the entity (set of entities) with the highest induced risk.
    Original languageUndefined
    Title of host publication2013 IEEE 5th International Conference on Cloud Computing Technology and Science, CloudCom
    Place of PublicationPiscataway, New Jersey
    Number of pages6
    ISBN (Print)978-0-7695-5095-4
    Publication statusPublished - 5 Dec 2013
    Event5th IEEE International Conference on Cloud Computing Technology and Science, CloudCom 2013 - Bristol, United Kingdom
    Duration: 2 Dec 20135 Dec 2013
    Conference number: 5

    Publication series

    PublisherIEEE Computer Society


    Conference5th IEEE International Conference on Cloud Computing Technology and Science, CloudCom 2013
    Abbreviated titleCloudCom
    Country/TerritoryUnited Kingdom
    Internet address


    • SCS-Cybersecurity
    • Socio-technical security
    • EWI-24649
    • induced risk
    • comparative security
    • weakest link
    • METIS-304055
    • EC Grant Agreement nr.: FP7/318003
    • security risk assessment
    • Security Metrics
    • IR-90427
    • Attacker utility
    • EC Grant Agreement nr.: FP7/2007-2013

    Cite this