<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Security Prediction Markets?</title>
	<atom:link href="http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:02:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: asiegel</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4727</link>
		<dc:creator>asiegel</dc:creator>
		<pubDate>Thu, 12 Jun 2008 14:59:50 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4727</guid>
		<description>I&#039;ve been following this stream and commented earlier (i&#039;m the adam that got yelled at about using his first name :) about the utility of prediction markets. I&#039;m the co-founder of a prediction market platform company, Inkling. We&#039;d be happy to facilitate an experiment if you&#039;d like to try out some of the theories bantered around as i think this is an interesting area that has not really been explored in the space. If someone (the original adam) wants to email me we can talk more about getting something set up. (adam [at] inklingmarkets [dot] com)
</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been following this stream and commented earlier (i&#8217;m the adam that got yelled at about using his first name :) about the utility of prediction markets. I&#8217;m the co-founder of a prediction market platform company, Inkling. We&#8217;d be happy to facilitate an experiment if you&#8217;d like to try out some of the theories bantered around as i think this is an interesting area that has not really been explored in the space. If someone (the original adam) wants to email me we can talk more about getting something set up. (adam [at] inklingmarkets [dot] com)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chesurow</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4726</link>
		<dc:creator>chesurow</dc:creator>
		<pubDate>Wed, 11 Jun 2008 11:18:33 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4726</guid>
		<description>A few thoughts about prediction markets: Banks have a vested interest in securing systems from data theft, corruption, and ensuring availability. Internal prediction markets for large organizations might provide insight to help prioritize tools and initiatives used to secure programs and systems.
1) To start, the discussion should be reframmed around internal prediction markets. The feedback of an public prediction market would be abject because of the firmly held belief that masses do not no more than experts. Nonetheless, this doesn&#039;t wholly invalidate  @jon&#039;s framework for looking at the problem. From a slightly different angle, a large pool of experts would behave like any large group. I believe theres a physics analogy here, but I&#039;ll leave it alone. So to reposition the argument, we&#039;re interested in knowing what programmers, network engineers, and DB administrators know about &quot;structural&quot; flaws and their likely impact on events (scale of problem increases liklihood and impact), versus application team managers, versus the managers (who sometimes aren&#039;t much different from Alice and Bob due to competing concerns) who establish security strategy and direction.
2) The utility in knowing the difference between perceptions of risk is well documented in the failure of the decision support system at NASA prior to the Challenger catastrophe.  Management has an inherent perception bias and there is often dissonance between perceived risk and actual risk. To illustrate, just ask someone about their fear of dying in a airplane crash versus finding the probability that it will actually happen.
3) Google (internal) prediction market makers suggest that in terms of diversity, regional location trumps department affiliation. So to acheive diversity of opionion you not only need  participants from a range of disciplines, you also need broad geographic participation.
4) With the correct incentives and market rules in place, knowledgable insiders can be contained and shouldn&#039;t be able to game the system. Granted it ss very difficult to address, and it may be the point of failure for internal prediction markets in large IT organizations.
</description>
		<content:encoded><![CDATA[<p>A few thoughts about prediction markets: Banks have a vested interest in securing systems from data theft, corruption, and ensuring availability. Internal prediction markets for large organizations might provide insight to help prioritize tools and initiatives used to secure programs and systems.<br />
1) To start, the discussion should be reframmed around internal prediction markets. The feedback of an public prediction market would be abject because of the firmly held belief that masses do not no more than experts. Nonetheless, this doesn&#8217;t wholly invalidate  @jon&#8217;s framework for looking at the problem. From a slightly different angle, a large pool of experts would behave like any large group. I believe theres a physics analogy here, but I&#8217;ll leave it alone. So to reposition the argument, we&#8217;re interested in knowing what programmers, network engineers, and DB administrators know about &#8220;structural&#8221; flaws and their likely impact on events (scale of problem increases liklihood and impact), versus application team managers, versus the managers (who sometimes aren&#8217;t much different from Alice and Bob due to competing concerns) who establish security strategy and direction.<br />
2) The utility in knowing the difference between perceptions of risk is well documented in the failure of the decision support system at NASA prior to the Challenger catastrophe.  Management has an inherent perception bias and there is often dissonance between perceived risk and actual risk. To illustrate, just ask someone about their fear of dying in a airplane crash versus finding the probability that it will actually happen.<br />
3) Google (internal) prediction market makers suggest that in terms of diversity, regional location trumps department affiliation. So to acheive diversity of opionion you not only need  participants from a range of disciplines, you also need broad geographic participation.<br />
4) With the correct incentives and market rules in place, knowledgable insiders can be contained and shouldn&#8217;t be able to game the system. Granted it ss very difficult to address, and it may be the point of failure for internal prediction markets in large IT organizations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Guido</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4725</link>
		<dc:creator>Dan Guido</dc:creator>
		<pubDate>Sat, 07 Jun 2008 13:38:10 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4725</guid>
		<description>It&#039;s Dan again,
@jon - I&#039;m sure that betting on futures will work great when I have a stack of 10 0day in Firefox and release them one at a time, betting on a future for a patch each time. Or when I&#039;m a Firefox developer myself and work on the code in question. I&#039;m also sure that betting on the results of pwn2own will work when I&#039;m sitting on an Apple 0day for 3 months before the contest. Or when one has been passed around non-publicly in the underground before the contract on the market.
In security, SOMEONE knows the RIGHT answer. It is not indeterminate, the code is out there, your network is accessible to me and so on. There&#039;s none of this wishy-washy risk stuff.
@Alex - You are getting closer. Predicting if a incident will occur is one level removed from predicting the discovery of security flaws, but I still see the same problems with it. Let&#039;s take this one from a different angle: I work at corp ABC in the security department. Myself and my coworkers have been tracking an intrusion into our network for the last 8 weeks. We know the answer to &quot;has corp ABC been breached?&quot; and you don&#039;t. So do our auditors. Game over.
@Nathaniel - It is NOT about having a diverse group of opinions. They will fail because you need to make security information &quot;protected&quot; the same way that other banking information is if you want to develop a market for it. If I know corp ABC has been breached, I shouldn&#039;t be able to play in the market with that information, so you need the law to keep my mouth shut. Same for security bugs/patches/exploits.
@Adam - I think you get it.
Until I see something really novel about the way to construct a security prediction market, I don&#039;t think they will work.
</description>
		<content:encoded><![CDATA[<p>It&#8217;s Dan again,<br />
@jon &#8211; I&#8217;m sure that betting on futures will work great when I have a stack of 10 0day in Firefox and release them one at a time, betting on a future for a patch each time. Or when I&#8217;m a Firefox developer myself and work on the code in question. I&#8217;m also sure that betting on the results of pwn2own will work when I&#8217;m sitting on an Apple 0day for 3 months before the contest. Or when one has been passed around non-publicly in the underground before the contract on the market.<br />
In security, SOMEONE knows the RIGHT answer. It is not indeterminate, the code is out there, your network is accessible to me and so on. There&#8217;s none of this wishy-washy risk stuff.<br />
@Alex &#8211; You are getting closer. Predicting if a incident will occur is one level removed from predicting the discovery of security flaws, but I still see the same problems with it. Let&#8217;s take this one from a different angle: I work at corp ABC in the security department. Myself and my coworkers have been tracking an intrusion into our network for the last 8 weeks. We know the answer to &#8220;has corp ABC been breached?&#8221; and you don&#8217;t. So do our auditors. Game over.<br />
@Nathaniel &#8211; It is NOT about having a diverse group of opinions. They will fail because you need to make security information &#8220;protected&#8221; the same way that other banking information is if you want to develop a market for it. If I know corp ABC has been breached, I shouldn&#8217;t be able to play in the market with that information, so you need the law to keep my mouth shut. Same for security bugs/patches/exploits.<br />
@Adam &#8211; I think you get it.<br />
Until I see something really novel about the way to construct a security prediction market, I don&#8217;t think they will work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam of Emergent Chaos</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4724</link>
		<dc:creator>Adam of Emergent Chaos</dc:creator>
		<pubDate>Fri, 06 Jun 2008 17:53:56 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4724</guid>
		<description>Jon,
That&#039;s a really interesting point.  I think the closest thing to a security prediction market would be Crispin Cowan&#039;s Sardonix.  Or perhaps Poindexter&#039;s Terrorism markets.  I did try to be careful to say I&#039;m skeptical, rather than &quot;don&#039;t try this.&quot;  That may have been the implied message, but I&#039;m pretty (free here on this blog)  saying &quot;that&#039;s silly.&quot;
Adam of the 11:55 comment
I thought about that, and don&#039;t know that there&#039;s enough information on the relation between flaws and breaches to make good calls.  On the other hand, maybe that would emerge from the chaos of a market.  PS: could you use a different name for the comments here?  As the bandleader, I often comment as Adam, and would prefer to avoid confusion about who&#039;s saying what.
</description>
		<content:encoded><![CDATA[<p>Jon,<br />
That&#8217;s a really interesting point.  I think the closest thing to a security prediction market would be Crispin Cowan&#8217;s Sardonix.  Or perhaps Poindexter&#8217;s Terrorism markets.  I did try to be careful to say I&#8217;m skeptical, rather than &#8220;don&#8217;t try this.&#8221;  That may have been the implied message, but I&#8217;m pretty (free here on this blog)  saying &#8220;that&#8217;s silly.&#8221;<br />
Adam of the 11:55 comment<br />
I thought about that, and don&#8217;t know that there&#8217;s enough information on the relation between flaws and breaches to make good calls.  On the other hand, maybe that would emerge from the chaos of a market.  PS: could you use a different name for the comments here?  As the bandleader, I often comment as Adam, and would prefer to avoid confusion about who&#8217;s saying what.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4723</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Fri, 06 Jun 2008 16:57:52 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4723</guid>
		<description>It&#039;s also interesting to look at using prediction markets in conjunction with other approaches.  Situations where the different mechanisms predict different results are especially interesting.
One of the reasons that prediction markets have such a hard time in practice is that experts all have a vested interest in prediction markets failing (or not getting tried).  After all, a successful prediction market means that they, the expert, will be out-predicted by a diverse crowd -- which includes a whole bunch of people who don&#039;t even know what a buffer overrun is.  That drives experts crazy.
Are there any examples of &lt;b&gt;un&lt;/b&gt;successful prediction markets in the security space?
</description>
		<content:encoded><![CDATA[<p>It&#8217;s also interesting to look at using prediction markets in conjunction with other approaches.  Situations where the different mechanisms predict different results are especially interesting.<br />
One of the reasons that prediction markets have such a hard time in practice is that experts all have a vested interest in prediction markets failing (or not getting tried).  After all, a successful prediction market means that they, the expert, will be out-predicted by a diverse crowd &#8212; which includes a whole bunch of people who don&#8217;t even know what a buffer overrun is.  That drives experts crazy.<br />
Are there any examples of <b>un</b>successful prediction markets in the security space?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bill</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4722</link>
		<dc:creator>bill</dc:creator>
		<pubDate>Fri, 06 Jun 2008 13:52:53 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4722</guid>
		<description>I have been debating the utility of using prediction markets for risk assessments, or more specifically, whether prediction markets could be used instead of the likelihood x impact calculation.  Really, you are asking the same thing when you ask people to rank either of those factors.
So, if you had a list of risks that you are trying to rank, rather than existence of a vulnerability, could you use prediction markets to &#039;stack rank&#039; the risks?
I think so.
</description>
		<content:encoded><![CDATA[<p>I have been debating the utility of using prediction markets for risk assessments, or more specifically, whether prediction markets could be used instead of the likelihood x impact calculation.  Really, you are asking the same thing when you ask people to rank either of those factors.<br />
So, if you had a list of risks that you are trying to rank, rather than existence of a vulnerability, could you use prediction markets to &#8217;stack rank&#8217; the risks?<br />
I think so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4721</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Fri, 06 Jun 2008 11:55:50 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4721</guid>
		<description>One point people may not be considering is a prediction market&#039;s utility at exposing information that may already be known, but under the radar. So to Dan&#039;s point, there IS a failure point in the code, but no one may be willing to talk about it because of office politics, etc. Or it may be that a team was under extreme pressure to succeed and the old hands know inevitably there are going to be failure points. How many, in what area, etc. would be based on how the project was conducted. For example, asking about possible failure points at the beginning of the project and watching the probabilities fluctuate based on how the project is going would be pretty interesting information for the company to know. Involving people beyond the team (employees or business partners) who have tangential knowledge or have worked on these types of projects before would diversify the trading pool and also help expose information that may not have been available. The ROI of course is if you can avoid even ONE failure point before the system goes in to production, you&#039;ve probably just paid for the marketplace 10-fold.
</description>
		<content:encoded><![CDATA[<p>One point people may not be considering is a prediction market&#8217;s utility at exposing information that may already be known, but under the radar. So to Dan&#8217;s point, there IS a failure point in the code, but no one may be willing to talk about it because of office politics, etc. Or it may be that a team was under extreme pressure to succeed and the old hands know inevitably there are going to be failure points. How many, in what area, etc. would be based on how the project was conducted. For example, asking about possible failure points at the beginning of the project and watching the probabilities fluctuate based on how the project is going would be pretty interesting information for the company to know. Involving people beyond the team (employees or business partners) who have tangential knowledge or have worked on these types of projects before would diversify the trading pool and also help expose information that may not have been available. The ROI of course is if you can avoid even ONE failure point before the system goes in to production, you&#8217;ve probably just paid for the marketplace 10-fold.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathaniel H.</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4720</link>
		<dc:creator>Nathaniel H.</dc:creator>
		<pubDate>Fri, 06 Jun 2008 11:34:31 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4720</guid>
		<description>I&#039;d have to agree that prediction markets in security would fail to predict breeches. In other markets, the investors/consumers have a greater amount of information to base their decisions upon. Processes are somewhat open, policies on how to handle goods are somewhat open, and news of snags in the process spread very quickly. With security, especially in industries such as banking, there is very little information available to base one&#039;s decision upon.
As mentioned above, for the prediction market to work, we need a wide and diverse population, and they need to have a large base of information to make their judgements upon.
</description>
		<content:encoded><![CDATA[<p>I&#8217;d have to agree that prediction markets in security would fail to predict breeches. In other markets, the investors/consumers have a greater amount of information to base their decisions upon. Processes are somewhat open, policies on how to handle goods are somewhat open, and news of snags in the process spread very quickly. With security, especially in industries such as banking, there is very little information available to base one&#8217;s decision upon.<br />
As mentioned above, for the prediction market to work, we need a wide and diverse population, and they need to have a large base of information to make their judgements upon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4719</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Fri, 06 Jun 2008 08:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4719</guid>
		<description>@Dan,
I don&#039;t think we&#039;d be betting on *if* the vulnerability exists to be exploited (all organizations have some degree of vulnerability), but *when* the existing vulnerabilities would be exploited to produce incident.
---
I&#039;m skeptical about a security prediction market working for a number of reasons, including what Adam has posted there.  Heck two years ago, someone pretty smart I know was all about prediction markets, and the greater InfoSec world thought he was *nuts*.  We&#039;re just not mature enough for a prediction market.
</description>
		<content:encoded><![CDATA[<p>@Dan,<br />
I don&#8217;t think we&#8217;d be betting on *if* the vulnerability exists to be exploited (all organizations have some degree of vulnerability), but *when* the existing vulnerabilities would be exploited to produce incident.<br />
&#8212;<br />
I&#8217;m skeptical about a security prediction market working for a number of reasons, including what Adam has posted there.  Heck two years ago, someone pretty smart I know was all about prediction markets, and the greater InfoSec world thought he was *nuts*.  We&#8217;re just not mature enough for a prediction market.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://emergentchaos.com/archives/2008/06/security-prediction-markets.html/comment-page-1#comment-4718</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Fri, 06 Jun 2008 01:48:22 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2785#comment-4718</guid>
		<description>Adam, if it&#039;s only Alice and Bob, or they truly know nothing, the market will of course fail.  If there are enough people who have diverse knowledge (even if potentially only-partially-accurate) and information sources, and there is liquidity, then they are likely to outperform experts.  Even if there aren&#039;t any experts in the market there are likely to be some participants who take it seriously enough that they follow the experts.
One potential challenge is breadth of information sources.  If everybody&#039;s getting their info from reading Bruce Schneier, Slashdot, and Emergent Chaos [or any small number of sources] or the echo chamber that TechMeme creates, then the market&#039;s not likely to function well.  This is why I though the &lt;i&gt;Industry Standard&lt;/i&gt; all-male bloglist was so funny: it&#039;s a huge lack of diversity in information sources.    From what I could tell the participants in their market similarly suffer from a lack of diversity.
Dan, there are ways to construct the questions in the market to reflect your concerns; for example, futures in the number of patches Microsoft/Apple/Ubuntu will issue this month, next three months, next year.  Or it&#039;d be great to do one in conjunction with pwn2own: which system will fall first, and how long until each system falls.  So I don&#039;t see it as fundamentally incompatible with security at all.
</description>
		<content:encoded><![CDATA[<p>Adam, if it&#8217;s only Alice and Bob, or they truly know nothing, the market will of course fail.  If there are enough people who have diverse knowledge (even if potentially only-partially-accurate) and information sources, and there is liquidity, then they are likely to outperform experts.  Even if there aren&#8217;t any experts in the market there are likely to be some participants who take it seriously enough that they follow the experts.<br />
One potential challenge is breadth of information sources.  If everybody&#8217;s getting their info from reading Bruce Schneier, Slashdot, and Emergent Chaos [or any small number of sources] or the echo chamber that TechMeme creates, then the market&#8217;s not likely to function well.  This is why I though the <i>Industry Standard</i> all-male bloglist was so funny: it&#8217;s a huge lack of diversity in information sources.    From what I could tell the participants in their market similarly suffer from a lack of diversity.<br />
Dan, there are ways to construct the questions in the market to reflect your concerns; for example, futures in the number of patches Microsoft/Apple/Ubuntu will issue this month, next three months, next year.  Or it&#8217;d be great to do one in conjunction with pwn2own: which system will fall first, and how long until each system falls.  So I don&#8217;t see it as fundamentally incompatible with security at all.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
