George Jones

Curious Musings

Sep 2026

Using Science in Cybersecurity

Critial open source projects, like Linux, will be unable to track/respond to knonw (and likely, many more unknow) exploints in real time. A book by two of of my former CERT co-workers pointed out that CVEs/vuln declosers were just a known sampling of a much larger unknown pouplation and that in that world the only rational way to respond is to treat seucrutiy vulnerablities as a statistics problem. Time for new approaches. Ahead of the curve again, see Using Science in Cybersecurity