Cyber-Security Can't Ignore Human Behavior

By Eric Bonabeau

In an earlier post, our beloved Jim Fallows wrote briefly about a DoD-funded cyber-security initiative named SENDS, for Science-Enhanced Networked Domains and Secure Social Spaces. The overall objective of SENDS is to promote and begin to demonstrate the concept of a science of cyberspace -- with an initial focus on security. The vision for SENDS, developed by Carl Hunt, Richard Raines and Craig Harm, is one that embraces the richness, diversity and messiness of cyberspace. Central to their vision is the idea that the social, economic and behavioral aspects of cyberspace, which are largely missing from the general discourse on cyber-security and are certainly under-funded and under-represented in government-sponsored programs, are at the core of what makes cyberspace the complex, adaptive system that it is. An inclusive, multi-disciplinary, holistic approach that combines the technical and the behavioral is needed.

Being a founding member of the SENDS initiative, I am definitely partial to its vision. The extent to which research and development in cyber-security has been skewed toward "technical solutions" is mind-boggling. As an illustration, it seems surreal that in an otherwise excellent document, the authors of a 2009 manifesto from Sandia National Laboratories entitled "Complexity Science Challenges in Cybersecurity" have not dedicated a single line to human behavior. For example, their main M&S thrust is entitled: "Modeling the behavior of programs, machines, and networks". No humans necessary -- although I concur with the authors that there is a need for a new "cyber-calculus" -- just the ability to frame concepts and issues in modern mathematical terms would be of enormous help. Or in a recent report by a DoD-funded group of physicists, you can read:  

On the positive side, the cyber-universe can be thought of as reduced to the 0s and 1s of binary data. Actions in this universe consist of sequences of changes to binary data, interleaved in time, and having some sort of locations in space. One can speculate as to why mathematics is so effective in explaining physics, but the cyber-world is inherently mathematical.

But cyberspace, although it is the result of tremendous technological progress, is not just a piece of technology: It is both an enabler and an amplifier of human nature, eliciting new manifestations of human nature. It feeds (and in many ways feeds on) one of the most fundamental needs of human beings: communication. That it has become such an integral part of our lives in such a short time shows how deeply it resonates with our need to communicate and be connected. It should come as no surprise, therefore, that the multifaceted dynamics of cyberspace be so strongly influenced, even defined, by the behavior of its participants.

According to Mark Graff of Lawrence Livermore National Laboratory, cyberspace gives individuals and small groups unprecedented reach to affect others; it makes physical distance much less of an insulating factor; confuses us about what is permanent, or public, or safe; and largely operates insensibly to us. We feel safer if important data is near us, or some place we know, or with someone we've met, but these comfort factors make no "Internet" sense and don't scale to Internet dimensions either. In matters of risk assessment, we feel pretty safe from attacks originating "far away;" we also tend to ignore "low and slow" -- or sporadic -- attacks; random, "pointless" attacks (like from Internet worms) mostly tend to be low on our worry list, too.

Presented by

James Fallows is a national correspondent for The Atlantic and has written for the magazine since the late 1970s. He has reported extensively from outside the United States and once worked as President Carter's chief speechwriter. His latest book is China Airborne. More

James Fallows is based in Washington as a national correspondent for The Atlantic. He has worked for the magazine for nearly 30 years and in that time has also lived in Seattle, Berkeley, Austin, Tokyo, Kuala Lumpur, Shanghai, and Beijing. He was raised in Redlands, California, received his undergraduate degree in American history and literature from Harvard, and received a graduate degree in economics from Oxford as a Rhodes scholar. In addition to working for The Atlantic, he has spent two years as chief White House speechwriter for Jimmy Carter, two years as the editor of US News & World Report, and six months as a program designer at Microsoft. He is an instrument-rated private pilot. He is also now the chair in U.S. media at the U.S. Studies Centre at the University of Sydney, in Australia.

Fallows has been a finalist for the National Magazine Award five times and has won once; he has also won the American Book Award for nonfiction and a N.Y. Emmy award for the documentary series Doing Business in China. He was the founding chairman of the New America Foundation. His recent books Blind Into Baghdad (2006) and Postcards From Tomorrow Square (2009) are based on his writings for The Atlantic. His latest book is China Airborne. He is married to Deborah Fallows, author of the recent book Dreaming in Chinese. They have two married sons.

Fallows welcomes and frequently quotes from reader mail sent via the "Email" button below. Unless you specify otherwise, we consider any incoming mail available for possible quotation -- but not with the sender's real name unless you explicitly state that it may be used. If you are wondering why Fallows does not use a "Comments" field below his posts, please see previous explanations here and here.

How to Cook Spaghetti Squash (and Why)

Cooking for yourself is one of the surest ways to eat well. Bestselling author Mark Bittman teaches James Hamblin the recipe that everyone is Googling.


How to Cook Spaghetti Squash (and Why)

Cooking for yourself is one of the surest ways to eat well.


Before Tinder, a Tree

Looking for your soulmate? Write a letter to the "Bridegroom's Oak" in Germany.


The Health Benefits of Going Outside

People spend too much time indoors. One solution: ecotherapy.


Where High Tech Meets the 1950s

Why did Green Bank, West Virginia, ban wireless signals? For science.


Yes, Quidditch Is Real

How J.K. Rowling's magical sport spread from Hogwarts to college campuses


Would You Live in a Treehouse?

A treehouse can be an ideal office space, vacation rental, and way of reconnecting with your youth.

More in Technology

From This Author

Just In