SoK: Science, Security and the Elusive Goal of Security as a Scientific Pursuit
Cormac Herley, Paul C. van Oorschot
Abstract
The past ten years has seen increasing calls to make security research more "scientific". On the surface, most agree that this is desirable, given universal recognition of "science" as a positive force. However, we find that there is little clarity on what "scientific" means in the context of computer security research, or consensus on what a "Science of Security" should look like. We selectively review work in the history and philosophy of science and more recent work under the label "Science of Security". We explore what has been done under the theme of relating science and security, put this in context with historical science, and offer observations and insights we hope may motivate further exploration and guidance. Among our findings are that practices on which the rest of science has reached consensus appear little used or recognized in security, and a pattern of methodological errors continues unaddressed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ec312eff-c327-4db7-9b09-e70daf90a2f6Cited by top-tier papers16
- Rethinking Softmax Cross-Entropy Loss for Adversarial RobustnessTianyu Pang, Kun Xu, Yinpeng Dong, Chao Du et al.ICLR 2020 · 176 citations
- Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesFaris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili et al.CCS 2019 · 134 citations
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- "If HTTPS Were Secure, I Wouldn't Need 2FA" - End User and Administrator Mental Models of HTTPSKatharina Krombholz, Karoline Busse, Katharina Pfeffer, Matthew Smith et al.S&P 2019 · 105 citations
- WaveGuard: Understanding and Mitigating Audio Adversarial ExamplesShehzeen Hussain, Paarth Neekhara, Shlomo Dubnov, Julian J. McAuley et al.USENIX Security 2021 · 89 citations
Builds on1
Related papers
- Data to Infinity and Beyond: Examining Data Sharing and Reuse Practices in the Computer Security CommunityAnna Crowder, Allison Lu, Kevin Childs, Carson Stillman et al.S&P 2025
- "Flawed, but like democracy we don't have a better system": The Experts' Insights on the Peer Review Process of Evaluating Security PapersAnanta Soneji, Faris Bugra Kokulu, Carlos E. Rubio-Medrano, Tiffany Bao et al.S&P 2022 · 17 citations
- Ethical Frameworks and Computer Security Trolley Problems: Foundations for ConversationsTadayoshi Kohno, Yasemin Acar, Wulf LohUSENIX Security 2023
- SoK: Towards a Unified Approach to Applied Replicability for Computer SecurityDaniel Olszewski, Tyler Tucker, Kevin R. B. Butler, Patrick TraynorUSENIX Security 2025
- SoK: Safer Digital-Safety Research Involving At-Risk UsersRosanna Bellini, Emily Tseng, Noel Warford, Alaa Daffalla et al.S&P 2024 · 48 citations
