Skip to main content
QUICK REVIEW

[Paper Review] What Should be Hidden and Open in Computer Security: Lessons from Deception, the Art of War, Law, and Economic Theory

Peter Swire|ArXiv.org|Sep 24, 2001
Cybersecurity and Cyber Warfare Studies3 citations
TL;DR

This paper develops a theoretical framework for determining what should be hidden or open in computer security by integrating insights from military strategy (Sun Tzu and Clausewitz), law, and economics. It argues that while secrecy protects against attacks—like military booby traps—openness in software and systems enhances trust and market efficiency, with economic models revealing potential market failures in openness levels, ultimately guiding policy and design decisions on transparency in cybersecurity.

ABSTRACT

"What Should be Hidden and Open in Computer Security: Lessons from Deception, the Art of War, Law, and Economic Theory" Peter P. Swire, George Washington University. Imagine a military base. It is defended against possible attack. Do we expect the base to reveal the location of booby traps and other defenses? No. But for many computer applications,a software developer will need to reveal a great deal about the code to get other system owners to trust the code and know how to operate with it. This article examines these conflicting intuitions and develops a theory about what should be open and hidden in computer security. Part I of the paper shows how substantial openness is typical for major computer security topics, such as firewalls, packaged software, and encryption. Part II shows what factors will lead to openness or hiddenness in computer security. Part III presents an economic analysis of the issue of what should be open in computer security. The owner who does not reveal the booby traps is like a monopolist, while the open-source software supplier is in a competitive market. This economic approach allows us to identify possible market failures in how much openness occurs for computer security. Part IV examines the contrasting approaches of Sun Tzu and Clausewitz to the role of hiddenness and deception in military strategy. The computer security, economic, and military strategy approaches thus each show factors relevant to what should be kept hidden in computer security. Part V then applies the theory to a range of current legal and technical issues.

Motivation & Objective

  • To resolve the tension between secrecy (like military defenses) and openness (like open-source software) in computer security.
  • To identify the factors that determine when security components should be hidden or revealed, based on strategic, legal, and economic principles.
  • To analyze market failures in the level of openness in computer security, particularly in software and cryptographic systems.
  • To apply insights from Sun Tzu and Clausewitz on deception and strategy to modern cybersecurity decision-making.
  • To provide a framework for legal and technical policy on transparency in software, encryption, and system design.

Proposed method

  • Analyzes real-world examples of openness and secrecy in major security domains: firewalls, packaged software, and encryption.
  • Applies economic models comparing monopolistic secrecy (hiding flaws) to competitive open-source models (revealing code) to assess market efficiency.
  • Uses military strategy—particularly the contrast between Sun Tzu’s emphasis on deception and Clausewitz’s focus on open confrontation—to inform security transparency decisions.
  • Integrates legal and regulatory perspectives on disclosure, including liability and compliance, to assess transparency trade-offs.
  • Constructs a theoretical model balancing security through obscurity versus security through transparency, using game-theoretic and incentive-based reasoning.
  • Evaluates current legal and technical issues (e.g., software disclosure, vulnerability reporting) through the lens of the proposed framework.

Experimental results

Research questions

  • RQ1When should security mechanisms be hidden to prevent exploitation, and when should they be open to enable verification and trust?
  • RQ2How do economic incentives influence the level of openness in software and cryptographic systems, and where do market failures occur?
  • RQ3What strategic lessons from Sun Tzu’s and Clausewitz’s military doctrines apply to modern computer security transparency?
  • RQ4How do legal and regulatory frameworks affect the decision to disclose or conceal security flaws and system designs?
  • RQ5What criteria can be used to determine the optimal balance between security through obscurity and security through transparency?

Key findings

  • Openness in software and security systems increases trust and reduces systemic risk, especially in competitive markets where transparency acts as a signal of quality.
  • Market failures occur when developers under-invest in openness due to incentives to hide vulnerabilities, leading to suboptimal security outcomes.
  • The contrast between Sun Tzu’s strategic deception and Clausewitz’s emphasis on open, decisive conflict reveals that different threat models require different transparency strategies.
  • Legal and regulatory frameworks often fail to align with optimal transparency levels, creating disincentives for responsible disclosure of vulnerabilities.
  • Economic models show that open-source software, despite potential risks, often leads to better long-term security due to peer review and competitive pressure.
  • The paper concludes that a balanced, context-sensitive approach—guided by economic, strategic, and legal principles—is essential for determining what should be hidden or open in computer security.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.