← Mathematical compendium

Published equation contexts

E=∑cpc dcE = \sum_{c} p_c \, d_c

Why this formula appears here

There is a simple way to see why capability removal should be the default move rather than the fallback. Model the expected exposure created by a credential as a sum over the capabilities c it carries, each with some probability pcp_c that it is exploited in a given period and some damage dcd_c if it is: E=∑cpc dcE = \sum_{c} p_c \, d_c. Two of the terms in that sum are hard to know honestly. An estimate of pcp_c assumes a threat model that has to guess at an adversary’s behaviour, and dcd_c is only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally. But there is one operation…

Read the full article-specific guide →

Read the representative guide

cc

Symbol c

c appears in the bound of this sum. The bound states where the repeated operation starts, ends, or which values it includes.

Read this term in its guide →
dcd_c

Symbol d_c

only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally.

Read this term in its guide →
cc

Starting index or lower bound: c

This label says where the repeated addition, multiplication, or accumulation starts. Read its value or condition together with the article’s description of the index.

Read this term in its guide →

How to interpret it

Read it with the definitions, units, and assumptions supplied by the article.

Research cited beside this formula

Published contexts (1)

A symbol can carry a different meaning in another article. Each occurrence keeps its own guide and term definitions.

E=∑cpc dc.E = \sum_{c} p_c \, d_c.

Equation 4 · AI Security

AI and Cybersecurity in Practice: An Advanced Technical Guide

This equation states an equality: the expressions on both sides have the same value under the article’s assumptions.

There is a simple way to see why capability removal should be the default move rather than the fallback. Model the expected exposure created by a credential as a sum over the capabilities c it carries, each with some probability pcp_c that it is exploited in a given period and some damage dcd_c if it is: E=∑cpc dcE = \sum_{c} p_c \, d_c. Two of the terms in that sum are hard to know honestly. An estimate of pcp_c assumes a threat model that has to guess at an adversary’s behaviour, and dcd_c is only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally. But there is one operation…

Meanings in this article

  • pcp_c: the better monitoring reduces your uncertainty about.
  • dcd_c: only bounded once you have already imagined the worst plausible use of the capability — the same failure of imagination that undermines defense-in-depth probability estimates generally.
Equation guide → · Article →