I Am a Scientist, Not a Philosopher!



Bibliographic Information


To evaluate anything we can’t prove using pure mathematics or logical syllogism, we must test hypotheses by performing controlled experiments to generate measurable, empirical data. But today’s computer security researchers often claim “proof” without following this approach. Failure to follow the scientific method rigorously can create problems. This article presents a method for scientific experimentation when others aren’t appropriate or can’t be readily applied. The goal is to further motivate researchers to apply science to experiments.

Copyright Notice

©2007 IEEE. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.
This material is presented to ensure timely dissemination of scholarly and technical work. Copyright and all rights therein are retained by authors or by other copyright holders. All persons copying this information are expected to adhere to the terms and constraints invoked by each author’s copyright. In most cases, these works may not be reposted without the explicit permission of the copyright holder.
The definitive version was published in IEEE Security & Privacy Magazine 5(4), July 2007.