* New journal hits the Web
A few days ago, I interviewed Kevin Soo Hoo, program manager at McAfee Avert Labs and editor of the new _Sage_ magazine from that company. I’m excited by the Volume 1, Number 1 of the magazine and delighted at the opportunity to speak to one of its moving forces.
NW: Why did you decide to put all this work into a new magazine?
Soo Hoo: Two years ago, Dan Geer and Andrew Jaquith and I published an article in _IEEE Security and Privacy Journal_ called “Information Security: Why the Future Belongs to the Quants” advocating increased data sharing among security experts. Since then, there’s been a tremendous increase in the amount of quantitative data appearing in publications. And we felt that McAfee should be contributing to this research flow along with better analysis. We want to do more than just report the news – we want to identify trends and deeper causes. We want to bring more science into the field: formulate models and hypotheses and test them.
NW: What are your plans for publication schedule, availability and readership?
Soo Hoo: We plan to post a new issue every six months on the Web; it will be available free to everyone. We’re trying to reach the security audience: executives, security officials, the spectrum of people responsible for security across the enterprise. We are trying to keep the writing clear and simple rather than using a lot of highly technical terms.
NW: Do you plan to have regular sections that will recur from issue to issue?
Soo Hoo: Yes, we expect to include such sections as News and Trends, Opinion / Editorial, features that are thematically related, and then some technical articles that may or may not be exactly in line with the theme of an issue. We don’t want to be too strict, but it makes it easier for people to understand an issue when there are several articles following a theme plus additional materials that are generally related.
NW: Can you characterize the scope of the magazine? What aspects of security are likely to be particularly well represented?
Soo Hoo: Our hope is that we will make good use of our experts, but we don’t want to be limited by that. So if there are trends emerging in which our labs don’t have expertise, we’ll go after it by assigning resources in the labs.
NW: Who will be writing for you? Who will review the submissions? Do you plan to have an editorial board?
Soo Hoo: We expect that eventually we will be able to attract good external writers. I hope that _Sage_ will become a place where good, scholarly and innovative thinking and writing will find a home. Right now, there’s a small group of us in the lab who are pretty senior and have technical expertise who are reviewing the submissions. But as time goes on, we hope that we’ll be getting others involved. We think that it’s our community responsibility as industry leaders to provide this kind of service, and depending on the response of the community, we hope that others will volunteer to become part of our editorial board.
NW: Could you tell the readers about what is most exciting to you about this first issue?
Soo Hoo: It’s how well the whole thing hangs together. It’s great to see how the articles complement each other so well. It’s about open source; it’s about how the social norms, the technology, the tools have been leveraged by the malware-writing community. If you’re into the here-and-now, then you’ll be particularly interested in the “Money Changes Everything” and “Building Better Bots” articles. If you’re interested in history – how we got here – you’ll be keen on reading “Good Intentions Gone Awry.” If you’re highly technical, the paper on “Open-Source Software In Windows Rootkits” will be good for you. If you’re a security executive or an industry consultant, you may be interested in the editorial pieces (“Is Open-Source Really So Open?” and “Vulnerability Bounties”).
Readers can download Sage Magazine as a colorful PDF file free at any time.
Good job, folks!
[Disclaimer from MK: I have no financial or other involvement whatever with McAfee or _Sage_ magazine.]




