Xconomy Q&A: Security Sleuth Stefan Savage Wins MacArthur Grant

Stefan Savage (UC San Diego photo by Alex Matthews used with permission)

After winning a MacArthur “genius” grant late Tuesday, the San Diego cybersecurity sleuth Stefan Savage acknowledged the honor “definitely triggers my imposter syndrome.”

Savage, a computer scientist at UC San Diego (and a San Diego Xconomist), added in an e-mail Wednesday, “It’s very nice to see all the work that I and my collaborators and students have done together be recognized this way.”

In response to questions from Xconomy, Savage wrote that his $625,000 MacArthur grant, to be paid quarterly over the next five years, would enable him to focus his future research on using evidence-based techniques for assessing cybersecurity.

Savage, a 48-year-old expert in computer security, was among 24 people selected Tuesday for the 2017 class of MacArthur Fellows, an honor that includes a “no-strings-attached” grant of $625,000 for each recipient from the Chicago-based James D. and Catherine T. MacArthur Foundation. The foundation says it picked Savage for “Identifying and addressing the technological, economic, and social vulnerabilities underlying Internet security challenges and cybercrime.”

Launched in 1981, the fellowship program is limited to U.S. citizens and is awarded annually to 20 to 30 individuals working in any field, and includes artists, scientists, journalists, social workers, poets, and quantum astrophysicists. It is broadly based on three criteria:

—Exceptional creativity.

—A promise for important future advances based on a track record of significant accomplishments.

—The potential for a MacArthur grant to facilitate additional creative work.­­

Previous MacArthur fellows include “Hamilton” creator and star Lin-Manuel Miranda, the physicist and energy analyst Amory Lovins, author Ta-Nehisi Coates, and Internet pioneer Timothy Berners-Lee. MacArthur alumni in San Diego include the organic chemist Phil Baran of The Scripps Research Institute and the planetary geologist Michael Malin, founder of Malin Space Science Systems.

According to the foundation, Savage helped to create new strategies for defending computer networks against malware and so-called “distributed denial of service” attacks. He and his colleagues also were the first to demonstrate how to remotely hack an automobile—and take control over the engine and brakes, and to monitor conversations taking place within the car. More recently, Savage and his collaborators analyzed network-level interactions to identify ways that online credit card transactions used by Internet crime rings to sell counterfeit drugs could be disrupted.

Asked what he plans to do next , Savage wrote in an e-mail to Xconomy: “Right now we’re focused on what we call ‘evidence-based security’… the notion that you should be able to measure how different defenses/behaviors impact security outcomes (in the same way that we look at the relationship between treatments and health outcomes in evidence-based medicine). Right now, most security decisions are driven by best-practice compliance, which is some combination of received wisdom and gut instinct… We’d like to make those decisions data-driven instead.”

Savage also provided some quick answers to a few other questions:

Xconomy: How should people think about cybersecurity in light of major computer attacks such as the Equifax data breach?

Stefan Savage: I’m not sure how to answer. I think it is quite evident that we are not doing a great job at

Author: Bruce V. Bigelow

In Memoriam: Our dear friend Bruce V. Bigelow passed away on June 29, 2018. He was the editor of Xconomy San Diego from 2008 to 2018. Read more about his life and work here. Bruce Bigelow joined Xconomy from the business desk of the San Diego Union-Tribune. He was a member of the team of reporters who were awarded the 2006 Pulitzer Prize in National Reporting for uncovering bribes paid to San Diego Republican Rep. Randy “Duke” Cunningham in exchange for special legislation earmarks. He also shared a 2006 award for enterprise reporting from the Society of Business Editors and Writers for “In Harm’s Way,” an article about the extraordinary casualty rate among employees working in Iraq for San Diego’s Titan Corp. He has written extensively about the 2002 corporate accounting scandal at software goliath Peregrine Systems. He also was a Gerald Loeb Award finalist and National Headline Award winner for “The Toymaker,” a 14-part chronicle of a San Diego start-up company. He takes special satisfaction, though, that the series was included in the library for nonfiction narrative journalism at the Nieman Foundation for Journalism at Harvard University. Bigelow graduated from U.C. Berkeley in 1977 with a degree in English Literature and from the Columbia University Graduate School of Journalism in 1979. Before joining the Union-Tribune in 1990, he worked for the Associated Press in Los Angeles and The Kansas City Times.