Trust-Based Security; Or, Trust Considered Harmful
Trust-Based Security; Or, Trust Considered Harmful
复制标题
基于信任的安全;
DOI:
10.1145/3442167.3442179
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Bishop, Matt
中科院分区:
文献类型:
--
作者:
Singer, Abe;Bishop, Matt
Our review of common, popular risk analysis frameworks finds that they are very homogenous in their approach. These are considered IT Security Industry ”best practices.” However, one wonders if they are indeed ”best”, as evinced by the almost daily news of large companies suffering major compromises.Embedded in these ”best practices” is the notion that ”trust” is ”good”, i.e. is a desirable feature: ”trusted computing,” ”trusted third party,” etc. We argue for the opposite: that vulnerabilities stem from trust relationships. We propose a a paradigm for risk analysis centered around identifying and minimizing trust relationships.We argue that by bringing trust relationships to the foreground, we can identify paths to compromise that would otherwise go undetected; a more comprehensive assessment of vulnerability, from which one can better prioritize and reduce risk.
登录
查看更多内容
DOI:
--
发表时间:
1991
期刊:
影响因子:
--
作者:
B. Reid
通讯作者:
B. Reid
DOI:
--
发表时间:
2019
期刊:
Authors group
影响因子:
--
作者:
Gary Singer
通讯作者:
Gary Singer
DOI:
--
发表时间:
2008
期刊:
Financial Cryptography
影响因子:
--
作者:
Ken L. Huang;P. Douthit
通讯作者:
P. Douthit
DOI:
--
发表时间:
1975
期刊:
影响因子:
--
作者:
R. Golembiewski;M. Mcconkie
通讯作者:
M. Mcconkie
DOI:
--
发表时间:
2017
期刊:
arXiv.org
影响因子:
--
作者:
Xiaokui Shu;K. Tian;Andrew Ciambrone;D. Yao
通讯作者:
D. Yao