Trust-Based Security; Or, Trust Considered Harmful

Trust-Based Security; Or, Trust Considered Harmful
复制标题

基于信任的安全;

DOI:
10.1145/3442167.3442179
复制
发表时间:
2020
期刊:
Proceedings of the 2020 New Security Paradigms Workshop
影响因子:
--
通讯作者:
Bishop, Matt
Bishop, Matt
中科院分区:
--
文献类型:
--
作者:
Singer, Abe;Bishop, Matt

文献摘要

参考文献

被引文献

相似文献

我们对常见的、流行的风险分析框架的回顾发现,它们在方法上是非常相似的。这些被认为是IT安全行业的“最佳实践”。然而,人们怀疑它们是否真的是“最好的”,就像几乎每天都有大公司遭受重大妥协的新闻所证明的那样。在这些“最佳实践”中嵌入的概念是“信任”是“好的”,即是一个理想的特性:“可信计算”、“可信第三方”等。我们的观点恰恰相反:脆弱性源于信任关系。我们提出了一个以识别和最小化信任关系为中心的风险分析范式。我们认为,通过将信任关系置于前台,我们可以确定妥协的路径,否则这些路径不会被发现;更全面的脆弱性评估,从中可以更好地确定优先级并减少风险。
Our review of common, popular risk analysis frameworks finds that they are very homogenous in their approach. These are considered IT Security Industry ”best practices.” However, one wonders if they are indeed ”best”, as evinced by the almost daily news of large companies suffering major compromises.Embedded in these ”best practices” is the notion that ”trust” is ”good”, i.e. is a desirable feature: ”trusted computing,” ”trusted third party,” etc. We argue for the opposite: that vulnerabilities stem from trust relationships. We propose a a paradigm for risk analysis centered around identifying and minimizing trust relationships.We argue that by bringing trust relationships to the foreground, we can identify paths to compromise that would otherwise go undetected; a more comprehensive assessment of vulnerability, from which one can better prioritize and reduce risk.
对最近一些广泛的计算机入侵事件的思考
DOI: --
发表时间: 1991
期刊:
影响因子: --
作者:
B. Reid
通讯作者: B. Reid
加里·辛格
DOI: --
发表时间: 2019
期刊: Authors group
影响因子: --
作者:
Gary Singer
通讯作者: Gary Singer
DOI: --
发表时间: 2008
期刊: Financial Cryptography
影响因子: --
作者:
Ken L. Huang;P. Douthit
通讯作者: P. Douthit
人际信任在团体流程中的中心地位
DOI: --
发表时间: 1975
期刊:
影响因子: --
作者:
R. Golembiewski;M. Mcconkie
通讯作者: M. Mcconkie
破坏目标:目标数据泄露分析及经验教训
DOI: --
发表时间: 2017
期刊: arXiv.org
影响因子: --
作者:
Xiaokui Shu;K. Tian;Andrew Ciambrone;D. Yao
通讯作者: D. Yao