Attacking the Washington, D.C. Internet Voting System

Attacking the Washington, D.C. Internet Voting System
复制标题

攻击华盛顿特区互联网投票系统

DOI:
10.1007/978-3-642-32946-3_10
复制
发表时间:
2012
期刊:
ArXiv
影响因子:
--
通讯作者:
J. A. Halderman
J. A. Halderman
中科院分区:
--
文献类型:
--
作者:
Scott Wolchok;Eric Wustrow;Dawn Isabel;J. A. Halderman

文献摘要

被引文献

相似文献

2010年,华盛顿,华盛顿特区开发了一个互联网投票试点项目,旨在允许海外缺席选民使用网站投票。在大选中部署该系统之前,该地区举行了一次独特的公开试验:一次模拟选举,任何人都被邀请测试该系统或试图破坏其安全性。本文介绍了我们参与这项试验的经验。在系统上线后48小时内,我们几乎完全控制了选举服务器。我们成功地改变了每一张选票,并公布了几乎每一张无记名投票。在将近两个工作日的时间里,选举官员们都没有发现我们的入侵,如果我们没有故意留下一个明显的线索,他们可能会在更长的时间里都没有发现。这种情况下,研究第一(据我们所知),以分析政府互联网投票系统的安全性,从攻击者的角度在一个现实的选举前部署,试图照亮的实际挑战,确保在线投票的实践,今天越来越多的司法管辖区。
In 2010, Washington, D.C. developed an Internet voting pilot project that was intended to allow overseas absentee voters to cast their ballots using a website. Prior to deploying the system in the general election, the District held a unique public trial: a mock election during which anyone was invited to test the system or attempt to compromise its security. This paper describes our experience participating in this trial. Within 48 hours of the system going live, we had gained near- complete control of the election server. We successfully changed every vote and revealed almost every secret ballot. Election ocials did not detect our intrusion for nearly two business days—and might have remained unaware for far longer had we not deliberately left a prominent clue. This case study—the first (to our knowledge) to analyze the security of a government Internet voting system from the perspective of an attacker in a realistic pre-election deployment—attempts to illuminate the practical challenges of securing online voting as practiced today by a growing number of jurisdictions.