Security automation considered harmful?

Security automation considered harmful?
复制标题

安全自动化被认为有害吗?

DOI:
10.1145/1600176.1600182
复制
发表时间:
2008
期刊:
Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security
影响因子:
--
通讯作者:
Jennifer Stoll
Jennifer Stoll
中科院分区:
--
文献类型:
--
作者:
W. Keith;Edwards Erika;Shehan Poole;Jennifer Stoll

文献摘要

被引文献

相似文献

终端用户通常被认为是信息安全中最薄弱的环节。由于这种看法,越来越多的研究和商业活动集中在自动化的安全方法上。通过这些方法,安全决策不再由用户决定,而是由系统本身、远程服务或建立自动执行策略的组织决定。我们认为,尽管安全自动化在理论上可能是有益的,但在实践中,它并不是最终用户信息安全的灵丹妙药。在许多情况下,许多技术和社会因素削弱了自动化终端用户安全解决方案的接受度和有效性。在本文中,我们讨论了为最终用户自动化安全性的固有限制。然后,我们讨论了一组设计准则,用于选择是否将最终用户安全系统自动化。我们总结了一系列研究方向,重点是提高最终用户对安全解决方案的接受度和有效性。
End-users are often perceived as the weakest link in information security. Because of this perception, a growing body of research and commercial activity is focused on automated approaches to security. With these approaches, security decisions are removed from the hands of the users, and are placed instead in systems themselves, or in remote services or organizations that establish policies that are automatically enforced. We contend that although security automation is potentially beneficial in theory, in practice it is not a panacea for end-user information security. A number of technical and social factors mitigate against the acceptance and efficacy of automated end-user security solutions in many cases. In this paper, we present a discussion of the inherent limitations of automating security for end-users. We then discuss a set of design guidelines for choosing whether to automate end-user security systems. We conclude with a set of research directions focused on increasing the acceptance and efficacy of security solutions for end-users.