Investigating System Operators' Perspective on Security Misconfigurations

Investigating System Operators' Perspective on Security Misconfigurations
复制标题

调查系统操作员对安全配置错误的看法

DOI:
10.1145/3243734.3243794
复制
发表时间:
2018
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
T. Fiebig
T. Fiebig
中科院分区:
--
文献类型:
--
作者:
Constanze Dietrich;Katharina Krombholz;Kevin Borgolte;T. Fiebig

文献摘要

参考文献

被引文献

相似文献

如今,安全事件已成为一个熟悉的“滋扰”,它们会定期导致私人和敏感数据的暴露。此类事件的根本原因很少是复杂的攻击。取而代之的是,它们是通过简单的错误配置来启用的,例如不需要身份验证或未安装安全更新。例如,最近历史上最严重的错误调查中,超过1.4亿美国人从Equifax的系统中泄漏了:长期以来已经知道了潜在的脆弱性,并且已有数月的安全补丁,但从未应用。最终,Equifax指责一名员工忘记更新受影响的系统,强调他的个人责任。在本文中,我们调查了操作员对安全性错误的看法,以了解这类安全问题的人类组成部分。我们将分析重点放在系统操作员上,他们没有受到先前研究的重大关注。因此,我们通过归纳方法调查了他们的观点,并采用了多步经验方法:(i),一项定性研究,以了解如何接近目标群体并测量错误配置现象(II)的定量调查,该定量调查植根于定性数据中。然后,我们对系统运营商对安全性错误配置的看法进行了首次分析,并确定了操作员认为是根本原因的因素。根据我们的发现,我们提供了有关如何减少安全性错误配置频率和影响的实用建议。
Nowadays, security incidents have become a familiar "nuisance," and they regularly lead to the exposure of private and sensitive data. The root causes for such incidents are rarely complex attacks. Instead, they are enabled by simple misconfigurations, such as authentication not being required, or security updates not being installed. For example, the leak of over 140 million Americans' private data from Equifax's systems is among most severe misconfigurations in recent history: The underlying vulnerability was long known, and a security patch had been available for months, but was never applied. Ultimately, Equifax blamed an employee for forgetting to update the affected system, highlighting his personal responsibility. In this paper, we investigate the operators' perspective on security misconfigurations to approach the human component of this class of security issues. We focus our analysis on system operators, who have not received significant attention by prior research. Hence, we investigate their perspective with an inductive approach and apply a multi-step empirical methodology: (i), a qualitative study to understand how to approach the target group and measure the misconfiguration phenomenon (ii) a quantitative survey rooted in the qualitative data. We then provide the first analysis of system operators' perspective on security misconfigurations, and we determine the factors that operators perceive as the root causes. Based on our findings, we provide practical recommendations on how to reduce security misconfigurations' frequency and impact.
MineSweeper:深入研究路过式加密货币挖矿及其防御
DOI: 10.1145/3243734.3243858
发表时间: 2018
期刊: 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Konoth, Radhesh Krishnan;Vineti, Emanuele;Moonsamy, Veelasha;Lindorfer, Martina;Kruegel, Christopher;Bos, Herbert;Vigna, Giovanni
通讯作者: Vigna, Giovanni
DOI: 10.1109/sp.2018.00027
发表时间: 2018-05
期刊: 2018 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者:
Kevin Borgolte;S. Hao;T. Fiebig;Giovanni Vigna
通讯作者: Kevin Borgolte;S. Hao;T. Fiebig;Giovanni Vigna
Cloud Strife:降低域验证证书的安全风险
DOI: 10.14722/ndss.2018.23327
发表时间: 2018
期刊: Internet Society Symposium on Network and Distributed System Security (NDSS
影响因子: --
作者:
Borgolte, Kevin;Fiebig, Tobias;Hao, Shuang;Kruegel, Christopher;Vigna, Giovanni
通讯作者: Vigna, Giovanni