"We make it a big deal in the company": Security Mindsets in Organizations that Develop Cryptographic Products

"We make it a big deal in the company": Security Mindsets in Organizations that Develop Cryptographic Products
复制标题

“我们在公司里把它当作一件大事”:开发加密产品的组织中的安全心态

DOI:
--
复制
发表时间:
2018
期刊:
SOUPS @ USENIX Security Symposium
影响因子:
--
通讯作者:
E. Truswell
E. Truswell
中科院分区:
--
文献类型:
--
作者:
M. Macphail;A. Partridge;E. Truswell

文献摘要

被引文献

相似文献

密码学是现代计算的重要组成部分。不幸的是,正确实现密码学是一项不平凡的任务。过去的研究通过揭示软件产品的加密实现中的大量错误和开发人员陷阱来支持这一观察结果。然而,这些研究的重点是个人开发人员;在更彻底地理解组织的加密开发实践方面存在明显的差距。为了解决这一差距,我们对21位经验丰富的个人进行了深入采访,这些人代表了在其产品中包含加密技术的组织。我们的研究结果表明,在其他研究结果中看不到安全思维,这体现在强大的组织安全文化和执行加密开发的人员的深厚专业知识上。反过来,这种心态指导了加密资源的仔细选择,并为正式、严格的开发和测试实践提供了信息。对组织实践的进一步理解鼓励了更多的研究举措,以探索实施密码学的组织的变化,这有助于通过教育机会,工具和其他机制将安全成熟组织的经验教训转移到更广泛的开发社区。研究结果还支持了过去的研究,即加密资源的可用性可能存在缺陷,并提供了额外的建议,使这些资源更容易被不同技能水平的开发人员访问和使用。
Cryptography is an essential component of modern computing. Unfortunately, implementing cryptography correctly is a non-trivial undertaking. Past studies have supported this observation by revealing a multitude of errors and developer pitfalls in the cryptographic implementations of software products. However, the emphasis of these studies was on individual developers; there is an obvious gap in more thoroughly understanding cryptographic development practices of organizations. To address this gap, we conducted 21 in-depth interviews of highly experienced individuals representing organizations that include cryptography in their products. Our findings suggest a security mindset not seen in other research results, demonstrated by strong organizational security culture and the deep expertise of those performing cryptographic development. This mindset, in turn, guides the careful selection of cryptographic resources and informs formal, rigorous development and testing practices. The enhanced understanding of organizational practices encourages additional research initiatives to explore variations in those implementing cryptography, which can aid in transferring lessons learned from more security-mature organizations to the broader development community through educational opportunities, tools, and other mechanisms. The findings also support past studies that suggest that the usability of cryptographic resources may be deficient, and provide additional suggestions for making these resources more accessible and usable to developers of varying skill levels.