Thou Shalt Discuss Security: Quantifying the Impacts of Instructions to RFC Authors

Thou Shalt Discuss Security: Quantifying the Impacts of Instructions to RFC Authors
复制标题

DOI:
10.1145/3338500.3360332
复制
发表时间:
2019-11
期刊:
Proceedings of the 5th ACM Workshop on Security Standardisation Research Workshop
影响因子:
--
通讯作者:
J. Whitaker;S. Prasad;Bradley Reaves;W. Enck
J. Whitaker;S. Prasad;Bradley Reaves;W. Enck
中科院分区:
其他
文献类型:
--
作者:
J. Whitaker;S. Prasad;Bradley Reaves;W. Enck

文献摘要

相似文献

安全开发新技术的重要性是毋庸置疑的,但实现这一目标的最佳方法还远未确定。一个关键的问题是,虽然在评估开发结果(例如,给定项目的安全性)上付出了大量的努力,但要确定哪些组织实践会产生安全的项目却要困难得多。在本文中,我们通过向RFC作者发布的命令和指导方针,定量地检查了在评论请求(RFC) (Internet和许多相关系统的设计文档)中改进安全性考虑的努力。我们首先确定用于量化安全信息内容的数量和质量的六个度量。然后,我们将这些指标纵向应用于8,437个文档和49年的开发中,以确定RFC作者的指南是否在后来的文档中更改了这些安全指标。我们发现,即使是一个简单的措辞——但有效地执行——明确地考虑安全性的命令,也会在强制的安全性考虑部分内外增加安全性内容的讨论和主题覆盖方面产生重大影响。我们发现,后来的指南在安全性方面提供了更详细的建议,也提高了rfc中安全性信息内容的数量和质量。我们的工作表明,即使是少量的指导也可以与rfc中安全重点的重大改进相关联,这为其他网络标准组织指明了一种有前途的方法。
The importance of secure development of new technologies is unquestioned, yet the best methods to achieve this goal are far from certain. A key issue is that while significant effort is given to evaluating the outcomes of development (e.g., security of a given project), it is far more difficult to determine what organizational practices result in secure projects. In this paper, we quantitatively examine efforts to improve the consideration of security in Requests for Comments (RFCs)--- the design documents for the Internet and many related systems --- through the mandates and guidelines issued to RFC authors. We begin by identifying six metrics that quantify the quantity and quality of security informative content. We then apply these metrics longitudinally over 8,437 documents and 49 years of development to determine whether guidance to RFC authors changed these security metrics in later documents. We find that even a simply worded --- but effectively enforced --- mandate to explicitly consider security created a significant effect in increased discussion and topic coverage of security content both in and outside of a mandated security considerations section. We find that later guidelines with more detailed advice on security also improve both volume and quality of security informative content in RFCs. Our work demonstrates that even modest amounts of guidance can correlate to significant improvements in security focus in RFCs, indicating a promising approach for other network standards bodies.