Risks of monoculture

Risks of monoculture
复制标题

DOI:
10.1145/971617.971650
复制
发表时间:
2004-03
期刊:
Commun. ACM
影响因子:
--
通讯作者:
M. Stamp
M. Stamp
中科院分区:
其他
文献类型:
--
作者:
M. Stamp

文献摘要

被引文献

相似文献

2003年8月,W32/Blaster蠕虫病毒突然出现在互联网上。通过利用Windows中的缓冲区溢出,该蠕虫能够在不到一个月的时间内感染全球140多万个系统。操作系统市场的多样性将限制易受感染系统的数量,从而降低感染水平。与生物系统的类比是不可抗拒的。当疾病袭击生物系统时,很大比例的受影响人口将存活下来,这主要是由于其遗传多样性。这对于以前未知的疾病也是如此。以此类推,多样化的计算系统应该比倾向于单一文化的系统更好地抵御网络攻击。但是这个类比有多正确呢?可以说,计算多样性的理由甚至比生物多样性的理由更充分。在生物系统中,攻击者随机找到目标,而在计算系统中,单一文化创造了更多的攻击动机,因为结果将更加壮观。另一方面,有人可能会说,网络单一文化是通过自然选择出现的,拥有最好的安全产品的供应商生存下来,主宰了市场。考虑到当今计算机安全的惨淡状况,这一论点并不特别有说服力。尽管网络多样性显然提供了安全方面的好处,但为什么我们生活在一个相对单一的计算文化时代?首先进入市场的优势和对流行产品的现成支持是不利于多样性的激励措施的例子。最终的结果是一个“(安全)公地悲剧”的现象-互联网的安全作为一个整体可以受益于增加多样性,但个人有单一文化的动机。目前还不清楚旨在提高计算安全的提案会如何影响网络多样性。例如,增加软件供应商的赔偿责任往往被认为是一种面向市场的办法,以提高安全性。然而,这种方法可能有利于那些口袋最深的人,导致多样性减少。虽然网络多样性是好的,但更多的多样性更好吗?特别是病毒编写者利用了多样性的优势;多态病毒目前很流行。这种病毒通常使用弱密码加密,每次病毒传播时使用新的密钥,从而混淆基于签名的检测。然而,由于解密例程不能被加密,所以检测仍然是可能的。病毒编写者即将释放所谓的变形病毒,即病毒本身在每次传播时都会发生变化。…
T he W32/Blaster worm burst onto the Internet scene in August of 2003. By exploiting a buffer overflow in Windows, the worm was able to infect more than 1.4 million systems worldwide in less than a month. More diversity in the OS market would have limited the number of susceptible systems, thereby reducing the level of infection. An analogy with biological systems is irresistible. When a disease strikes a biological system, a significant percentage of the affected population will survive, largely due to its genetic diversity. This holds true even for previously unknown diseases. By analogy , diverse computing systems should weather cyber attacks better than systems that tend toward mono-culture. But how valid is the analogy? It could be argued that the case for computing diversity is even stronger than the case for biological diversity. In biological systems, attackers find their targets at random, while in computing systems, monoculture creates more incentive for attack because the results will be all the more spectacular. On the other hand, it might be argued that cyber-monoculture has arisen via natural selection—providers with the best security products have survived to dominate the market. Given the dismal state of computer security today, this argument is not particularly persuasive. Although cyber-diversity evidently provides security benefits, why do we live in an era of relative computing monoculture? The first-to-market advantage and the ready availability of support for popular products are examples of incentives that work against diversity. The net result is a " tragedy of the (security) commons " phenomenon—the security of the Internet as a whole could benefit from increased diversity, but individuals have incentives for monoculture. It is unclear how proposals aimed at improving computing security might affect cyber-diversity. For example , increased liability for software providers is often suggested as a market-oriented approach to improved security. However, such an approach might favor those with the deepest pockets, leading to less diversity. Although some cyber-diversity is good, is more diversity better? Virus writers in particular have used diversity to their advantage; polymorphic viruses are currently in vogue. Such viruses are generally encrypted with a weak cipher, using a new key each time the virus propagates, thus confounding signature-based detection. However, because the decryption routine cannot be encrypted, detection is still possible. Virus writers are on the verge of unleashing so-called metamorphic viruses, where the body of the virus itself changes each time it propagates. …