In Defence of the Human Factor

In Defence of the Human Factor
复制标题

捍卫人为因素

DOI:
10.3389/fpsyg.2020.01390
复制
发表时间:
2020
影响因子:
3.8
通讯作者:
C. Mc Mahon
C. Mc Mahon
中科院分区:
心理学3区
文献类型:
--
作者:
C. Mc Mahon

文献摘要

被引文献

相似文献

长期以来,在网络安全领域占据主导地位的一个说法是“人类是最薄弱的环节”。虽然它的知识起源比这个行业早了几十年,如果不是几个世纪的话,但就我们目前的目的而言,我们只需要追溯到本世纪初。它似乎始于Schneier(2000),并延续到Mitnick和Simon(2002)。从那以后,网络安全讨论就充斥着这种陈词滥调。Schneier(2000)在他的书中讨论了完美计算机安全的概念。想象一台完美无瑕的计算机,拥有强大的加密技术和安全协议。即使这很困难,假设它是可操作的。不幸的是,它并不安全,因为它迟早要与用户交互,而“这种交互是所有交互中最大的风险。人往往是安全链中最薄弱的一环,长期对安全系统的失败负责”(Schneier, 2000, p. 149)。虽然米特尼克和西蒙(2002)以不同的语气开始,但他的观点本质上是相同的。谈到家庭安全,以及人们如何安装锁以获得安全感,他说,无论安装什么,家庭本质上仍然是脆弱的,因为“人为因素是真正安全的最薄弱环节。”Schneier和Mitnicks的影响是如此之大,以至于这个短语在信息安全圈中发展了重要的货币,尽管它在物理安全话语中可能已经是一个常见的比喻。“人的因素是网络安全中最薄弱的一环”已经成为一种终结思想的陈词滥调,它的持续流行正在制约着这一领域的智力发展。它应该作为一个紧迫的问题而退出。但目前,网络安全完全沉浸在这一理念中。它在安全意识博客(Spitzner, 2012)、It行业出版物(Rossi, 2015; Wright, 2016)、媒体(Vishwanath, 2016),甚至牛津大学出版社的专著(Singer和Friedman, 2014)中都有突出的特点。最近,在爱尔兰政府赞助的活动中,一个下午的小组题为“网络安全:捍卫最薄弱的环节”(都柏林数字峰会,2019)。因此,这种对人性的负面描述丝毫没有减弱的迹象。值得注意的是,一些学者从一开始就反对(例如,Sasse et al., 2001),但这些声音很少。相比之下,大量的文献明确主张它:在机场(Schwaninger, 2006)和移动安全(Lau, 2017)的背景下;系统评价(Mahfuth et al., 2017)、网络心理学(Wiederhold, 2014)、社交网络(Lehrman, 2010)等等。这些引用只是那些公开提到这句话的引用:对文献的更详细的阅读几乎肯定会揭示“人为因素是网络安全中最薄弱的环节”,这是信息安全科学当前范式所基于的前提之一(库恩,1962)。
A trope that has long dominated cybersecurity is the idea that “humans are the weakest link.”While its intellectual origins predate the industry by several decades, if not centuries, for our present purposes we need go back no further than the beginning of this millennium. It seems to have started with Schneier (2000), and continued with Mitnick and Simon (2002). Since then, cybersecurity discourse has been awash with this cliché. In his book, Schneier (2000) discusses the idea of perfect computer security. Imagine a flawless computer, with strong cryptography and secure protocols. Even though it would be difficult, suppose it is operational. Unfortunately, it isn’t secure, because sooner or later it will have to interact with a user, and “this interaction is the biggest risk of them all. People often represent the weakest link in the security chain and are chronically responsible for the failure of security systems” (Schneier, 2000, p. 149). And while Mitnick and Simon (2002) begins in a different tone, his point is essentially the same. Talking about home security, and how people install locks in order to feel safe, he says no matter what is put in place, the home remains essentially vulnerable, because “the human factor is truly security’s weakest link.” Schneier’s and Mitnicks’ influences are such that this phrase developed significant currency in information security circles, though it was likely an already common trope in physical security discourse. “The human factor is the weakest link in cybersecurity” has acquired the status of a thoughtterminating cliché, and its continued popularity is restraining the intellectual development of this field. It should be retired as an immediate concern. But at present, cybersecurity is utterly soaked in this idea. It features prominently in security awareness blogs (Spitzner, 2012), IT industry publications (Rossi, 2015; Wright, 2016), media outlets (Vishwanath, 2016), and even Oxford University Press monographs (Singer and Friedman, 2014). Recently, at a government-sponsored event in Ireland, an afternoon panel was titled “Cybersecurity: Defending the weakest link” (Dublin Digital Summit, 2019). As such, this negative characterisation of human nature shows no sign of waning. Notably, some scholars pushed back from the very outset (e.g., Sasse et al., 2001) but these voices have been rare. In contrast, a vast amount of literature explicitly advocated for it: in the context of airport (Schwaninger, 2006) and mobile security (Lau, 2017); systematic reviews (Mahfuth et al., 2017), cyberpsychology (Wiederhold, 2014), social networking (Lehrman, 2010)— and many more. These citations are only those which mention the phrase overtly: a more detailed reading of the literature would almost certainly expose the “human factor is the weakest link in cybersecurity” as one of the premises on which information security science’s current paradigm is based (Kuhn, 1962).