DigiNotar: Dissecting the First Dutch Digital Disaster

DigiNotar: Dissecting the First Dutch Digital Disaster
复制标题

DigiNotar:剖析荷兰第一场数字灾难

DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
N. D. Meulen
N. D. Meulen
中科院分区:
--
文献类型:
--
作者:
N. D. Meulen

文献摘要

被引文献

相似文献

2011年9月2日午夜,荷兰内政和王国关系部部长召开紧急新闻发布会。DigiNotar,一个证书颁发机构(CA),被电子“闯入”,结果入侵者设法生成了伪造的证书。作为CA, DigiNotar颁发数字证书以确保数字通信的安全,但由于该漏洞,无法再验证此类证书的真实性。荷兰政府随后撤销了对DigiNotar发行的所有证书的信任。这是荷兰第一次数字灾难的开始。作为一个开创性的灾难,本文将重点介绍DigiNotar作为未来数字灾难管理场景的重要案例研究的影响。本文的主要焦点是DigiNotar事件的潜在“弱点”,这使得情况从一个问题演变成一场灾难。这些问题包括缺乏监督、缺乏安全注意和风险意识以及缺乏有效的缓解战略。通过识别并随后分析潜在的问题,本文旨在展示如果对这些因素给予足够的关注并引入随后的变化,如何更好地控制未来的情况。本文发表于《战略安全杂志》:http://scholarcommons.usf.edu/jss/vol6/iss2/4
In the middle of the night on September 2, 2011, the Dutch Minister of the Interior and Kingdom Relations held an emergency press conference. DigiNotar, a Certificate Authority (CA), had been electronically ‘broken into’ and as a result intruders had managed to generate falsified certificates. As a CA, DigiNotar issued digital certificates to secure digital communication, but as a result of the breach the authenticity of such certificates could no longer be verified. The Dutch government subsequently revoked its trust in all certificates issued by DigiNotar. This was the beginning of the first digital disaster in the Netherlands. As a pioneering disaster, this article focuses on the implications of DigiNotar as a vital case study for future scenarios of digital disaster management. The main focus of this article is on the underlying ‘weaknesses’ of the DigiNotar incident, which allowed the situation to evolve from a problem into a disaster. These include lack of oversight, lack of security attention and risk awareness and the absence of an effective mitigation strategy. By identifying and subsequently analyzing the underlying problems, this article aims to demonstrate how future situations can be better contained if sufficient attention is granted to these factors and subsequent changes are introduced. This article is available in Journal of Strategic Security: http://scholarcommons.usf.edu/jss/vol6/iss2/4