论文标题

安全政策审核:为什么以及如何

Security policy audits: why and how

论文作者

Narayanan, Arvind, Lee, Kevin

论文摘要

信息安全不仅与软件和硬件有关 - 至少与政策和流程有关。但是,研究界压倒性地集中在后者的前者上,同时持续的政策和过程问题持续存在。在这篇经验论文中,我们描述了我们进行的一系列安全政策审核,以揭示影响数十亿个用户可能(而且经常)的策略缺陷,而低技术攻击者不需要使用任何工具或利用软件漏洞。反过来,解决方案需要基于政策。我们倡导研究政策和过程,指出其智力和实践挑战,列出我们的变革理论,并提出研究议程。

Information security isn't just about software and hardware -- it's at least as much about policies and processes. But the research community overwhelmingly focuses on the former over the latter, while gaping policy and process problems persist. In this experience paper, we describe a series of security policy audits that we conducted, exposing policy flaws affecting billions of users that can be -- and often are -- exploited by low-tech attackers who don't need to use any tools or exploit software vulnerabilities. The solutions, in turn, need to be policy-based. We advocate for the study of policies and processes, point out its intellectual and practical challenges, lay out our theory of change, and present a research agenda.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源