Coming of Age: Stressing the importance of threat models.

The article describes the author's experiences in the field of computer security research, noting that many of his colleagues entered the field from a hacking background due to the limited academic resources at the time. He describes the thrill of offensive security research, which focuses on findin...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 66; no. 9; pp. 21 - 24
Autor principal: Zanero, Stefano
Formato: Artículo
Publicado: Association for Computing Machinery Sep2023
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=170382024&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 170382024
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Sep2023
      vid: 66
      iid: 9
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        170382024
        10.1145/3608965
      ppf: 21
      ppct: 3
      formats:
      tig:
        atl: Coming of Age: Stressing the importance of threat models.
      aug:
        au: Zanero, Stefano
        affil: Professor at NECST Laboratory, Politecnico di Milano, Milan, Italy
      su:
        Computer security
        Internet security
        Computer hacking
        Research
        Computer security vulnerabilities
      sug:
        subj:
          Computer security
          Internet security
          Computer hacking
          Research
          Computer security vulnerabilities
      ab: The article describes the author's experiences in the field of computer security research, noting that many of his colleagues entered the field from a hacking background due to the limited academic resources at the time. He describes the thrill of offensive security research, which focuses on finding vulnerabilities and proposing mitigations, and highlights the fact that security evaluations often revolve around resilience to attacks and that offense-driven thinking is central to security defense. However, the author acknowledges that while this mindset is exciting, it falls short in teaching the public to think sensibly about security issues. He emphasizes the use of threat modeling as the key to effective security, since it involves understanding realistic threats and attack surfaces of systems. Despite the fascination with hacking, the author suggests that the cybersecurity community needs to communicate and prioritize defense, address vulnerabilities in context, and collaborate across disciplines to ensure resilient systems and a safer society.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2023
    holdings:
      @attributes:
        islocal: N