How to Think About Security Failures.

The article presents information on how human intuition influences the security design of complex systems. Computer engineers build the virtual walls of computing centers thicker and higher, while attackers exercise brilliantly diabolical attacks on weak links, turning systems against themselves in...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 49; no. 1; pp. 37 - 40
Autor principal: Campbell, Scott
Formato: Artículo
Publicado: Association for Computing Machinery Jan2006
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=19349564&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 19349564
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Jan2006
      vid: 49
      iid: 1
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        19349564
        10.1145/1107458.1107482
      ppf: 37
      ppct: 3
      formats:
      tig:
        atl: How to Think About Security Failures.
      aug:
        au: Campbell, Scott
        affil: Computer security analyst, National Energy Research Scientific Computing Center, Lawrence Berkeley National Laboratory, Berkeley, CA.
      su:
        Computer security
        Computer systems
        Computer hackers
        Computer hacking
        Computer users
        Computer simulation
        Computer networks
        Digital communications
      sug:
        subj:
          Computer security
          Computer systems
          Computer hackers
          Computer hacking
          Computer users
          Computer simulation
          Computer networks
          Digital communications
      ab: The article presents information on how human intuition influences the security design of complex systems. Computer engineers build the virtual walls of computing centers thicker and higher, while attackers exercise brilliantly diabolical attacks on weak links, turning systems against themselves in an arms race that has gone on for as long as computers have communicated through networks. A new class of attack--the client-side attack--has emerged increasingly popular and dangerous. With the rise of this client-side attacks, a flaw emerges in the old model, despite avoiding a direct connection to the outside, users might still be attacked by the very services they have requested. A new attack vector has been designed in which users are transformed into a protected interior of the network. Securing a system enforces pressure on attackers, forcing changes in their formerly successful behavior and previously unexplored attack patterns to take advantage of still unprotected resources. Security designs must recognize that the enhancements are the driving force behind new intrusion techniques.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2006
    holdings:
      @attributes:
        islocal: N