How to Think About Security Failures.
The article presents information on how human intuition influences the security design of complex systems. Computer engineers build the virtual walls of computing centers thicker and higher, while attackers exercise brilliantly diabolical attacks on weak links, turning systems against themselves in...
| Publicado en: | Communications of the ACM Vol. 49; no. 1; pp. 37 - 40 |
|---|---|
| Autor principal: | |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Jan2006
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=19349564&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 19349564 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Jan2006 vid: 49 iid: 1 pid: 68 pub: Association for Computing Machinery artinfo: ui: 19349564 10.1145/1107458.1107482 ppf: 37 ppct: 3 formats: tig: atl: How to Think About Security Failures. aug: au: Campbell, Scott affil: Computer security analyst, National Energy Research Scientific Computing Center, Lawrence Berkeley National Laboratory, Berkeley, CA. su: Computer security Computer systems Computer hackers Computer hacking Computer users Computer simulation Computer networks Digital communications sug: subj: Computer security Computer systems Computer hackers Computer hacking Computer users Computer simulation Computer networks Digital communications ab: The article presents information on how human intuition influences the security design of complex systems. Computer engineers build the virtual walls of computing centers thicker and higher, while attackers exercise brilliantly diabolical attacks on weak links, turning systems against themselves in an arms race that has gone on for as long as computers have communicated through networks. A new class of attack--the client-side attack--has emerged increasingly popular and dangerous. With the rise of this client-side attacks, a flaw emerges in the old model, despite avoiding a direct connection to the outside, users might still be attacked by the very services they have requested. A new attack vector has been designed in which users are transformed into a protected interior of the network. Securing a system enforces pressure on attackers, forcing changes in their formerly successful behavior and previously unexplored attack patterns to take advantage of still unprotected resources. Security designs must recognize that the enhancements are the driving force behind new intrusion techniques. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2006 holdings: @attributes: islocal: N |
|---|