• DocumentCode
    2074028
  • Title

    Beyond hacking: an SOS!

  • Author

    Schneider, Fred B.

  • Author_Institution
    Cornell University
  • Volume
    1
  • fYear
    2010
  • fDate
    2-8 May 2010
  • Firstpage
    2
  • Lastpage
    2
  • Abstract
    Cyber-security today is focused largely on defending against known attacks. We learn about the latest attack and find a hack to defend against it. So our defenses improve only after they have been successfully penetrated. This is a recipe to ensure some attackers succeed---not a recipe for achieving system trustworthiness. We must move beyond reacting to yesterday\´s attacks and instead start building systems whose trustworthiness derives from first principles. Yet today we lack the understanding to adopt that proactive approach; it\´s not only a matter of engineering, but we lack a science of security (SOS). The SOS landscape would includes attacks, defense mechanisms, and security properties; the science would characterize how these relate. What security properties can be preserved by a given defense mechanism? What attacks are resisted by a given mechanism? How can enforcement mechanisms be viewed as "trust relocators"? Some challenges are reminiscent of problems that software engineering researchers confront; others resemble problems addressed in the fault-tolerance community. In fact, there are significant technical differences for an SOS, deriving from the very different assumptions about requirements and the environment. This talk will attempt clarify the differences. We will also survey recent and promising avenues toward building a SOS and creating a principled basis for the engineering of trustworthy systems.
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering, 2010 ACM/IEEE 32nd International Conference on
  • Conference_Location
    Cape Town, South Africa
  • ISSN
    0270-5257
  • Print_ISBN
    978-1-60558-719-6
  • Type

    conf

  • DOI
    10.1145/1806799.1806802
  • Filename
    6062066