DocumentCode
2074028
Title
Beyond hacking: an SOS!
Author
Schneider, Fred B.
Author_Institution
Cornell University
Volume
1
fYear
2010
fDate
2-8 May 2010
Firstpage
2
Lastpage
2
Abstract
Cyber-security today is focused largely on defending against known attacks. We learn about the latest attack and find a hack to defend against it. So our defenses improve only after they have been successfully penetrated. This is a recipe to ensure some attackers succeed---not a recipe for achieving system trustworthiness. We must move beyond reacting to yesterday\´s attacks and instead start building systems whose trustworthiness derives from first principles. Yet today we lack the understanding to adopt that proactive approach; it\´s not only a matter of engineering, but we lack a science of security (SOS). The SOS landscape would includes attacks, defense mechanisms, and security properties; the science would characterize how these relate. What security properties can be preserved by a given defense mechanism? What attacks are resisted by a given mechanism? How can enforcement mechanisms be viewed as "trust relocators"? Some challenges are reminiscent of problems that software engineering researchers confront; others resemble problems addressed in the fault-tolerance community. In fact, there are significant technical differences for an SOS, deriving from the very different assumptions about requirements and the environment. This talk will attempt clarify the differences. We will also survey recent and promising avenues toward building a SOS and creating a principled basis for the engineering of trustworthy systems.
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering, 2010 ACM/IEEE 32nd International Conference on
Conference_Location
Cape Town, South Africa
ISSN
0270-5257
Print_ISBN
978-1-60558-719-6
Type
conf
DOI
10.1145/1806799.1806802
Filename
6062066
Link To Document