资源描述:
《towards better definitions and measures of internet security》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、TowardsBetterDenitionsandMeasuresofInternetSecurity(PositionPaper)J.AspnesandJ.FeigenbaumM.MitzenmacherandD.ParkesYaleUniversityHarvardUniversityfaspnes,feigenbaumg@cs.yale.edufmichaelm,parkesg@eecs.harvard.eduJanuary30,20031IntroductionTheconventionalwisdomisthattheIn
2、ternetisveryinsecure."Thesubtitleofthisworkshop,namelydeploymentobstacles,"impliesthatnetworkowners,operators,anduserscouldhavesolvedpervasivesecurityproblemsiftheyhaddeployedexistingsecuritytechnology.Istheresolidevidencethateitherofthesestatementsistrue?Clearly,thereh
3、avebeensomewellpublicizedInternetsecurityproblems(e.g.,virusesanddistributeddenial-of-serviceattacks)duringthepastveyears,andsomelossbyindividualsandbusinessesisattributabletothem.DoesthismeanthatInternetinsecurityisreallyasignicantproblem?Isitamoreseriousproblemthanit
4、was,say,tenyearsago,oristheresimplymoreawarenessofitnowthantherewasthen?WhatfractionofInternetactivityorpotentialactivityisdisruptedorpreventedbecauseofactualorperceivedinsecurity?Isthisfractionhigherorlowerthanitwastenyearsago?Itisourthesisthatbettermodels,denitions,me
5、trics,anddatawouldgreatlyaidthedevelopmentofdeployable,eectivesecuritytechnology.WeexpanduponthisthesisinSections2-4below.Somehighlightsinclude:Itmightbefruitfultotakeasystemicapproach,i.e.,todene,measure,andprotectthesecurityofthenetworkasawhole,ratherthanthesecurity
6、ofindividualhostsandsubnetworks.Similarly,itmightbefruitfultotakearisk-managementapproach,inwhichthegoalistopredict,limit,contain,andcorrectthedamagedonebysecurityfailures,ratherthanthemoretraditionalcomplexity-theoretic,logical,andalgebraicapproaches,inwhichthegoalisto
7、preventfailuresortoisolatefailedcomponents.Asymptoticboundsoncomputationalresourcessuchastime,space,andbandwidtharenotsu-cientmeasuresofthecostofasecuritysolution;morerealistic,comprehensive,andquantitativemetricsareneeded.Securityresearchersneedbetterdataandmeasureme
8、nttechniques.Inparticular,thereshouldbeawaytoobtainquantitativeanswerstothequestionsraisedaboveaboutthe