Skip to main content
QUICK REVIEW

[論文レビュー] Computer Security: Competing Concepts

Helen Nissenbaum, Batya Friedman|ArXiv.org|Sep 28, 2001
Privacy, Security, and Data Protection被引用数 5
ひとこと要約

この論文は、コンピュータセキュリティにおける根本的な対立を特定し、解明している。それは、個人のユーザーに対する脅威からの保護というセキュリティのあり方と、国家の利益を焦点とした国家セキュリティの側面という、2つの対立する概念の間の対立である。著者らは、これらの概念を区別することで、より価値観に整合したウェブブラウザーシステムの設計を導くために、あるフレームワークへの意図的なコミットメントが不可欠であると主張している。特にモジラのプロジェクトのような文脈においてその重要性が顕著である。

ABSTRACT

This paper focuses on a tension we discovered in the philosophical part of our multidisciplinary project on values in web-browser security. Our project draws on the methods and perspectives of empirical social science, computer science, and philosophy to identify values embodied in existing web-browser security and also to prescribe changes to existing systems (in particular, Mozilla) so that values relevant to web-browser systems are better served than presently they are. The tension, which we had not seen explicitly addressed in any other work on computer security, emerged when we set out to extract from the concept of security the set values that ought to guide the shape of web-browser security. We found it impossible to construct an internally consistent set of values until we realized that two robust -- and in places competing -- conceptions of computer security were influencing our thinking. We needed to pry these apart and make a primary commitment to one. One conception of computer security invokes the ordinary meaning of security. According to it, computer security should protect people -- computer users -- against dangers, harms, and threats. Clearly this ordinary conception of security is already informing much of the work and rhetoric surrounding computer security. But another, substantively richer conception, also defines the aims and trajectory of computer security -- computer security as an element of national security. Although, like the ordinary conception, this one is also concerned with protection against threats, its primary subject is the state, not the individual. The two conceptions suggest divergent system-specifications, not for all mechanisms but a significant few.

研究の動機と目的

  • 先行研究で見過ごされてきた、コンピュータセキュリティにおける哲学的対立を特定・分析すること。
  • ウェブブラウザーシステムの設計と価値にどのように作用するかを検討する、2つの対立するセキュリティの概念(個人保護と国家セキュリティ)の分析。
  • システム仕様の根拠としてどのセキュリティ概念を採用すべきかを明確化することで、モジラのようなウェブブラウザーセキュリティシステムの再設計を導くこと。
  • 対立するセキュリティ概念を是正することで、技術的システムを倫理的価値と一致させるための枠組みを提供すること。

提案手法

  • ウェブブラウザーセキュリティにおける価値を分析するため、実証的社会科学、コンピュータサイエンス、哲学を統合した多分野的アプローチを採用する。
  • コンピュータセキュリティの2つの異なる概念(個人保護と国家セキュリティ)に内蔵された核心的価値を抽出・比較する。
  • 各概念が、脅威モデル、アクセス制御、データ処理の観点からシステム設計にどのように影響を与えるかを分析する。
  • 哲学的分析を通じて、セキュリティの主語(個人対国家)を区別し、システム仕様に与える影響を明らかにする。
  • 実世界のシステム(例:モジラのブラウザ)にこの区別を適用し、どの概念が倫理的および機能的目標をよりよく満たすかを評価する。
  • 内部的な整合性のない価値志向のシステム設計を是正するため、ある概念への意図的で原則的コミットメントを提唱する。

実験結果

リサーチクエスチョン

  • RQ1ウェブブラウザーシステムの設計に影響を与える2つの対立するコンピュータセキュリティの概念は何か?
  • RQ2個人の保護としてのセキュリティと、国家セキュリティとしてのセキュリティという2つの概念が、どのように異なるシステム仕様を生じさせるのか?
  • RQ3なぜこの2つの概念の間の緊張関係が、先行するコンピュータセキュリティの文献では明示的に扱われてこなかったのか?
  • RQ4モジラのようなウェブブラウザーシステムの開発を進めるにあたり、どのセキュリティ概念が倫理的価値をよりよく満たすか?
  • RQ52つの強固で対立するセキュリティ概念が存在する状況で、どのように一貫性のある価値セットを構築できるか?

主な発見

  • この論文は、コンピュータセキュリティにおける2つの明確で対立する概念を特定している。1つはユーザーの個人的保護を焦点としたもので、もう1つは国家を主な保護対象とするものである。
  • これらの2つの概念は、脅威の定義や緩和の仕方において、根本的に異なるシステム仕様を生じさせる。
  • 一般的なセキュリティの概念(個人保護中心)は、すでに現在のセキュリティの言説と設計に広く反映されている。
  • 国家セキュリティの概念は、目立たないが、とりわけ政策やインfra構築の分野で、コンピュータセキュリティの方向性に顕著な影響を与えている。
  • これらの概念の間の緊張関係を明示的に認識し、是正しなければ、システム設計のための一貫性のある価値セットを構築することは不可能である。
  • 整合的で価値志向のシステム開発を達成するためには、特に個人中心の概念への主なコミットメントが不可欠である。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。