Skip to main content
QUICK REVIEW

[论文解读] Bring-Your-Own-Device (BYOD): An Evaluation of Associated Risks to Corporate Information Security

Ezer Osei Yeboah-Boateng, Francis Edmund Boaten|arXiv (Cornell University)|Sep 5, 2016
Information and Cyber Security被引用 6
一句话总结

本文评估了企业环境中使用自带设备(BYOD)政策所涉及的网络风险,识别出由于安全控制不足,数据丢失是主要威胁。通过专家意见和风险评估,本文揭示了非管理个人设备带来的漏洞,并提出了平衡生产力与信息安全的缓解策略。

ABSTRACT

This study evaluates the cyber-risks to Business Information Assets posed by the adoption of Bring-Your-Own-Device (BYOD) to the workplace. BYOD is an emerging trend where employees bring and use personal computing devices on the companys network to access applications and sensitive data like emails, calendar and scheduling applications, documents, etc. Employees are captivated by BYOD because they can have access to private items as well as perform certain job functions while being unrestricted to their desks. This is however usually done on the blind side of management or the system administrator; a situation that tends to expose vital and sensitive corporate information to various threats like unwanted network traffic, unknown applications, malwares, and viruses. Expert opinions were elicited in this exploratory study. The study evaluated the characteristics of BYOD, assessed associated risks, threats and vulnerabilities. The findings indicate that little or no security measures were instituted to mitigate risks associated with BYOD. Though, profound benefits abound with BYOD adoption, they could be eroded by security threats and costs of mitigation in curing breaches. The most significant risk was found to be Data Loss which was in consonance with similar studies on Smartphone security risks. Some mitigation measures are then recommended.

研究动机与目标

  • 评估员工在企业网络中使用个人设备所带来的风险。
  • 识别与企业采用BYOD相关的关键威胁和漏洞。
  • 评估现有安全控制措施(或缺乏)对BYOD相关风险的应对情况。
  • 提出切实可行的缓解策略,以降低BYOD环境中网络威胁的暴露风险。

提出的方法

  • 基于信息安全专业人员的专家意见,开展探索性研究。
  • 分析BYOD的特征,以理解其在企业网络中的整合方式。
  • 评估来自个人设备的威胁,如恶意软件、未经授权的应用程序以及网络入侵。
  • 识别与缺乏设备管理、访问控制薄弱以及加密不足相关的漏洞。
  • 使用定性风险评估方法,根据影响程度和发生可能性对威胁进行排序。
  • 基于识别出的风险和专家共识,提出安全缓解措施。

实验结果

研究问题

  • RQ1在企业环境中采用BYOD所关联的主要网络风险是什么?
  • RQ2未经管理的个人设备如何为企业信息资产引入漏洞?
  • RQ3在BYOD场景中,对数据机密性和完整性的最大威胁是什么?
  • RQ4当前的安全政策在缓解BYOD相关风险方面的有效性如何?
  • RQ5哪些安全控制措施能有效降低BYOD部署中的数据丢失风险?

主要发现

  • 数据丢失被确定为BYOD环境中最严重的风险,与智能手机安全研究的发现一致。
  • 发现极少或完全没有实施安全措施来缓解与BYOD采用相关的风险。
  • 员工经常在缺乏管理监督的情况下使用个人设备,增加了遭受恶意软件和未经授权访问的风险。
  • 缺乏集中式设备管理与加密,增加了敏感数据被窃取的可能性。
  • BYOD带来的优势可能被安全漏洞和补救成本所抵消。
  • 推荐的缓解策略包括移动设备管理(MDM)、数据加密以及用户安全意识培训。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。