Skip to main content
QUICK REVIEW

[论文解读] Computer Security: Competing Concepts

Helen Nissenbaum, Batya Friedman|ArXiv.org|Sep 28, 2001
Privacy, Security, and Data Protection被引用 5
一句话总结

本文識別並剖析了計算機安全領域中一個根本性的矛盾:一方面將安全視為對個人用戶免受威脅的保護,另一方面將安全視為聚焦於國家利益的國家安全組成部分。透過區分這兩種觀點,作者主張解決此衝突需要明確地選擇一種框架來引導更符合價值觀的網頁瀏覽器系統設計,特別是在 Mozilla 等項目中。

ABSTRACT

This paper focuses on a tension we discovered in the philosophical part of our multidisciplinary project on values in web-browser security. Our project draws on the methods and perspectives of empirical social science, computer science, and philosophy to identify values embodied in existing web-browser security and also to prescribe changes to existing systems (in particular, Mozilla) so that values relevant to web-browser systems are better served than presently they are. The tension, which we had not seen explicitly addressed in any other work on computer security, emerged when we set out to extract from the concept of security the set values that ought to guide the shape of web-browser security. We found it impossible to construct an internally consistent set of values until we realized that two robust -- and in places competing -- conceptions of computer security were influencing our thinking. We needed to pry these apart and make a primary commitment to one. One conception of computer security invokes the ordinary meaning of security. According to it, computer security should protect people -- computer users -- against dangers, harms, and threats. Clearly this ordinary conception of security is already informing much of the work and rhetoric surrounding computer security. But another, substantively richer conception, also defines the aims and trajectory of computer security -- computer security as an element of national security. Although, like the ordinary conception, this one is also concerned with protection against threats, its primary subject is the state, not the individual. The two conceptions suggest divergent system-specifications, not for all mechanisms but a significant few.

研究动机与目标

  • 識別並分析先前研究中被忽略的計算機安全領域中的哲學性矛盾。
  • 檢視兩種競爭性的安全觀念——個人保護與國家安全——如何塑造網頁瀏覽器系統的設計與價值觀。
  • 透過明確哪種安全觀念應作為系統規格的基礎,來引導網頁瀏覽器安全系統(如 Mozilla 的系統)的重構。
  • 透過調和相互衝突的安全觀念,提供一種使技術系統與倫理價值相一致的框架。

提出的方法

  • 採用跨學科方法,結合實證社會科學、計算機科學與哲學,分析網頁瀏覽器安全中的價值觀。
  • 提取並比較兩種截然不同的計算機安全觀念中所嵌入的核心價值:個人保護與國家安全。
  • 分析每種觀念如何影響系統設計,特別是在威脅建模、存取控制與資料處理方面的影響。
  • 運用哲學分析來區分安全的主體——個人與國家——及其對系統規格的影響。
  • 將此區分應用於現實系統(如 Mozilla 的瀏覽器),以評估哪種觀念更能實現倫理與功能目標。
  • 主張應明確、基於原則地選擇一種觀念,以解決價值驅動系統設計中的內在不一致。

实验结果

研究问题

  • RQ1影響網頁瀏覽器系統設計的兩種競爭性計算機安全觀念是什麼?
  • RQ2將安全視為對個人的保護與將安全視為國家安全組成部分的觀念,如何導致系統規格的分歧?
  • RQ3為何這兩種觀念之間的矛盾在以往的計算機安全文獻中未被明確處理?
  • RQ4哪種安全觀念應引導 Mozilla 等網頁瀏覽器系統的開發,以更好地實現倫理價值?
  • RQ5當兩種強大且競爭性的安全觀念同時存在時,如何建立一組一致的價值觀?

主要发现

  • 本文識別出兩種截然不同且競爭性的計算機安全觀念:一種以保護個人用戶免受威脅為核心,另一種則以保護國家為主要主體。
  • 這兩種觀念導致根本不同的系統規格,特別是在威脅定義與緩解方式上的差異。
  • 以個人保護為焦點的常規安全觀念,已廣泛反映在當前的安全言論與設計中。
  • 國家安全觀念雖較不顯著,但對計算機安全的發展軌跡,特別是在政策與基礎設施設計方面,具有顯著影響。
  • 若未明確認識並解決這兩種觀念之間的矛盾,就無法為系統設計構建內在一致的價值體系。
  • 必須明確地專注於其中一種觀念——特別是個人中心的觀念——才能實現一致且價值導向的系統開發。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。