Skip to main content
QUICK REVIEW

[论文解读] What Should be Hidden and Open in Computer Security: Lessons from Deception, the Art of War, Law, and Economic Theory

Peter Swire|ArXiv.org|Sep 24, 2001
Cybersecurity and Cyber Warfare Studies被引用 3
一句话总结

本文提出了一套理论框架,通过整合军事战略(孙子与克劳塞维茨)、法律和经济学的洞见,确定计算机安全中应隐藏或公开的内容。该理论认为,虽然保密可防范攻击(如军事诡雷),但软件与系统的开放性可增强信任并提升市场效率,经济模型揭示了开放程度的潜在市场失灵,最终为网络空间安全的透明度政策与设计决策提供指导。

ABSTRACT

"What Should be Hidden and Open in Computer Security: Lessons from Deception, the Art of War, Law, and Economic Theory" Peter P. Swire, George Washington University. Imagine a military base. It is defended against possible attack. Do we expect the base to reveal the location of booby traps and other defenses? No. But for many computer applications,a software developer will need to reveal a great deal about the code to get other system owners to trust the code and know how to operate with it. This article examines these conflicting intuitions and develops a theory about what should be open and hidden in computer security. Part I of the paper shows how substantial openness is typical for major computer security topics, such as firewalls, packaged software, and encryption. Part II shows what factors will lead to openness or hiddenness in computer security. Part III presents an economic analysis of the issue of what should be open in computer security. The owner who does not reveal the booby traps is like a monopolist, while the open-source software supplier is in a competitive market. This economic approach allows us to identify possible market failures in how much openness occurs for computer security. Part IV examines the contrasting approaches of Sun Tzu and Clausewitz to the role of hiddenness and deception in military strategy. The computer security, economic, and military strategy approaches thus each show factors relevant to what should be kept hidden in computer security. Part V then applies the theory to a range of current legal and technical issues.

研究动机与目标

  • 解决计算机安全中保密(如军事防御)与开放(如开源软件)之间的张力。
  • 基于战略、法律与经济原则,识别决定安全组件应隐藏或公开的因素。
  • 分析计算机安全中开放程度的市场失灵,尤其在软件与密码系统领域。
  • 将孙子与克劳塞维茨关于欺骗与战略的洞见应用于现代网络安全决策。
  • 为软件、加密与系统设计中的透明度提供法律与技术政策框架。

提出的方法

  • 分析防火墙、成套软件与加密等主要安全领域中开放与保密的实际案例。
  • 应用经济模型,比较垄断性保密(隐藏缺陷)与竞争性开源模式(公开代码),以评估市场效率。
  • 运用军事战略,特别是孙子强调欺骗与克劳塞维茨注重公开对抗的对比,指导安全透明度决策。
  • 整合法律与监管视角,评估披露的法律责任与合规性,以权衡透明度的取舍。
  • 构建一个理论模型,平衡通过隐蔽性获得的安全与通过透明性获得的安全,采用博弈论与激励机制推理。
  • 通过所提出的框架评估当前法律与技术问题(如软件披露、漏洞报告)的透明度影响。

实验结果

研究问题

  • RQ1在何种情况下应隐藏安全机制以防止被利用,而在何种情况下应公开以促进验证与信任?
  • RQ2经济激励如何影响软件与密码系统中的开放程度,市场失灵发生于何处?
  • RQ3孙子与克劳塞维茨军事学说中的战略教训,对现代计算机安全透明度有何适用性?
  • RQ4法律与监管框架如何影响披露或隐藏安全缺陷与系统设计的决策?
  • RQ5可采用何种标准来确定通过隐蔽性与通过透明性实现安全之间的最优平衡?

主要发现

  • 软件与安全系统的开放性可增强信任并降低系统性风险,尤其在竞争性市场中,透明度作为质量信号发挥关键作用。
  • 当开发者因隐藏漏洞的激励而过度减少开放投入时,市场失灵便会出现,导致安全结果不理想。
  • 孙子强调的策略性欺骗与克劳塞维茨强调的公开、决定性对抗之间的对比,揭示了不同威胁模型需要不同的透明度策略。
  • 法律与监管框架往往与最优透明度水平不一致,导致对负责任漏洞披露的激励不足。
  • 经济模型表明,尽管存在潜在风险,开源软件通常因同行审查与竞争压力而带来更优的长期安全性。
  • 本文结论认为,必须采用一种平衡且情境敏感的方法——以经济、战略与法律原则为指导——来确定计算机安全中应隐藏或公开的内容。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。