计算机系统防御中的反常效应:当更多反而更少

Perverse Effects in Defense of Computer Systems: When More Is Less

Journal of Management Information Systems · 2016
被引 22
FT 50ABS 4

中文导读

研究了计算机安全投入增加反而可能引入新漏洞的反常现象,基于意外后果理论和技术双重性分析其成因,并分类提出规避方法,对安全决策者有用。

Abstract

With computer security spending on the rise, organizations seem to have accepted the notion that buying more—and more expensive—defenses allows them to better protect their computer systems. In the context of complex computer systems, however, defenses can also have the opposite effect, creating new, unforeseen vulnerabilities in the systems they are intended to protect. Advocacy for defense-in-depth and diverse security measures has contributed to this “more is better” mentality for defending computer systems, which fails to consider the complex interaction of different components in these systems, especially with regard to what impact new security controls may have on the operation and functionality of other, preexisting defenses. We give examples of several categories of perverse effects in defending computer systems and draw on the theory of unintended consequences and the duality of technology to analyze the origins of these perverse effects, and to develop a classification scheme for the different types and some methods for avoiding them.

计算机安全复杂系统风险管理意外后果