论文标题

有效的安全性

Effective Security by Obscurity

论文作者

Smith, J. Christian

论文摘要

“默默无闻的安全性”是一种溴化物,经常用于破坏安全性技术中某种类别的感知价值。这种用法最初源于密码理论领域的应用和经验,以及开放式和封闭式辩论。通过认为缺乏真正的安全性,默默无闻的安全领域并未成为安全从业者的可行或可识别的方法。这样的后果导致这些技术不足和被防御者的重视程度不足,而他们继续为攻击者提供价值,从而造成了不幸的信息不对称性。可以看出,可以看出,在其他可行的安全学科中未被发现的例子已经被嵌入了示例,例如信息隐藏,混淆,多样性和行动目标辩护。在表明默默无闻的措施是对其他安全措施的可实现和理想的补充,显然,可以通过默默无闻的有效和有效地使用安全性来增强对组织资产的深入辩护。

"Security by obscurity" is a bromide which is frequently applied to undermine the perceived value of a certain class of techniques in security. This usage initially stemmed from applications and experience in the areas of cryptographic theory, and the open vs. closed source debate. Through the perceived absence of true security, the field of security by obscurity has not coalesced into a viable or recognizable approach for security practitioners. The ramifications of this has resulted in these techniques going underused and underappreciated by defenders, while they continue to provide value to attackers, which creates an unfortunate information asymmetry. Exploring effective methods for employing security by obscurity, it can be seen that examples are already embedded unrecognized in other viable security disciplines, such as information hiding, obfuscation, diversity, and moving target defense. In showing that obscurity measures are an achievable and desirable supplement to other security measures, it is apparent that the in-depth defense of an organization's assets can be enhanced by intentional and effective use of security by obscurity.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源