首页> 外文会议>2010 Fifth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering >Identifying and Addressing Rogue Servers in Countering Internet Email Misuse
【24h】

Identifying and Addressing Rogue Servers in Countering Internet Email Misuse

机译:识别和解决恶意Internet电子邮件滥用中的恶意服务器

获取原文
获取原文并翻译 | 示例

摘要

Digital forensics is important in solving Internet security problems. However, in terms of improving security, its usefulness may have been hampered by the limitation of law enforcement and by a distrust, anti-establishment sentiment in the Internet. For digital forensics to work with (not against) security measures, a check and balance mechanism is needed. We have proposed a trust management framework that incorporates accountability to be such a mechanism. It is for servers in the Internet to set their security goals beyond protecting themselves, and to augment their services with accountability. Users or peer servers who trust and use a service shall be protected, and governed, not by their or even the server's own security measures, but by the collectively established accountability. To address email misuse this way, we have considered facilitating digital forensics in two requirements of accountability, namely, identification and attestation. We also considered how the authorization and retribution requirements of accountability can work with digital forensics to deter and provide a recourse to fix wrongdoing, to achieve the goal of accountability, hence security. In this paper, we analyze an email trace to show that unilateral identifying and addressing in countering email misuse such as spam are coarse and the effectiveness is greatly limited by the human-shield effects, i.e., we have to accept more spam in order to avoid collateral damages. However, by making trust and accountability explicit, some of those mixed senders (servers sent both ham and spam) can be rehabilitated to change behavior. With a proper trust and interaction mechanism aiming to achieve the readiness for e-discovery, we believe legitimate mail servers will distinguish themselves in upholding accountability. We can then bilaterally and multilaterally further identify and address those rogue servers.
机译:数字取证对于解决Internet安全问题很重要。但是,就提高安全性而言,其有效性可能由于执法的局限性以及Internet中的不信任,反建立情绪而受到阻碍。为了使数字取证能够(不违反)安全措施,需要一种制衡机制。我们提出了一种信任管理框架,该框架将问责制纳入了这种机制。 Internet上的服务器不仅要设置自身的安全性目标,还需要保护自己,并通过问责制来增强其服务。信任和使用服务的用户或对等服务器,不受其乃至服务器自身的安全措施的保护和管理,而应由集体建立的责任制进行保护和管理。为了解决这种方式的电子邮件滥用问题,我们考虑了在问责制的两个要求(即身份证明和证明)中促进数字取证。我们还考虑了问责制的授权和分配要求如何与数字取证一起使用,以阻止并提供解决错误行为的资源,以实现问责制和安全性的目标。在本文中,我们分析了电子邮件的痕迹,以表明在对抗电子邮件滥用(例如垃圾邮件)时,单方面的识别和处理是粗略的,其有效性受到人为屏蔽效应的极大限制,即,我们必须接受更多的垃圾邮件以避免附带损害赔偿。但是,通过明确表明信任和责任制,可以修复其中一些混合发件人(同时发送垃圾邮件和垃圾邮件的服务器)以更改行为。借助旨在实现电子发现准备就绪的适当信任和交互机制,我们相信合法邮件服务器将在维护责任制方面脱颖而出。然后,我们可以在双边和多边进一步识别和处理那些恶意服务器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号