【24h】

Enforcing the Unenforceable

机译:强制执行

获取原文
获取原文并翻译 | 示例

摘要

A security policy is intended to regulate the behaviour of a socio-technical system (computers, networks and humans) in such a way as to ensure that certain properties are maintained or goals achieved. Two problems arise here: regulating the behaviour of humans is non-trivial and, secondly, many security goals are not "enforceable" in the Schneider sense, Thus, security policy mechanisms inevitably involve approximations and trade-offs. We discuss the theoretical and practical limitations on what is technically enforceable and argue for the need for models that encompass social as well as technical enforcement mechanisms.
机译:安全策略旨在通过某种方式来规范社会技术系统(计算机,网络和人)的行为,以确保维持某些属性或实现目标。这里出现两个问题:规范人类的行为并非易事,其次,从Schneider的意义上讲,许多安全目标不是“可强制执行的”。因此,安全策略机制不可避免地涉及近似和权衡。我们讨论了在技术上可执行的内容的理论和实践限制,并提出了对包含社会和技术执行机制的模型的需求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号