首页> 外文会议>International security protocols workshop >Device Attacker Models: Fact and Fiction (Transcript of Discussion)
【24h】

Device Attacker Models: Fact and Fiction (Transcript of Discussion)

机译:设备攻击者模型:事实和虚构(讨论的成绩单)

获取原文

摘要

Good morning everyone, this talk is about the question of what happens when your device gets contaminated by malware and becomes under the control of adversaries. Is there anything that you can still do in the way of security functionality, for example, could you still make use of cryptographic keys that are stored on the device. Now that sounds a bit hopeless, because clearly if the device is controlled by an adversary then the adversary also has those keys and can make copies of them and so on. But I hope to convince you that there's a few weak results that you can get in that space. So the assumption that we make, the kind of fiction in this space is that we have a device that's capable of long-term storage of crypto keys, and of course that's the underlying assumption of cryptography. Crypto systems assume that you have a secure private key, but as we know, this is difficult to achieve in the face of security, vulnerability and malware. So I'm not going to spend much time convincing you that there is a lot of malware out there, and a lot of security vulnerabilities, here is a recent graph of security vulnerabilities in 2014, and as you can see, all of the major systems are affected. And then in the mobile space the amount of malware is of course increasing as mobiles become more penetrating, and more vulnerable.
机译:大家早上好,这个谈话是关于当你的设备被恶意软件被污染时发生的事情的问题,并成为对手的控制。例如,您可以在安全功能的方式中是否可以使用存储在设备上的加密密钥。现在听起来有点无望,因为清楚地,如果设备由对手控制,那么对手也有那些钥匙,可以制作它们的副本等。但我希望说服你能够在那个空间中获得一些薄弱的结果。因此,假设我们制作,这个空间中的小说是我们拥有一个能够长期存储加密键的设备,当然这是加密的潜在假设。 Crypto Systems假设您拥有一个安全的私钥,但正如我们所知,这很难面对安全,漏洞和恶意软件。所以我不会花费很多时间说服你那里有很多恶意软件,以及很多安全漏洞,这是2014年的安全漏洞的第一个图表,就像你可以看到的那样,所有的专业系统受到影响。然后在移动空间中,恶意软件的数量当然越来越多,因为手机变得更加渗透,更脆弱。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号