【24h】

Security in Wiki-Style Authoring Systems

机译:维基风格创作系统的安全性

获取原文

摘要

During the past decade, online collaboration has grown from a practice primarily associated with the workplace to a social phenomenon, where ordinary people share information about their life, hobbies, interests, politics etc. In particular, social software, such as open collaborative authoring systems like wikis, has become increasingly popular. This is probably best illustrated through the immense popularity of the Wikipedia, which is a free encyclopedia collabo-ratively edited by thousands of Internet users with a minimum of administration. As more and more people come to rely on the information stored in open collaborative authoring systems, security is becoming an important concern for such systems. Inaccuracies in the Wikipedia have been rumoured to cause students to fail courses, innocent people have been associated with the murder of John F. Kennedy, etc. Improving the correctness, completeness and integrity of information in collaboratively authored documents is therefore of vital importance to the continued success of such systems. It has previously been observed that integrity is the most important security property in open collaborative authoring systems. In this paper we propose a general security model for open collaborative authoring systems based on a combination of classic integrity mechanisms from computer security and reputation systems. The model is able to accommodate a number of different integrity policies and three different policies are presented in the paper. While the model provides a reputation based assessment of the trustworthiness of the information contained in a document, the primary objective is to prevent untrustworthy authors from compromising the integrity of the document. In order to determine the effectiveness of the proposed integrity model, we present an attacker model for open collaborative authoring systems, which allows us to calculate the vulnerability of a given document based on the fraction of malicious authors in the system.
机译:在过去十年中,在线合作从主要与工作场所相关的实践中成长为社会现象,普通人分享有关其生活,爱好,兴趣,政治等的信息,特别是社会软件,例如公开协作创作系统像维基一样,越来越受欢迎。这可能是通过维基百科的巨大普及,这是一部分由数千名互联网用户的免费百科全书,最少的百科全书。随着越来越多的人来依靠存储在公开协作创作系统中的信息,安全性正在成为这种系统的重要关注。维基百科的不准确性令人传闻称,让学生失败课程,无辜的人与约翰F.肯尼迪的谋杀有关,提高了合作撰写的文件的正确性,完整性和诚信,因此对撰写的文件至关重要这种系统的持续成功。先前已观察到,诚信是公开协同创作系统中最重要的安全性。在本文中,我们提出了一种基于计算机安全性和信誉系统的经典完整性机制的组合的开放协同创作系统的一般安全模型。该模型能够适应许多不同的完整性政策,并在纸上提出了三种不同的政策。虽然该模型提供了基于众所周知的基于信誉的评估,但是主要目标是防止不值得信赖的作者损害文件的完整性。为了确定所提出的完整性模型的有效性,我们为公开协作创作系统提供了一种攻击者模型,这使我们能够根据系统中的恶意作者的一部分计算给定文档的漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号