首页> 外文会议>International Conference on Cyber Conflict >Vulnerabilities and their surrounding ethical questions: a code of ethics for the private sector
【24h】

Vulnerabilities and their surrounding ethical questions: a code of ethics for the private sector

机译:漏洞及其周围的道德问题:私营部门的道德准则

获取原文

摘要

Zero-day vulnerabilities - weaknesses in software that are unknown to the parties who can mitigate their specific negative effects - are gaining a prominent role in the modern-day intelligence, national-security, and law-enforcement operations. At the same time, the lack of transparency and accountability in their trade and adoption, their possible overexploitation or abuse, the latent conflict of interests by entities handling them, and their potential double effect may pose societal risks or lead to the breach of human rights. If left unaddressed, these usage-related challenges call into question the legitimacy of zero-day vulnerabilities as enablers of national security and law enforcement operations and erode the benefits that their proportionate use have for the judiciary, defence, and intelligence purposes. This work explores what the private sector involved in the trade of zero-day vulnerabilities can do to ensure the respect human rights and the benign and societally beneficial use of those capabilities. After reviewing what can go wrong in the acquisition of zero-day vulnerabilities, the article contributes the first code of ethics focused on the trade of vulnerability information, where the author sets forth six principles and eight corresponding ethical standards aimed respectively at guiding and regulating the conduct of this business.
机译:零日漏洞-各方可以减轻其特定负面影响的未知软件弱点-在现代情报,国家安全和执法行动中正扮演着重要角色。同时,在贸易和采用过程中缺乏透明度和问责制,可能的过度开发或滥用,处理它们的实体之间潜在的利益冲突以及其潜在的双重影响可能构成社会风险或导致侵犯人权的行为。 。如果不加以解决,这些与使用相关的挑战就将零日漏洞作为国家安全和执法行动的推动力的合法性提出了疑问,并削弱了零日漏洞在司法,国防和情报方面的应有用途。这项工作探讨了参与零日漏洞交易的私营部门可以做什么,以确保尊重人权以及对这些功能的良性和社会性使用。在回顾了零日漏洞的获取可能出了什么问题之后,本文提出了以漏洞信息交易为重点的第一份道德守则,作者提出了六项原则和八项相应的道德标准,分别旨在指导和规范漏洞。这项业务的开展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号