【24h】

Enforcing the Unenforceable

机译:强制执行不可行的

获取原文

摘要

A security policy is intended to regulate the behaviour of a socio-technical system (computers, networks and humans) in such a way as to ensure that certain properties are maintained or goals achieved. Two problems arise here: regulating the behaviour of humans is non-trivial and, secondly, many security goals are not "enforceable" in the Schneider sense, Thus, security policy mechanisms inevitably involve approximations and trade-offs. We discuss the theoretical and practical limitations on what is technically enforceable and argue for the need for models that encompass social as well as technical enforcement mechanisms.
机译:安全策略旨在规范社会技术系统(计算机,网络和人类)的行为,以确保维持某些物业或实现的目标。出现两个问题:规范人类的行为是非微不足道的,其次,许多安全目标在施奈德的感觉中没有“可强制”,因此,安全策略机制不可避免地涉及近似和权衡。我们讨论了对技术上强制性的理论和实践局限性,并争论需要涵盖社会和技术执法机制的模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号