【24h】

Message from the Workshop Organizers

机译:来自研讨会组织者的信息

获取原文

摘要

It has been ten years since we had the idea of founding a workshop dedicated to socio-technical aspects of cyber-security. At that time, something was missing in the landscape of events in security research: a venue in which to discuss security in a broader manner, a manner that combined technical discussion with other topics traditionally linked to usability and human computer interaction research, yet much broader than just these. There was a need to discuss attacks that exploit technical hacking in combination with social engineering and, equally, there was a need to discuss user practices, organizational processes, and social culture as instruments to establish security or, by contrast, as possible vectors to break it. Discussing such matters was, and still is, relevant since evidence shows that designing systems that are secure when analyzed from a merely technical perspective, regardless of the values and merits of the approach, does not guarantee that security works as expected once deployed. The common and arguable explanation is that the human, the "weakest link," did not comply. However, blaming users neither helps nor gives us instruments to design stronger systems. We have learned by experience that a better strategy is to holistically conceive systems whose security emerges by harmonizing the technical features with the modalities in which humans, organizations, and societies operate. The manifesto of addressing security problems socio-technically means exactly that all the components are addressed as a whole. We have also learned that such a manifesto has a very wide impact, encompassing virtually all application areas where human beings may play a role in the effectiveness of security measures; hence, it concerns virtually every ICT application that must be protected from criminals.
机译:十年前,我们提出了成立一个专门讨论网络安全的社会技术方面的研讨会的想法。当时,安全研究领域的活动中缺少了一些东西:一个以更广泛的方式讨论安全性的场所,一种将技术讨论与传统上与可用性和人机交互研究相关的其他主题相结合的方式,但远不止这些。有必要讨论利用技术黑客和社会工程相结合的攻击,同样,也有必要讨论用户实践、组织流程和社会文化,作为建立安全的工具,或相反,作为破坏安全的可能载体。讨论这些问题过去是,现在仍然是相关的,因为证据表明,设计仅从技术角度进行分析时安全的系统,无论该方法的价值和优点如何,都不能保证一旦部署,安全性就会如预期的那样工作。一种常见且有争议的解释是,作为“最薄弱环节”的人没有遵守。然而,指责用户既没有帮助,也没有给我们设计更强大系统的工具。我们从经验中了解到,更好的策略是整体构想系统,通过将技术特征与人类、组织和社会运作的模式相协调,系统的安全性得以显现。《从社会技术角度解决安全问题宣言》确切地意味着所有组成部分都作为一个整体来解决。我们还了解到,这样的宣言具有非常广泛的影响,几乎涵盖了人类可能在安全措施的有效性方面发挥作用的所有应用领域;因此,它几乎涉及每一个必须受到保护的ICT应用程序,使其免受犯罪分子的侵害。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号