...
首页> 外文期刊>Communications of the ACM >SOFTWARE SECURITY AND PRIVACY RISKS IN MOBILE E-COMMERCE
【24h】

SOFTWARE SECURITY AND PRIVACY RISKS IN MOBILE E-COMMERCE

机译:移动电子商务中的软件安全性和隐私风险

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

While many of the risks of desktop Internet-based commerce will pervade m-commerce, m-commerce itself presents new risks. The nature of the medium requires a degree of trust and cooperation between member nodes in networks that can be exploited by malicious entities to deny service as well as collect confidential information and disseminate false information. Furthermore, the platforms and languages being developed for wireless devices have failed to adopt fundamental security concepts employed in the current generation of desktop machines. Encrypted communication protocols are necessary to provide confidentiality, integrity, and authentication services for m-commerce applications. Perhaps the greatest risk of encrypted communication links, though, is the false sense of security they provide wireless users and purveyors of m-commerce. Probably the most significant risk to m-commerce systems will be from malicious code that is beginning to penetrate wireless networks. Malicious code has the ability to undermine other security technologies such as signing, authentication, and encryption because it runs resident to the device with all the privileges of the owner. The risks presented by malicious mobile scripts to wireless devices are significant. As illustrated here, wireless device manufacturers and language developers have ignored past lessons learned with regard to security and privacy risks in mobile code. Our goal here is to highlight the key security and privacy risks already apparent in these devices and their language platforms in order to influence device and platform manufacturers to build more robust and secure systems. It is important to note here that though the current version of WAP, 1.2 uses WML and WML Script as its language and partner script, WAP version 2.0 is scheduled to be released within the next year. Version 2.0 may retire WML and WML Script in favor of a more robust language such as XHTML and a similar partner script, possibly JavaScript. While we expect many of the same security risks to apply to the scripting language of choice for version 2.0, we hope the specification addresses the weaknesses highlighted in this article. The best strategy for addressing the security and privacy risks of Internet-based content is to build security into the platform and applications themselves, rather than attempt to introduce security patches afterward. For instance, Java provides type safety, memory protection, and sandboxing for untrusted content. While history has shown that various implementations of the Java virtual machine have not been perfect, its model of secure computation is relatively good. The device manufacturers and the language developers for wireless applications should leverage the decades of progress in secure operating system models and secure models of computation before going forward with business-critical and privacy-related wireless applications. Otherwise, we are doomed to repeat the mistakes of the past, and potentially take two steps backward as we move one step forward.
机译:尽管基于桌面Internet的商务的许多风险将遍及移动商务,但移动商务本身也带来了新的风险。介质的性质要求网络中成员节点之间具有一定程度的信任和合作,恶意实体可以利用该信任和合作来拒绝服务以及收集机密信息并散布虚假信息。此外,为无线设备开发的平台和语言未能采用当前一代台式机中采用的基本安全概念。为了为移动商务应用程序提供机密性,完整性和身份验证服务,必须使用加密的通信协议。但是,加密通信链路的最大风险也许是它们为无线用户和移动商务提供者提供的错误的安全感。移动电子商务系统面临的最大风险可能是来自开始渗透到无线网络的恶意代码。恶意代码具有破坏其他安全技术的能力,例如签名,身份验证和加密,因为它以所有者的所有特权驻留在设备上。恶意移动脚本给无线设备带来的风险是巨大的。如此处所示,无线设备制造商和语言开发人员已经忽略了过去有关移动代码中的安全性和隐私风险的经验教训。我们的目标是突出这些设备及其语言平台中已经显而易见的关键安全和隐私风险,以影响设备和平台制造商构建更强大和安全的系统。这里需要特别注意的是,尽管当前的WAP版本1.2使用WML和WML脚本作为其语言和合作伙伴脚本,但WAP版本2.0计划在明年发布。 2.0版可能弃用WML和WML脚本,而推荐使用更健壮的语言(例如XHTML)和类似的合作伙伴脚本(可能是JavaScript)。尽管我们期望许多相同的安全风险会应用于版本2.0的脚本语言,但我们希望该规范解决本文中强调的弱点。解决基于Internet的内容的安全和隐私风险的最佳策略是将安全性内置到平台和应用程序本身中,而不是尝试在以后引入安全补丁。例如,Java为不受信任的内容提供类型安全性,内存保护和沙箱。历史记录表明,Java虚拟机的各种实现尚不完善,但其安全计算模型却相对不错。无线应用程序的设备制造商和语言开发人员应该利用安全操作系统模型和安全计算模型数十年来的进展,然后再进行关键业务和隐私相关的无线应用程序的开发。否则,我们注定要重复过去的错误,并可能在向前迈出一步时向后迈出两步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号