Some fundamental cybersecurity concepts

被引:0
作者
Wilson, Kelce S. [1 ,2 ]
Kiy, Müge Ayse [3 ]
机构
[1] IEEE, United States
[2] Patent Litigation, BlackBerry, TX,75094, United States
[3] Black Berry, Washington,DC,20001, United States
关键词
Personal computing - Security systems - Cybersecurity;
D O I
暂无
中图分类号
学科分类号
摘要
The results of successful hacking attacks against commercially available cybersecurity protection tools that had been touted as secure are distilled into a set of concepts that are applicable to many protection planning scenarios. The concepts, which explain why trust in those systems was misplaced, provides a framework for both analyzing known exploits and also evaluating proposed protection systems for predicting likely potential vulnerabilities. The concepts are: 1) differentiating security threats into distinct classes; 2) a five layer model of computing systems; 3) a payload versus protection paradigm; and 4) the nine Ds of cybersecurity, which present practical defensive tactics in an easily remembered scheme. An eavesdropping risk, inherent in many smartphones and notebook computers, is described to motivate improved practices and demonstrate real-world application of the concepts to predicting new vulnerabilities. Additionally, the use of the nine Ds is demonstrated as analysis tool that permits ranking of the expected effectiveness of some potential countermeasures. © 2014 IEEE.
引用
收藏
页码:116 / 124
相关论文
empty
未找到相关数据