E-Voting Risk Assessment: A Threat Tree for Direct Recording Electronic Systems

被引:4
作者
Pardue, Harold [1 ]
Landry, Jeffrey [2 ]
Yasinsac, Alec [2 ]
机构
[1] Univ S Alabama, Sch Comp & Informat Sci, Informat Syst, Mobile, AL 36688 USA
[2] Univ S Alabama, Sch Comp & Informat Sci, Mobile, AL 36688 USA
关键词
Direct Electronic Recording; Risk Assessment; Security; Threat Trees; Voting;
D O I
10.4018/jisp.2011070102
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Approximately 25% (according to http://verifiedvoting.com/) of voting jurisdictions use direct recording electronic systems to record votes. Accurate tabulation of voter intent is critical to safeguard this fundamental act of democracy: voting. Electronic voting systems are known to be vulnerable to attack. Assessing risk to these systems requires a systematic treatment and cataloging of threats, vulnerabilities, technologies, controls, and operational environments. This paper presents a threat tree for direct recording electronic (DRE) voting systems. The threat tree is organized as a hierarchy of threat actions, the goal of which is to exploit a system vulnerability in the context of specific technologies, controls, and operational environment. As an abstraction, the threat tree allows the analyst to reason comparatively about threats. A panel of elections officials, security experts, academics, election law attorneys, representatives from governmental agencies, voting equipment vendors, and voting equipment testing labs vetted the DRE threat tree. The authors submit that the DRE threat tree supports both individual and group risk assessment processes and techniques.
引用
收藏
页码:19 / 35
页数:17
相关论文
共 30 条
  • [1] Blaze M., 2009, IS EVOTING HONEYMOON
  • [2] CALANDRINO JA, 2007, SOURCE CODE REV DIEB
  • [3] HUMBLE PROGRAMER
    DIJKSTRA, EW
    [J]. COMMUNICATIONS OF THE ACM, 1972, 15 (10) : 859 - &
  • [4] Dill D. L., 2008, FREQUENTLY ASKED QUE
  • [5] Electronic Voting
    Epstein, Jeremy
    [J]. COMPUTER, 2007, 40 (08) : 92 - 95
  • [6] Feldman A. J., 2006, PROC 2006 USENIXACCU
  • [7] Fishcher E. A., 2003, ELECTION REFORM ELEC
  • [8] Ballot Formats, Touchscreens, and Undervotes: A Study of the 2006 Midterm Elections in Florida
    Frisina, Laurin
    Herron, Michael C.
    Honaker, James
    Lewis, Jeffrey B.
    [J]. ELECTION LAW JOURNAL, 2008, 7 (01): : 25 - 47
  • [9] GARDNER R, 2007, SOFTWARE REV SECURIT
  • [10] Hasen R. L., 2000, CALIFORNIA LAW REV, V88