Bickering In-Depth: Rethinking the Composition of Competing Security Systems
Michael E. Locasto, Sergey Bratus, Brian Schulte
Abstract
Michael E. Locasto, Sergey Bratus, Brian Schulte
Abstract
A wide variety of security software competes for control of desktops, servers, and handhelds. Competition for control over a system's security posture can leave systems mired in a performance tar pit and subvert the very security they were meant to provide. Although the use of defense in-depth is widely recommended, it isn't nearly as automated as it could be, particularly when it comes to composing policy in addition to functionality. We suggest a paradigm in which security programmers intentionally design their code to cooperate with similar software by negotiating over security-critical resources, system measurement points, event types, and trusted information flow paths.
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
A wide variety of security software competes for control of desktops, servers, and handhelds. Competition for control over a system's security posture can leave systems mired in a performance tar pit and subvert the very security they were meant to provide. Although the use of defense in-depth is widely recommended, it isn't nearly as automated as it could be, particularly when it comes to composing policy in addition to functionality. We suggest a paradigm in which security programmers intentionally design their code to cooperate with similar software by negotiating over security-critical resources, system measurement points, event types, and trusted information flow paths.
Key concepts: Negotiation, Computer security, Software security assurance, Computer science, Variety (cybernetics), Software, Event (particle physics), Server