Centro de Documentação da PJ | ||||
| GOODMAN, Seymour E., e outro Toward a safer and more secure cyberspace [Documento electrónico] / ed. Seymour E. Goodman, ed. Herbert S. Lin ; Committee on Improving Cybersecurity Research in the United States.- Washington, DC : National Academies Press, 2007.- 1 CD-ROM ; 12 cm Ficheiro de 1,58 MB em formato PDF (328 p.). ISBN 0-309-66741-0 SEGURANÇA INFORMÁTICA, MEDIDAS DE SEGURANÇA, CRIME INFORMÁTICO, CIBERTERRORISMO, TECNOLOGIA DA INFORMAÇÃO Executive summary. Part I Setting the stage. 1 Introduction. 1.1 The report in brief. 1.2 Background of the study. 2 What is at stake ? 2.1 Interconnected information technology everywhere, all the time. 2.2 The nature of cybersecurity vulnerabilities. 2.3 Systems and networks at risk. 2.3.1 Attacks on the internet. 2.3.2 Attacks on embedded/real-time computing and control systems. 2.3.3 Attacks on dedicated computing facilities. 2.4 Potential consequences of exploits. 2.5 The magnitude of the threat against today’s technologies. 2.6 An ominous future. 2.6.1 The evolution of the threat. 2.6.2 The broad range of capabilities and goals of cyberattackers. 3 Improving the Nation ’s cybersecurity posture. 3.1 The cybersecurity bill of rights. 3.1.1 Introduction to the cybersecurity bill of rights. 3.1.2 The provisions of the cybersecurity bill of rights. 3.1.3 Concluding comments. 3.2 Realizing the vision. 3.3 The necessity of research. 3.4 Principles to shape the Research Agenda. 3.4.1 Principle 1: Conduct cybersecurity research as though its application will be important. 3.4.2 Principle 2: Hedge against uncertainty in the nature of the future threat. 3.4.3 Principle 3: Ensure programmatic continuity in the research agenda. 3.4.4 Principle 4: Respect the need for breadth in the research agenda. 3.4.5 Principle 5: Disseminate new knowledge and artifacts. Part II An illustrative research agenda. 4 Category 1—Blocking and limiting the impact of compromise. 4.1 Secure design, development, and testing. 4.1.1 Research to support design. 4.1.2 Research to support development. 4.1.3 Research to support testing and evaluation. 4.2 Graceful degradation and recovery. 4.2.1 Containment. 4.2.2 Recovery. 4.3 Software and systems assurance. 5 Category 2—Enabling accountability. 5.1 Attribution. 5.2 Misuse and anomaly detection systems. 5.3 Digital Rights Management. 6 Category 3—Promoting deployment. 6.1 Usable security. 6.2 Exploitation of previous work. 6.3 Cybersecurity metrics. 6.4 The Economics of cybersecurity. 6.4.1 Conflicting Interests and incentives among the actors in cybersecurity. 6.4.2 Risk assessment in cybersecurity. 6.4.3 The nature and extent of market failure (if any) in cybersecurity. 6.4.4 Changing business cases and altering the market calculus. 6.5 Security policies. 7 Category 4—Deterring would -be attackers and penalizing attackers. 7.1 Legal issues related to cybersecurity. 7.2 Honeypots. 7.3 Forensics. 8 Category 5—Illustrative crosscutting. Problem-focused research areas. 8.1 Security for legacy systems. 8.2 The role of secrecy in cyberdefense. 8.3 Insider threats. 8.4 Security in nontraditional computing environments and in the context of use. 8.4.1 Health information technology. 8.4.2 The electric power grid. 8.4.3 Web services. 8.4.4 Pervasive and embedded systems. 8.5 Secure network architectures. 8.6 Attack characterization. 8.7 Coping with denial-of-service attacks. 8.7.1 The nature of denial-of-service attacks. 8.7.2 Responding to distributed denial-of-service attacks. 8.7.3 Research challenges. 8.8 Dealing with spam. 9 Category 6—Speculative research. 9.1 A cyberattack research activity. 9.2 Biological approaches to security. 9.3 Using attack techniques for defensive purposes. 9.4 Cyber-retaliation. Part III Conclusion. 10 Looking to the future. 10.1 Why has little action occurred? 10.2 Priorities for action. 10.2.1 Item 1: Create a sense of urgency about the cybersecurity problem commensurate with the risks. 10.2.2 Item 2: Commensurate with a rapidly growing cybersecurity threat, support a robust and sustained research agenda at levels which ensure that a large fraction of good ideas for cybersecurity research can be explored. 10.2.3 Item 3: Establish a mechanism for continuing follow-up on a research agenda. 10.2.4 Item 4: Support infrastructure for cybersecurity research. 10.2.5 Item 5: Sustain and grow the human resource base. 10.3 Concluding comments. APPENDIXES: A Committee and staff biographies. B Cybersecurity reports and policy: the recent past. B.1 Introduction. B.2 Cybersecurity policy activity since 2001. B.3 Identifying exposures, best practices, and procedures. B.4 Public-Private collaboration, coordination, and cooperation. B.4.1 Information sharing and Analysis Centers. B.4.2 Alliances and partnerships. B.4.3 Private-Sector support for cybersecurity research in Academia. B.5 Notable recent efforts at identifying a Research Agenda. B.6 The current federal research and development landscape. B.6.1 The nature of supported activity in cybersecurity. B.6.2 Interagency cooperation and coordination. B.6.3 Research focus areas. B.6.4 Agency specifics. C Contributors to the study. |