首页> 外文会议>IEEE/WIC/ACM International Conference on Intelligent Agent Technology >#x0022;Stacking the Deck#x0022; Attack on Software Updates: Solution by Distributed Recommendation of Testers
【24h】

#x0022;Stacking the Deck#x0022; Attack on Software Updates: Solution by Distributed Recommendation of Testers

机译:对软件更新的“堆叠式”攻击:测试人员的分布式推荐解决方案

获取原文

摘要

The discussed "Stacking the Deck" attack and our solution are relevant only to software controlled by loosely constituted communities. Developers can change their vision and abandon features that are essential for certain users. Moreover, well funded attackers can effectively take control of a project by orchestrating the transfer of the leadership of the developers to people that they control. We propose a mechanism to reduce the level of trust that users are required to have in the maintainers of free and open-source agent software. In fact, with the proposed method, it is sufficient for the user to trust that his constellation of independent testers are safe from attack, even as all testers may be subject to different attacks. Our solution inserts independent intermediaries (testers) between the developers and the end-users. To encourage independence of the testers, essential for the desired security, a distributed recommendation mechanism is employed, suggesting testers for end-users based on preferences of immediate connections, and on the frequency of usage of these testers in her neighborhood. Metrics of success and experiments for identifying promising parameters are reported.
机译:讨论中的“堆栈平台”攻击和我们的解决方案仅与由松散组成的社区控制的软件有关。开发人员可以更改他们的视野和放弃某些用户必不可少的功能。而且,资金充裕的攻击者可以通过协调开发人员的领导权转移到他们控制的人手中,从而有效地控制项目。我们提出一种机制,以减少要求用户在免费和开源代理软件的维护者中拥有的信任度。实际上,使用所提出的方法,即使所有测试人员可能遭受不同的攻击,也足以让用户相信他的独立测试人员的群不受攻击。我们的解决方案在开发人员和最终用户之间插入了独立的中介(测试人员)。为了鼓励测试人员的独立性,这是实现所需安全性所必需的,它采用了分布式推荐机制,根据即时连接的偏好以及这些测试人员在其邻域中的使用频率为最终用户建议测试人员。报告了成功的度量标准和用于确定有希望的参数的实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号