Design Principles and Patterns for Computer Systems That Are Simultaneously Secure and Usable 1st edition by Simson Garfinkel ISBN 0130171057 978-0130171052

Original price was: $50.00.Current price is: $35.00.

Authors:Simson Garfinkel , Series:Cyber Security [100] , Tags:Secure design patterns; software security; Secure coding , Author sort:Garfinkel, Simson , Languages:Languages:eng , Published:Published:Apr 2005 , Publisher:Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science , Comments:Comments:It is widely believed that security and usability are two antagonistic goals in system design. This thesis argues that there are many instances in which security and usability can be synergistically improved by revising the way that specific functionality is implemented in many of today’s operating systems and applications. Specific design principles and patterns are presented that can accomplish this goal. Patterns are presented that minimize the release of confidential information through remnant and remanent data left on hard drives, in web browsers, and in documents. These patterns are based on a study involving the purchase of 236 hard drives on the secondary market, interviews conducted with organizations whose drives had been acquired, and through a detailed examination of modern web browsers and reports of information leakage in documents. Patterns are presented that enable secure messaging through the adoption of new key management techniques. These patterns are supported through an analysis of S/MIME handling in modern email clients, a survey of 469 Amazon.com merchants, and a user study of 43 individuals. Patterns are presented for promoting secure operation and for reducing the danger of covert monitoring. These patterns are supported by the literature review and an analysis of current systems.