Observations on information security crisis
Jussipekka Leiwo · 1999
Despite a wide body of academic knowledge of secure information systems, application software, communication protocols and cryptographic primitives remain insecure. This is especially alarming in the emerge of application domains and organisational structures that depend heavily on the availability of reliable and secure data communication infrastructure, such as electronic commerce. A survey of recently reported vulnerabilities demonstrates that systems remain susceptible to attacks known for decades. The lack of security awareness among system and protocol designers and therefore occurring security problems are called the information security crisis. This paper surveys the symptoms and causes of information security crisis, and sketches an outline of an approach required for tackling the crisis. Keywords: Data security, Computer communication systems BRT Keywords: USE, UF Introduction Since the information theory based cryptography by Shannon (1949) and the public key cryptography...