Towards Community Standards for Ethical Behavior in Computer Security Research
David Dittrich, Michael Q. Bailey, Sven Dietrich · 2009
Since the first distributed attack networks were seen in 1999, computer misuse enabled by botnets, worms, and other vectors has steadily grown. This rapid growth has given rise to a variety of ethical challenges for researchers seeking to combat these threats. For example, if someone has the ability to take control of a botnet, can they just clean up all the infected hosts? Can we deceive users, if our goal is to better understand how they are deceived by attackers? Can we demonstrate the need for better methods, by breaking something that people rely on today? When one considers the implications of something like botnet cleanup – the blind modification and possible rebooting of thousands of computers without their owners ’ knowledge or consent – this complexity becomes all the more obvious. To be effective, we must find ways to balance societal needs and the ethical issues surrounding our efforts, lest we drift to the extremes— becoming the very thing we deplore, or ceding the Internet to the miscreants because we fear to act. In this paper, we endeavor to create a dialogue on the ethical issues in computer security and the ethical standards that we intend to enforce as a community. 1.