Trusted recovery

Sushil Jajodia, Catherine D. McCollum, Paul Ammann · Communications of the ACM · 1999

To protect a system against information warfare, it is of course necessary to take steps to prevent attacks from succeeding.At the same time, however, it is important to recognize that not all attacks can be averted at the outset.Attacks that succeed to some degree are unavoidable, and comprehensive support for identifying and responding to attacks is required [1].Information warfare defense must consider the whole process of attack, response, and recovery.This requires a recognition of the multiple phases of the information warfare process.Prevention is just one phase; we explain others and then focus on the oft- JAMES GARYRecent exploits by hackers have drawn attention to the importance of defending against potential information warfare.Defense and civil institutions rely so heavily on their information systems and networks that attacks that disable them could be devastating.Yet, as hacker attacks have demonstrated, protective mechanisms are fallible.Features and services that must be in place to carry out needed, legitimate functions can be abused by being used in unexpected ways to provide an avenue of attack.Further, an attacker who penetrates one system can use its relationships with other systems on the network to compromise them as well.Experiences of actual attacks have led to the recognition of the need to detect and react to attacks that succeed in breaching a system's protective mechanisms.

Read the paper · More papers on PaperTik