首页 > 最新文献

Journal of Information Systems Security最新文献

英文 中文
Katrina's Gift: A Wake-Up Call for Improved Disaster Planning 卡特里娜飓风的礼物:提高灾害规划的警钟
Q4 Social Sciences Pub Date : 2006-12-01 DOI: 10.1080/10658980601051839
R. Vedder
Abstract The forced evacuation in 2005 of two major U.S. cities provide an excellent opportunity for IT executives to take stock of their plans for disaster management. Your first reaction to this statement might be, “But my company doesn't operate anyplace where a major hurricane could strike.” Think again. Aside from potential urban paralysis caused by other natural events, such as a massive earthquake or F5 tornado, cities are prime targets for terrorism. In addition to biological and chemical attacks, terrorists could explode a radiological bomb in a major urban center. (A radiological bomb is not a nuclear weapon. It is an ordinary explosive device encased with highly radioactive particulate materials. The objective is to disperse these materials into the air and thus render many square miles of a city uninhabitable for years or even decades.) Because of terrorism and other threats, you and your IT department do have to worry about a possible mass urban evacuation.
2005年美国两个主要城市的强制疏散为IT管理人员评估他们的灾难管理计划提供了一个极好的机会。你对这句话的第一反应可能是,“但我的公司不会在大飓风可能袭击的地方运营。”再想想。除了大地震或5级龙卷风等自然事件可能造成的城市瘫痪外,城市还是恐怖主义的主要目标。除了生物和化学袭击,恐怖分子还可能在主要城市中心引爆放射性炸弹。(放射性炸弹不是核武器。这是一种普通的爆炸装置,用高放射性微粒材料包裹。目标是将这些物质分散到空气中,从而使城市的许多平方英里在数年甚至数十年内不适合居住。由于恐怖主义和其他威胁,您和您的IT部门确实需要担心可能的大规模城市疏散。
{"title":"Katrina's Gift: A Wake-Up Call for Improved Disaster Planning","authors":"R. Vedder","doi":"10.1080/10658980601051839","DOIUrl":"https://doi.org/10.1080/10658980601051839","url":null,"abstract":"Abstract The forced evacuation in 2005 of two major U.S. cities provide an excellent opportunity for IT executives to take stock of their plans for disaster management. Your first reaction to this statement might be, “But my company doesn't operate anyplace where a major hurricane could strike.” Think again. Aside from potential urban paralysis caused by other natural events, such as a massive earthquake or F5 tornado, cities are prime targets for terrorism. In addition to biological and chemical attacks, terrorists could explode a radiological bomb in a major urban center. (A radiological bomb is not a nuclear weapon. It is an ordinary explosive device encased with highly radioactive particulate materials. The objective is to disperse these materials into the air and thus render many square miles of a city uninhabitable for years or even decades.) Because of terrorism and other threats, you and your IT department do have to worry about a possible mass urban evacuation.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"80160740","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Securing Against Insider Attacks 防止内部攻击
Q4 Social Sciences Pub Date : 2006-11-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95430.6
D. M. Lynch
Abstract We are all creatures of habit; the way we think and the views we take are conditioned by our education, society as a whole, and, at a much deeper level, our cultural memories or instinct.
我们都是有习惯的生物;我们的思维方式和观点是由我们的教育、整个社会以及更深层次的文化记忆或本能决定的。
{"title":"Securing Against Insider Attacks","authors":"D. M. Lynch","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95430.6","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95430.6","url":null,"abstract":"Abstract We are all creatures of habit; the way we think and the views we take are conditioned by our education, society as a whole, and, at a much deeper level, our cultural memories or instinct.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"81608406","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 9
Information Security Tradeoffs: The User Perspective 信息安全权衡:用户视角
Q4 Social Sciences Pub Date : 2006-11-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95428.4
Gerald V. Post, A. Kagan
Abstract When taking a typical approach to computer security, one could make the following relatively extreme statements: A piece of data can be rendered completely secure with 100 percent assurance. Simply write the data on a piece of paper, burn the paper, and scatter the ashes. No one will be able to read or alter that data ever again. Of course, this exercise and the underlying premise are a trick. Understanding the deception is the key to understanding information security: Data that is being “protected” has to remain available to legitimate users. There is a strong tendency for information security researchers and practitioners to focus on “securing” data by preventing attacks and loss of data. An IS practitioner's job might depend on preventing and recovering from security-related problems. However, increased monitoring and enhanced use of security controls can easily lead to interference and delays of information usage for legitimate users.
当采取一种典型的计算机安全方法时,人们可以做出以下相对极端的陈述:一条数据可以100%保证完全安全。简单地把数据写在一张纸上,烧掉纸,撒上灰烬。再也没有人能读取或修改这些数据了。当然,这个练习和潜在的前提是一个技巧。理解欺骗是理解信息安全的关键:被“保护”的数据必须对合法用户保持可用性。对于信息安全研究人员和从业者来说,有一种强烈的趋势是通过防止攻击和数据丢失来关注“保护”数据。信息系统从业者的工作可能取决于预防和从安全相关问题中恢复。但是,增加监视和增强安全控制的使用很容易导致合法用户使用信息的干扰和延迟。
{"title":"Information Security Tradeoffs: The User Perspective","authors":"Gerald V. Post, A. Kagan","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95428.4","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95428.4","url":null,"abstract":"Abstract When taking a typical approach to computer security, one could make the following relatively extreme statements: A piece of data can be rendered completely secure with 100 percent assurance. Simply write the data on a piece of paper, burn the paper, and scatter the ashes. No one will be able to read or alter that data ever again. Of course, this exercise and the underlying premise are a trick. Understanding the deception is the key to understanding information security: Data that is being “protected” has to remain available to legitimate users. There is a strong tendency for information security researchers and practitioners to focus on “securing” data by preventing attacks and loss of data. An IS practitioner's job might depend on preventing and recovering from security-related problems. However, increased monitoring and enhanced use of security controls can easily lead to interference and delays of information usage for legitimate users.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"76613279","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 6
Implementing Security Metrics Initiatives 实施安全度量措施
Q4 Social Sciences Pub Date : 2006-11-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95429.5
Elizabeth A. Nichols, Andrew Sudbury
Abstract Although Global 2000 organizations today are becoming increasingly aware of the importance of a metrics program to maximize the effectiveness of an information security strategy, there's little guidance available around the practical “how to's” of putting such a program into practice. As a result, security metrics are shrouded in mystery and are considered “too hard” to do—with the end result being that this necessary and effective management tool has yet to be implemented at many organizations, and in the organizations where it has been launched, it has yet to be automated to ease management and reduce resource costs.
尽管全球2000强企业越来越意识到度量程序对于最大化信息安全策略有效性的重要性,但关于如何将此类程序付诸实践的实用指南却很少。因此,安全度量被笼罩在神秘之中,被认为“太难”——最终的结果是,这个必要而有效的管理工具还没有在许多组织中实现,在已经启动它的组织中,它还没有自动化,以简化管理并降低资源成本。
{"title":"Implementing Security Metrics Initiatives","authors":"Elizabeth A. Nichols, Andrew Sudbury","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95429.5","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95429.5","url":null,"abstract":"Abstract Although Global 2000 organizations today are becoming increasingly aware of the importance of a metrics program to maximize the effectiveness of an information security strategy, there's little guidance available around the practical “how to's” of putting such a program into practice. As a result, security metrics are shrouded in mystery and are considered “too hard” to do—with the end result being that this necessary and effective management tool has yet to be implemented at many organizations, and in the organizations where it has been launched, it has yet to be automated to ease management and reduce resource costs.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"77196859","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 3
Measuring Security 测量安全
Q4 Social Sciences Pub Date : 2006-11-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95426.2
Abe Kleinfeld
Abstract Ask a CEO a very broad question such as, “How is your company doing?” and he or she is likely lo rattle off concise metrics describing revenue, earnings per share, gross margin, and market share. These few metrics, measured over time, provide a surprisingly clear picture of the health and well-being of a company and whether its prospects are improving or deteriorating. However, ask that same CEO a far narrower question: “How secure is your network?” and you're likely to be met with a blank stare.
问CEO一个非常宽泛的问题,比如“你的公司怎么样?”他或她可能会脱口而出一些简洁的指标,包括收入、每股收益、毛利率和市场份额。随着时间的推移,这几个指标可以提供一幅令人惊讶的清晰画面,显示一家公司的健康和福祉,以及它的前景是在改善还是在恶化。然而,你可以问这位CEO一个更狭隘的问题:“你的网络有多安全?”你可能会被茫然地盯着看。
{"title":"Measuring Security","authors":"Abe Kleinfeld","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95426.2","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95426.2","url":null,"abstract":"Abstract Ask a CEO a very broad question such as, “How is your company doing?” and he or she is likely lo rattle off concise metrics describing revenue, earnings per share, gross margin, and market share. These few metrics, measured over time, provide a surprisingly clear picture of the health and well-being of a company and whether its prospects are improving or deteriorating. However, ask that same CEO a far narrower question: “How secure is your network?” and you're likely to be met with a blank stare.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"84159558","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Password Security: An Empirical Investigation into E-Commerce Passwords and Their Crack Times 密码安全:电子商务密码及其破解时间的实证研究
Q4 Social Sciences Pub Date : 2006-11-01 DOI: 10.1080/10658980601051318
J. Cazier, B. Medlin
Abstract Strong passwords are essential to the security of any e-commerce site as well as to individual users. Without them, hackers can penetrate a network and stop critical processes that assist consumers and keep companies operating. For most e-commerce sites, consumers have the responsibility of creating their own passwords and often do so without guidance from the web site or system administrator. One fact is well known about password creation—consumers do not create long or complicated passwords because they cannot remember them. Through an empirical analysis, this paper examines whether the passwords created by individuals on an e-commerce site use either positive or negative password practices. This paper also addresses the issue of crack times in relationship to password choices. The results of this study will show the actual password practices of current consumers, which could enforce the need for systems administrators to recommend secure password practices on e-commerce sites and in general.
强密码对于任何电子商务网站和个人用户的安全都是必不可少的。如果没有它们,黑客就可以渗透到网络中,停止帮助消费者和维持公司运营的关键进程。对于大多数电子商务网站,用户有责任创建自己的密码,而且通常在没有网站或系统管理员指导的情况下这样做。关于密码创建有一个众所周知的事实——用户不会创建长或复杂的密码,因为他们记不住。通过实证分析,本文考察了个人在电子商务网站上创建的密码是否使用了积极或消极的密码实践。本文还讨论了与密码选择有关的破解时间问题。这项研究的结果将显示当前消费者的实际密码实践,这可能会强制要求系统管理员在电子商务网站和一般情况下推荐安全的密码实践。
{"title":"Password Security: An Empirical Investigation into E-Commerce Passwords and Their Crack Times","authors":"J. Cazier, B. Medlin","doi":"10.1080/10658980601051318","DOIUrl":"https://doi.org/10.1080/10658980601051318","url":null,"abstract":"Abstract Strong passwords are essential to the security of any e-commerce site as well as to individual users. Without them, hackers can penetrate a network and stop critical processes that assist consumers and keep companies operating. For most e-commerce sites, consumers have the responsibility of creating their own passwords and often do so without guidance from the web site or system administrator. One fact is well known about password creation—consumers do not create long or complicated passwords because they cannot remember them. Through an empirical analysis, this paper examines whether the passwords created by individuals on an e-commerce site use either positive or negative password practices. This paper also addresses the issue of crack times in relationship to password choices. The results of this study will show the actual password practices of current consumers, which could enforce the need for systems administrators to recommend secure password practices on e-commerce sites and in general.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"74918870","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 65
Social Engineering: Concepts and Solutions 社会工程:概念和解决方案
Q4 Social Sciences Pub Date : 2006-11-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95427.3
Thomas R. Peltier
Abstract Social engineering attacks are usually conducted by outsiders who use a variety of psychological tricks to get the computer user to give them the information they need to access a computer or network. Do not be confused about the concept of “outsiders.” Although the true outside hackers get the headlines, the far more prevalent form of social engineering is conducted by one employee on another employee.
社会工程攻击通常是由外部人员进行的,他们使用各种心理技巧让计算机用户给他们访问计算机或网络所需的信息。不要对“外人”的概念感到困惑。尽管真正的外部黑客占据了新闻头条,但更为普遍的社会工程形式是由一名员工对另一名员工实施的。
{"title":"Social Engineering: Concepts and Solutions","authors":"Thomas R. Peltier","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95427.3","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95427.3","url":null,"abstract":"Abstract Social engineering attacks are usually conducted by outsiders who use a variety of psychological tricks to get the computer user to give them the information they need to access a computer or network. Do not be confused about the concept of “outsiders.” Although the true outside hackers get the headlines, the far more prevalent form of social engineering is conducted by one employee on another employee.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"81661313","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 9
Protecting Your Internal Resources with Intranet Application Firewalls 使用Intranet应用防火墙保护内部资源
Q4 Social Sciences Pub Date : 2006-11-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95431.7
Alan Murphy
Abstract Web application firewalls (WAFs) are rapidly becoming a key component of end-to-end network security. Although the market is still struggling to move beyond the early adopter stages, WAF placement in the network is now well known and generally accepted as a necessary requirement. When looking at total security architecture, securing public Web applications over ports 80 and 443 is the next logical step to perimeter security: the concept of restricting access from the outside to the resources on the inside. Coupled with network firewalls, HTTP application firewalls can close perimeter security holes opened by allowing unrestricted access to public Web servers. Bui focusing solely on external, public application security is only half of the solution. Internal Web-based applications, such as corporate intranets, HR systems, CRM systems, HTTP-based databases, and report management applications, can also be al risk for the same open-access reasons, but from trusted internal attackers.
Web应用防火墙(waf)正迅速成为端到端网络安全的关键组成部分。尽管市场仍在努力超越早期采用者阶段,WAF在网络中的放置现在是众所周知的,并且被普遍接受为必要的要求。在查看整个安全体系结构时,保护端口80和443上的公共Web应用程序是外围安全的下一个合乎逻辑的步骤:限制从外部访问内部资源的概念。与网络防火墙相结合,HTTP应用程序防火墙可以通过允许对公共Web服务器的无限制访问来关闭外围安全漏洞。但是,仅仅关注外部、公共应用程序的安全性只是解决方案的一半。内部基于web的应用程序,如公司内部网、人力资源系统、CRM系统、基于http的数据库和报告管理应用程序,也可能由于相同的开放访问原因而面临风险,但是来自受信任的内部攻击者。
{"title":"Protecting Your Internal Resources with Intranet Application Firewalls","authors":"Alan Murphy","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95431.7","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95431.7","url":null,"abstract":"Abstract Web application firewalls (WAFs) are rapidly becoming a key component of end-to-end network security. Although the market is still struggling to move beyond the early adopter stages, WAF placement in the network is now well known and generally accepted as a necessary requirement. When looking at total security architecture, securing public Web applications over ports 80 and 443 is the next logical step to perimeter security: the concept of restricting access from the outside to the resources on the inside. Coupled with network firewalls, HTTP application firewalls can close perimeter security holes opened by allowing unrestricted access to public Web servers. Bui focusing solely on external, public application security is only half of the solution. Internal Web-based applications, such as corporate intranets, HR systems, CRM systems, HTTP-based databases, and report management applications, can also be al risk for the same open-access reasons, but from trusted internal attackers.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"82974628","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
MetaFisher: Next–Generation Bots and Phishing MetaFisher:下一代机器人和网络钓鱼
Q4 Social Sciences Pub Date : 2006-10-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95425.1
Ken Dunham
Abstract MetaFisher is a little-known code to most, yet it is one of the most important as we consider current-day and future threats. It's the most sophisticated bot ever developed. It utilizes a PHP command and control interface to monitor, update, and control bots. This is a pull technique instead of the traditional push technique utilized within IRC. Additionally, it contains sophisticated phishing attacks that dynamically inject HTML into targeted banking sites to steal information from the victim. MetaFisher is a cause for alarm, revealing the sophistication behind criminal fraud and hacker-for-hire situations that have matured over the past few years on the Internet.
对于大多数人来说,MetaFisher是一个鲜为人知的代码,但当我们考虑当前和未来的威胁时,它是最重要的代码之一。这是有史以来最复杂的机器人。它利用PHP命令和控制界面来监视、更新和控制机器人。这是一种pull技术,而不是IRC中使用的传统push技术。此外,它还包含复杂的网络钓鱼攻击,动态地将HTML注入目标银行站点以窃取受害者的信息。MetaFisher引起了人们的警惕,它揭示了过去几年互联网上犯罪欺诈和雇佣黑客的情况背后的复杂性。
{"title":"MetaFisher: Next–Generation Bots and Phishing","authors":"Ken Dunham","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95425.1","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95425.1","url":null,"abstract":"Abstract MetaFisher is a little-known code to most, yet it is one of the most important as we consider current-day and future threats. It's the most sophisticated bot ever developed. It utilizes a PHP command and control interface to monitor, update, and control bots. This is a pull technique instead of the traditional push technique utilized within IRC. Additionally, it contains sophisticated phishing attacks that dynamically inject HTML into targeted banking sites to steal information from the victim. MetaFisher is a cause for alarm, revealing the sophistication behind criminal fraud and hacker-for-hire situations that have matured over the past few years on the Internet.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"79520648","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
Securing RFID Applications: Issues, Methods, and Controls 保护RFID应用:问题,方法和控制
Q4 Social Sciences Pub Date : 2006-09-01 DOI: 10.1201/1086.1065898X/46353.15.4.20060901/95123.5
Stuart C. K. So, John J. Liu
Abstract Radio frequency identification (RFID) is an automatic identification (auto- ID) technology developed by the Auto-ID Center at the Massachusetts Institute of Technology, relying on storing and remotely retrieving data using devices called RFID tags and readers (Auto-ID Center, 2002; Doyle, 2004; EPC, 2004b; Finkenzeller, 2000; Shepard, 2005). With RFID technology, physical assets will have embedded intelligence that allows them to communicate with each other and with the tracking points (Auto-ID Center, 2002; IBM, 2003; VeriSign, 2004).
摘要射频识别(RFID)是由麻省理工学院的自动识别中心开发的一种自动识别(auto- ID)技术,依靠使用称为RFID标签和读取器的设备存储和远程检索数据(auto- ID Center, 2002;柯南道尔,2004;EPC, 2004 b;Finkenzeller, 2000;谢泼德,2005)。有了RFID技术,实物资产将具有嵌入式智能,使它们能够相互通信,并与跟踪点通信(自动识别中心,2002;IBM, 2003;VeriSign, 2004)。
{"title":"Securing RFID Applications: Issues, Methods, and Controls","authors":"Stuart C. K. So, John J. Liu","doi":"10.1201/1086.1065898X/46353.15.4.20060901/95123.5","DOIUrl":"https://doi.org/10.1201/1086.1065898X/46353.15.4.20060901/95123.5","url":null,"abstract":"Abstract Radio frequency identification (RFID) is an automatic identification (auto- ID) technology developed by the Auto-ID Center at the Massachusetts Institute of Technology, relying on storing and remotely retrieving data using devices called RFID tags and readers (Auto-ID Center, 2002; Doyle, 2004; EPC, 2004b; Finkenzeller, 2000; Shepard, 2005). With RFID technology, physical assets will have embedded intelligence that allows them to communicate with each other and with the tracking points (Auto-ID Center, 2002; IBM, 2003; VeriSign, 2004).","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0,"publicationDate":"2006-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"72587608","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 20
期刊
Journal of Information Systems Security
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1