You'll see this message when it is too late: The Legal and Economic Aftermath of Cybersecurity Breaches (Information Policy)
暫譯: 當一切為時已晚時你會看到這則訊息:網路安全漏洞的法律與經濟後果(資訊政策)
Josephine Wolff
相關主題
商品描述
What we can learn from the aftermath of cybersecurity breaches and how we can do a better job protecting online data.
Cybersecurity incidents make the news with startling regularity. Each breach―the theft of 145.5 million Americans' information from Equifax, for example, or the Russian government's theft of National Security Agency documents, or the Sony Pictures data dump―makes headlines, inspires panic, instigates lawsuits, and is then forgotten. The cycle of alarm and amnesia continues with the next attack, and the one after that. In this book, cybersecurity expert Josephine Wolff argues that we shouldn't forget about these incidents, we should investigate their trajectory, from technology flaws to reparations for harm done to their impact on future security measures. We can learn valuable lessons in the aftermath of cybersecurity breaches.
Wolff describes a series of significant cybersecurity incidents between 2005 and 2015, mapping the entire life cycle of each breach in order to identify opportunities for defensive intervention. She outlines three types of motives underlying these attacks―financial gain, espionage, and public humiliation of the victims―that have remained consistent through a decade of cyberattacks, offers examples of each, and analyzes the emergence of different attack patterns. The enormous TJX breach in 2006, for instance, set the pattern for a series of payment card fraud incidents that led to identity fraud and extortion; the Chinese army conducted cyberespionage campaigns directed at U.S.-based companies from 2006 to 2014, sparking debate about the distinction between economic and political espionage; and the 2014 breach of the Ashley Madison website was aimed at reputations rather than bank accounts.
商品描述(中文翻譯)
**我們可以從網路安全漏洞的後果中學到什麼,以及如何更好地保護線上數據。**
網路安全事件以驚人的頻率登上新聞。每一次漏洞事件——例如,從Equifax盜取1.455億美國人信息,或俄羅斯政府竊取國家安全局文件,或索尼影業的數據洩漏——都會成為頭條新聞,引發恐慌,激起訴訟,然後被遺忘。這種警報與健忘的循環隨著下一次攻擊而持續,然後是下一次。在這本書中,網路安全專家Josephine Wolff主張,我們不應該忘記這些事件,而應該調查它們的發展軌跡,從技術缺陷到對造成的損害的賠償,再到它們對未來安全措施的影響。我們可以在網路安全漏洞的後果中學到寶貴的教訓。
Wolff描述了2005年至2015年間一系列重要的網路安全事件,繪製每次漏洞的整個生命週期,以識別防禦介入的機會。她概述了這些攻擊背後的三種動機——財務利益、間諜活動和對受害者的公開羞辱——這些動機在十年的網路攻擊中始終如一,並提供了每種動機的例子,分析了不同攻擊模式的出現。例如,2006年的TJX大漏洞為一系列導致身份詐騙和勒索的支付卡詐騙事件設立了模式;中國軍方在2006年至2014年間對美國公司進行了網路間諜活動,引發了關於經濟間諜與政治間諜之間區別的辯論;而2014年Ashley Madison網站的漏洞則是針對名譽而非銀行賬戶。