Securing With the Enemy: Social Strategy and Teams of Rivals

No ratings

Presented at ShakaCon 2009 by

While computer science is not traditionally viewed as a social science, problems in its  domain  are  inherently  social  in  nature ‐ relating  to  people,  their  interactions  and  the  relationships between them and their organizational contexts. The broad scope of the field  of "security engineering" and increasing recognition that economics and psychology are  integral parts of security are good examples of this, but only begin to scratch the surface.  We will present this unexpected new lens and examine the two areas of economics and  psychology  in  security,  extracting  insights  and generalizing  concepts  to  help  attendees  understand how these perspectives might be useful in their own roles.  Sarah Blankinship will introduce the perspective and explain its application in the Microsoft  security  ecosystem  over  the  last  few  years.  Sarah  is  a  Senior  Security  Strategist,  an  'EcoStrategist', leading the Security Ecosystem Strategy team within the Microsoft Security  Response  Center  (MSRC)  to  engage  security  communities  from  around  the  world  to  research and respond to software vulnerabilities.   Jon Pincus will apply the similar perspective of social science theories to the field of static  analysis as it relates to security. Jon's return to static analysis (he was architect of PREFix  and PREfast from 1995‐2001) provides an opportunity for unique perspective, highlighting  where progress has been made, where it hasn't, and identifying remaining barriers to  pervasive deployment of static analysis tools ‐‐ in particular, user interface challenges for  defect understanding and work‐in‐context. Developments in disciplines like "gender HCI"  and  captology  may  offer  paths  forward.  At  the  same  time,  efforts  like  SAMATE  and  Coverity's Scan are building the social infrastructure to the community as a whole to follow  the lead of the security research community and incorporate an explicit ecosystem focus.  The important theme to discuss is opportunities for shared goals and cooperation from  organizations  and  people  usually  seen  as  rivals:  security  researchers  and  software  engineers, developers and security auditors, employees of bitter competitors. In many  situations,  well‐chosen  "teams  of  rivals"  strategies  ‐‐  while  easy  to  overlook  ‐‐  offer  substantial benefits and positive‐sum outcomes. We'll close the session by showing how to  apply this approach to several timely challenges in the computer security field.