【正文】
Own 八、電腦犯罪 ? 資訊時代的新威脅 ? 犯案時間縮短 ? 犯案區(qū)域擴增 ? 犯罪方法新穎 ? 資產型態(tài)改變 ? 犯案環(huán)境單純 八、電腦犯罪 ? 入侵電腦系統(tǒng)方式 ? 摧毀實體 ? 摧毀資訊 ? 竄改資訊 ? 偷用服務 ? 偷窺 ? 偷用資料 八、電腦犯罪 ? 犯案新方法 ? 清道夫 ? 混水摸魚 ? 社會心理 ? 篡改資料 ? 線路竊聽 ? 積少成多 ? 建立陷井 ? 邏輯炸彈 ? 木馬藏兵 ? 異步攻擊 ? 超級指令 ? 模擬 九、結論 ? 10 Commandments of Commercial Security Today ? Don’t aim for perfect security. So, be realistic, and do the best you can within your limits. Roughly, you should double security expenditure to halve risk. ? Don’t solve the wrong problem. For example, note that US banks lose 10 billion dollars a year in check fraud but only 5 million in online fraud. 九、結論 ? Don’t sell security bottomup ( in terms of the personnel hierarchy). ? Don’t use cryptographic overkill. Even bad crypto is usually the strong part of the system. ? Don’t make it plicated. This yields more places to attack the system, and it encourages users to find ways to bypass security. ? Don’t make it expensive. 九、結論 ? Don’t use a single line of defense. Have several layers so security can be maintained without expensive replacement of the primary line. ? Don’t fet the “mystery attack”. Be able to regenerate security even when you have no idea what’s going wrong. For example, smart cards are attackable but are great for quick cheap recovery. ? Don’t trust systems. ? Don’t trust people.