Notice bibliographique
Résumé
Software installation and updates have become simpler for end users in recent years.The commoditization of the internet has enabled users to obtain more software than ever before from more developers than ever before.Additionally, software installation now requires less input from users, allowing installation with merely a single click or tap.At the same time, different software installation models with varying levels of security, usability and freedom have emerged.In centralized environments, available software is limited by an authority, whereas decentralized environments allow users and developers to interact freely.Decentralized software installation ecosystems pose the most significant security challenges due to the lack of centralized control.In this thesis we identify, through the systematic evaluation of prominent systems, limitations in the way operating systems provide security guarantees (including verification of integrity and authentication, and establishment of trust) in decentralized software installation environments.We address these limitations by designing tools and protocols that help secure software installation and updates at each of the three installation stages (software discovery, initial install and updates, and enforcing security policies).Specifically, we propose a cryptographically verifiable protocol for developers to delegate digital signature privileges to other certificates (possibly owned by other developers) without requiring a centrally trusted public key infrastructure.Our proposal allows trust to be delegated during software updates without user involvement.We also propose a flexible policy for developers to authenticate and share privileges amongst applications being executed simultaneously on a device.We evaluate these proposals and show that they are direct improvements over currently deployed real-world systems.We discuss the design and implementation of an install-time architecture that allows users to query crowdsourced expert information sources to gain trust in software they are about to install.We motivate the requirements for such a system, designed to mirror the security semantics provided by centralized environments.The proposed protocols and tools have been implemented as proofs-of-concept using Google's Android mobile operating system.We leverage a large application dataset to inform our design decisions and demonstrate backward compatibility with existing applications.While the implementations are specific to Android, we discuss how our general proposals extend to other decentralized environments.iii I owe thanks to my wife Elizabeth for her love and patience during the many (and often stressful) milestones of my doctorate.Elizabeth was a constant reminder that there was life outside the university walls.I'd like to thank my mom for always checking in on me despite living 3600 Km away.It is always comforting to know that my mom is thinking about me, no matter how far I am.I also owe thanks to my father (the other Dr. Barrera) for always asking about the details of my research and showing great interest in my progress as an academic.And of course to my sisters who always provided their unconditional support.I'm grateful to Daniel McCarney, Jeremy Clark, and William Enck who helped with the papers that eventually made up this dissertation.I could not have produced this document without their hard work, insight, and discussion.A special mention to Glenn Wurster and Mohammad
Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.
Comment cette classification a été obtenuedéplier
Prédiction machine sur la base complète
Imitation des enseignantsNi prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.
Scores du classifieur distillé par catégorie (deux têtes)
| Catégorie | Codex | Gemma |
|---|---|---|
| Métarecherche | 0,007 | 0,038 |
| Méta-épidémiologie (sens strict) | 0,001 | 0,001 |
| Méta-épidémiologie (sens large) | 0,001 | 0,000 |
| Bibliométrie | 0,001 | 0,001 |
| Études des sciences et des technologies | 0,002 | 0,002 |
| Communication savante | 0,004 | 0,009 |
| Science ouverte | 0,002 | 0,007 |
| Intégrité de la recherche | 0,002 | 0,003 |
| Charge utile insuffisante (le modèle a refusé de juger) | 0,003 | 0,005 |
Scores machine (provisoires)
Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.
Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.
score_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découleClassification
machine, non validéePrédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.
Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».