MétaCan
Menu
Retour à la cohorte
Enregistrement W2523880200 · doi:10.22215/etd/2014-10421

Securing Decentralized Software Installation and Updates

2014· dissertation· en· W2523880200 sur OpenAlexaff
David Barrera

Notice bibliographique

Revuenon disponible
Typedissertation
Langueen
DomaineComputer Science
ThématiqueAdvanced Malware Detection Techniques
Établissements canadiensCarleton University
Organismes subventionnairesnon disponible
Mots-clésComputer scienceComputer securityDelegateSoftwareTrusted Platform ModuleSoftware security assuranceAuthentication (law)Software deploymentWorld Wide WebSoftware engineeringOperating systemSecurity serviceInformation security

Résumé

récupéré en direct d'OpenAlex

Software installation and updates have become simpler for end users in recent years.The commoditization of the internet has enabled users to obtain more software than ever before from more developers than ever before.Additionally, software installation now requires less input from users, allowing installation with merely a single click or tap.At the same time, different software installation models with varying levels of security, usability and freedom have emerged.In centralized environments, available software is limited by an authority, whereas decentralized environments allow users and developers to interact freely.Decentralized software installation ecosystems pose the most significant security challenges due to the lack of centralized control.In this thesis we identify, through the systematic evaluation of prominent systems, limitations in the way operating systems provide security guarantees (including verification of integrity and authentication, and establishment of trust) in decentralized software installation environments.We address these limitations by designing tools and protocols that help secure software installation and updates at each of the three installation stages (software discovery, initial install and updates, and enforcing security policies).Specifically, we propose a cryptographically verifiable protocol for developers to delegate digital signature privileges to other certificates (possibly owned by other developers) without requiring a centrally trusted public key infrastructure.Our proposal allows trust to be delegated during software updates without user involvement.We also propose a flexible policy for developers to authenticate and share privileges amongst applications being executed simultaneously on a device.We evaluate these proposals and show that they are direct improvements over currently deployed real-world systems.We discuss the design and implementation of an install-time architecture that allows users to query crowdsourced expert information sources to gain trust in software they are about to install.We motivate the requirements for such a system, designed to mirror the security semantics provided by centralized environments.The proposed protocols and tools have been implemented as proofs-of-concept using Google's Android mobile operating system.We leverage a large application dataset to inform our design decisions and demonstrate backward compatibility with existing applications.While the implementations are specific to Android, we discuss how our general proposals extend to other decentralized environments.iii I owe thanks to my wife Elizabeth for her love and patience during the many (and often stressful) milestones of my doctorate.Elizabeth was a constant reminder that there was life outside the university walls.I'd like to thank my mom for always checking in on me despite living 3600 Km away.It is always comforting to know that my mom is thinking about me, no matter how far I am.I also owe thanks to my father (the other Dr. Barrera) for always asking about the details of my research and showing great interest in my progress as an academic.And of course to my sisters who always provided their unconditional support.I'm grateful to Daniel McCarney, Jeremy Clark, and William Enck who helped with the papers that eventually made up this dissertation.I could not have produced this document without their hard work, insight, and discussion.A special mention to Glenn Wurster and Mohammad

Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.

Comment cette classification a été obtenuedéplier

Prédiction machine sur la base complète

Imitation des enseignants

Ni prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.

score de la tête « metaresearch » (Codex)0,007
score de la tête « metaresearch » (Gemma)0,038
Version: metacan-v3-hybrid-931329e0061cStatut de validation: machine_predicted_unvalidated
Catégories candidatesaucune
Catégories consensuellesaucune
DomaineSignal candidat: aucune · Signal consensuel: aucune
Devis d'étudeSignal candidat: Sans objet · Signal consensuel: aucune
GenreSignal candidat: Autre · Signal consensuel: aucune
Score de désaccord entre enseignants0,007
Score d'incertitude au seuil0,036

Scores du classifieur distillé par catégorie (deux têtes)

CatégorieCodexGemma
Métarecherche0,0070,038
Méta-épidémiologie (sens strict)0,0010,001
Méta-épidémiologie (sens large)0,0010,000
Bibliométrie0,0010,001
Études des sciences et des technologies0,0020,002
Communication savante0,0040,009
Science ouverte0,0020,007
Intégrité de la recherche0,0020,003
Charge utile insuffisante (le modèle a refusé de juger)0,0030,005

Scores machine (provisoires)

Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.

Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.

Tête enseignante Opus0,005
Tête enseignante GPT0,246
Écart entre enseignants0,241 · la distance entre les deux têtes enseignantes sur ce seul travail
Statut de validationscore_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découle

Classification

machine, non validée

Prédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.

Les modèles n’ont appliqué aucune catégorie : rien dans la taxonomie ne correspondait à ce travail.
Devis d'étudeSans objet
Domainenon disponible
GenreAutre

Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».

En bref

Citations3
Publié2014
Routes d'admission1
Résumé présentoui

Explorer davantage

Même sujetAdvanced Malware Detection TechniquesTravaux en français237 207