Licensing security

T. Alspaugh, W. Scacchi
{"title":"Licensing security","authors":"T. Alspaugh, W. Scacchi","doi":"10.1109/RELAW.2012.6347799","DOIUrl":null,"url":null,"abstract":"There exist legal structures defining the exclusive rights of authors, and means for licensing portions of them to others in exchange for appropriate obligations. We propose an analogous approach for security, in which portions of exclusive security rights owned by system stakeholders may be licensed as needed to others, in exchange for appropriate security obligations. Copyright defines exclusive rights to reproduce, distribute, and produce derivative works, among others. We envision exclusive security rights that might include the right to access a system, the right to run specific programs, and the right to update specific programs or data, among others. Such an approach uses the existing legal structures of licenses and contracts to manage security, as copyright licenses are used to manage copyrights. At present there is no law of “security right” as there is a law of copyright, but with the increasing prevalence and prominence of security attacks and abuses, of which Stuxnet and Flame are merely the best known recent examples, such legislation is not implausible. We discuss kinds of security rights and obligations that might produce fruitful results, and how a license structure and approach might prove more effective than security policies.","PeriodicalId":444010,"journal":{"name":"2012 Fifth IEEE International Workshop on Requirements Engineering and Law (RELAW)","volume":"27 21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-09-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Fifth IEEE International Workshop on Requirements Engineering and Law (RELAW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RELAW.2012.6347799","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

There exist legal structures defining the exclusive rights of authors, and means for licensing portions of them to others in exchange for appropriate obligations. We propose an analogous approach for security, in which portions of exclusive security rights owned by system stakeholders may be licensed as needed to others, in exchange for appropriate security obligations. Copyright defines exclusive rights to reproduce, distribute, and produce derivative works, among others. We envision exclusive security rights that might include the right to access a system, the right to run specific programs, and the right to update specific programs or data, among others. Such an approach uses the existing legal structures of licenses and contracts to manage security, as copyright licenses are used to manage copyrights. At present there is no law of “security right” as there is a law of copyright, but with the increasing prevalence and prominence of security attacks and abuses, of which Stuxnet and Flame are merely the best known recent examples, such legislation is not implausible. We discuss kinds of security rights and obligations that might produce fruitful results, and how a license structure and approach might prove more effective than security policies.
许可的安全
现有的法律结构定义了作者的专有权,以及将其中的部分授权给他人以换取适当义务的方法。我们提出了一种类似的安全方法,在这种方法中,系统利益相关者拥有的部分独家安全权利可以根据需要许可给其他人,以换取适当的安全义务。版权定义了复制、发行和制作衍生作品等的专有权。我们设想的独家安全权利可能包括访问系统的权利,运行特定程序的权利,以及更新特定程序或数据的权利等。这种方法使用许可证和合同的现有法律结构来管理安全性,就像使用版权许可证来管理版权一样。目前,没有“安全权”的法律,因为有版权法,但随着安全攻击和滥用的日益流行和突出,其中震网和火焰只是最近最著名的例子,这样的立法并非不合理。我们将讨论可能产生丰硕成果的各种安全权利和义务,以及许可结构和方法如何证明比安全策略更有效。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信