Building General Knowledge of Mechanisms in Information Security.

Saved in:
Bibliographic Details
Title: Building General Knowledge of Mechanisms in Information Security.
Authors: Spring, Jonathan M.1 (AUTHOR) jspring@cs.ucl.ac.uk, Illari, Phyllis2 (AUTHOR)
Source: Philosophy & Technology. Dec2019, Vol. 32 Issue 4, p627-659. 33p.
Subject Terms: *Computer networks, *Computer security, Information technology security, Botnets, Cyberterrorism, Philosophy of science
Abstract: We show how more general knowledge can be built in information security, by the building of knowledge of mechanism clusters, some of which are multifield. By doing this, we address in a novel way the longstanding philosophical problem of how, if at all, we come to have knowledge that is in any way general, when we seem to be confined to particular experiences. We also address the issue of building knowledge of mechanisms by studying an area that is new to the mechanisms literature: the methods of what we shall call mechanism discovery in information security. This domain offers a fascinating novel constellation of challenges for building more general knowledge. Specifically, the building of stable communicable mechanistic knowledge is impeded by the inherent changeability of software, which is deployed by malicious actors constantly changing how their software attacks, and also by an ineliminable secrecy concerning the details of attacks not just by attackers (black hats), but also by information security defenders (white hats) as they protect their methods from both attackers and commercial competitors. We draw out ideas from the work of the mechanists Darden, Craver, and Glennan to yield an approach to how general knowledge of mechanisms can be painstakingly built. We then use three related examples of active research problems from information security (botnets, computer network attacks, and malware analysis) to develop philosophical thinking about building general knowledge using mechanisms, and also apply this to develop insights for information security. We show that further study would be instructive both for practitioners (who might welcome the help in conceptualizing what they do) and for philosophers (who will find novel insights into building general knowledge of a highly changeable domain that has been neglected within philosophy of science). [ABSTRACT FROM AUTHOR]
Copyright of Philosophy & Technology is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Education Research Complete
FullText Text:
  Availability: 0
Header DbId: ehh
DbLabel: Education Research Complete
An: 139744140
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Building General Knowledge of Mechanisms in Information Security.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Spring%2C+Jonathan+M%2E%22">Spring, Jonathan M.</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> jspring@cs.ucl.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Illari%2C+Phyllis%22">Illari, Phyllis</searchLink><relatesTo>2</relatesTo> (AUTHOR)
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Philosophy+%26+Technology%22">Philosophy & Technology</searchLink>. Dec2019, Vol. 32 Issue 4, p627-659. 33p.
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: *<searchLink fieldCode="DE" term="%22Computer+networks%22">Computer networks</searchLink><br />*<searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink><br /><searchLink fieldCode="DE" term="%22Information+technology+security%22">Information technology security</searchLink><br /><searchLink fieldCode="DE" term="%22Botnets%22">Botnets</searchLink><br /><searchLink fieldCode="DE" term="%22Cyberterrorism%22">Cyberterrorism</searchLink><br /><searchLink fieldCode="DE" term="%22Philosophy+of+science%22">Philosophy of science</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: We show how more general knowledge can be built in information security, by the building of knowledge of mechanism clusters, some of which are multifield. By doing this, we address in a novel way the longstanding philosophical problem of how, if at all, we come to have knowledge that is in any way general, when we seem to be confined to particular experiences. We also address the issue of building knowledge of mechanisms by studying an area that is new to the mechanisms literature: the methods of what we shall call mechanism discovery in information security. This domain offers a fascinating novel constellation of challenges for building more general knowledge. Specifically, the building of stable communicable mechanistic knowledge is impeded by the inherent changeability of software, which is deployed by malicious actors constantly changing how their software attacks, and also by an ineliminable secrecy concerning the details of attacks not just by attackers (black hats), but also by information security defenders (white hats) as they protect their methods from both attackers and commercial competitors. We draw out ideas from the work of the mechanists Darden, Craver, and Glennan to yield an approach to how general knowledge of mechanisms can be painstakingly built. We then use three related examples of active research problems from information security (botnets, computer network attacks, and malware analysis) to develop philosophical thinking about building general knowledge using mechanisms, and also apply this to develop insights for information security. We show that further study would be instructive both for practitioners (who might welcome the help in conceptualizing what they do) and for philosophers (who will find novel insights into building general knowledge of a highly changeable domain that has been neglected within philosophy of science). [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Philosophy & Technology is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=ehh&AN=139744140
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s13347-018-0329-z
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 33
        StartPage: 627
    Subjects:
      – SubjectFull: Computer networks
        Type: general
      – SubjectFull: Computer security
        Type: general
      – SubjectFull: Information technology security
        Type: general
      – SubjectFull: Botnets
        Type: general
      – SubjectFull: Cyberterrorism
        Type: general
      – SubjectFull: Philosophy of science
        Type: general
    Titles:
      – TitleFull: Building General Knowledge of Mechanisms in Information Security.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Spring, Jonathan M.
      – PersonEntity:
          Name:
            NameFull: Illari, Phyllis
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 12
              Text: Dec2019
              Type: published
              Y: 2019
          Identifiers:
            – Type: issn-print
              Value: 22105433
          Numbering:
            – Type: volume
              Value: 32
            – Type: issue
              Value: 4
          Titles:
            – TitleFull: Philosophy & Technology
              Type: main
ResultId 1