Home

Awesome

Information Security: Panacea becoming a malady

Abstract

Information Security is often considered as technology-driven field, which creates perimeters around valuable assets, that are, in turn threatened by external or internal actors. The ever-evolving threatscape includes other people, both internal (insider threat) and external (spies, social engineers, or other criminals), as well as technology-based threats, where the intrusion happens via the network (i.e. using malware, brute-force attacks). The variations of the above methods are numerous and in constant flux.

Threat actor, as a rationale entity, after establishing a goal, has to only find one chink in the armor. Therefore, the defending - traditionally - has tried to cover all corners of security. Yet, herein lies the problem; as technology is in constant flux, and it is impossible to freeze the surrounding reality, total control is not viable. In most cases, where services have to be accessed, it is impossible.

Information security exists as a cure to combat the evils lurking, what ever they might be. In this dissertation, we establish information security as an additional element, resource-draining parasite. In its very nature, it is paradoxical, and might (FIXME!) often bring about new problems with its deployment. Wrong implementation of information security brings about a myriad of problems, such as new attack vectors, maintenaince resposibilities, unpredictable outcomes, increasing complexity (both technical and cognitive).

This dissertation has is comprised of four publications, of which three are published. Together, they form a narrative to challenge the powers that be. The work is divided as follows: