Prospectives for modelling trust in information security
Lecture notes in computer sciencePublished 1 January 1997
Audun Jøsang
Citations44
SJR quartileQ2
SJR score0.35
SNIP0.55
Generate an AI Snapshot to get a quick, structured summary of this paper.
Study Snapshot
ObjectiveStudy objective
MethodsResearch methodology
PopulationPopulation studied
Sample sizeSample sizes
OutcomesStudy outcomes here
ResultsStudy results comes here
LimitationsResearch study limitations comes here
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
TL;DR
Four formal models for trust which have been proposed in the recent years are analysed with the purpose of determining their strong and weak sides.
Abstract
This paper describes trust in information security as a subjective human belief. On this background, four formal models for trust which have been proposed in the recent years are analysed with the purpose of determining their strong and weak sides. From this we try to define general criteria for the feasibility of modelling trust.
Keywords
Social SciencesComputer Science
The Economic Approach to Human Behavior
4,969 Citations1976Gary S. Becker
Contemporary Sociology A Journal of ReviewsPathologies of Rational Choice Theory: A Critique of Applications in Political Science.
960 Citations1996Peter Hedström, Donald P. Green +1 more
The official PGP user's guide
896 Citations1996Philip Zimmermann
This tutorial discusses how public key cryptography works installing PGP using PGP managing keys advanced topics beware of snake oil and a peek under the hood vulnerabilities.
Lecture notes in computer scienceValuation of trust in open networks
656 Citations1994Thomas Beth, Malte Borcherding +1 more
A method for the valuation of trustworthiness which can be used to accept or reject an entity as being suitable for sensitive tasks is presented, an extension of the work of Yahalom, Klein and Beth.
A logic of authentication
642 Citations1989Michael T. Burrows, M. Abadi +1 more
The right type of trust for distributed systems
312 Citations1996Audun Jøsang
This paper examines the types of trust and trust relationships which are relevant for information security and shows that it is a very complex concept with many interesting and important implications.
Trust relationships in secure systems-a distributed authentication perspective
261 Citations2002Raphael Yahalom, Birgit Klein +1 more
A formalism for expressing trust relations is presented along with an algorithm for deriving trust relations from recommendations, and the advantages of the approach are demonstrated by analyzing and comparing the trust relation requirements of a few known authentication protocols.
Simulated social control for secure Internet commerce
222 Citations1996Lars Rasmusson, Sverker Jansson
It is suggested that soft security such as social COIIt.rol has to be used to create secure open systems and is more robust than hard security mechnnisms such as passwo7.ds, who reveal everythi7Lg if they are bypassed.
ACM SIGOPS Operating Systems ReviewOn key distribution protocols for repeated authentication
42 Citations1993Paul Syverson
This paper sets out implementation assumptions required for the attacks to take place and implementation assumptions that preclude such an attack on NS, and looks at other protocols, including one that is not subject to this form of attack and has the same number of messages as NS.
Die Trusted Computer System Evaluation Criteria (TCSEC)
33 Citations1998Kai Rannenberg
Als erste Evaluationskriterien fur die Sicherheit von IT-Systemen gelten die 1983 erstmals und 1985 nahezu unverandert erneut veroffentlichten „Trusted Computer Security Evaluation Criteria” (TCSEC) des „Department of Defense“ (DoD) der USA.
Journal of Computer SecurityThe Role of Trust in Information Integrity Protocols*
30 Citations1995Gustavus J. Simmons, Catherine Meadows
Formal methods are developed to analyze trust as a fundamental dimension in protocol analysis and proof as a result of actions taken by some of the participants reflecting trusts that exist among them.
Machine intelligence and pattern recognitionAn Expert System Framework for Non-Monotonic Reasoning about Probabilistic Assumptions
23 Citations1986
The present work addresses the problem in the context of conflict resolution in expert systems for image analysis with the design of an expert system inference framework in which probabilistic statements are regarded as assumptions, which are explicitly tracked and reevaluated when they lead to conflict among different sources of evidence or lines of reasoning.
Information Technology Security Evaluation Criteria (ITSEC) - a Contribution to Vulnerability?
15 Citations1992Michael Gehrke, Andreas Pfitzmann +1 more
Criticism focusses on the intended scope, the functionality aspects, the assessment of effectiveness and correctness, and problems arising after the evaluation of IT systems.
