{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:31:47Z","timestamp":1750307507532,"version":"3.41.0"},"reference-count":84,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2009,12,3]],"date-time":"2009-12-03T00:00:00Z","timestamp":1259798400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGSOFT Softw. Eng. Notes"],"published-print":{"date-parts":[[2009,12,3]]},"abstract":"<jats:p>This paper studies computer security from first principles. The basic questions \"Why?\", \"How do we know what we know?\" and \"What are the implications of what we believe?\"<\/jats:p>","DOI":"10.1145\/1640162.1655274","type":"journal-article","created":{"date-parts":[[2009,12,8]],"date-time":"2009-12-08T20:53:14Z","timestamp":1260305594000},"page":"8-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["The epistemology of computer security"],"prefix":"10.1145","volume":"34","author":[{"given":"Robert","family":"Schaefer","sequence":"first","affiliation":[{"name":"Daniel Webster College"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2009,12,3]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSPEC.2008.4505310"},{"key":"e_1_2_1_2_1","first-page":"2","article-title":"Subversion as a Threat in Information Warfare","volume":"3","author":"Anderson Emory A","year":"2004","journal-title":"Journal of Information Warfare, Space and Naval Warfare (SPAWAR) SC"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.668971"},{"volume-title":"Security Engineering","year":"2008","author":"Anderson Ross","key":"e_1_2_1_4_1"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.37"},{"volume-title":"22nd Annual Computer Security Applications Conference","year":"2006","author":"Bell David Elliot","key":"e_1_2_1_6_1"},{"volume-title":"Information and Cyberspace Symposium, September 22 - 24, 2008","year":"2008","author":"Berg Michael","key":"e_1_2_1_7_1"},{"volume-title":"Computer Security","year":"2003","author":"Bishop Matt","key":"e_1_2_1_8_1"},{"key":"e_1_2_1_9_1","first-page":"223","volume-title":"Proceedings of the Fourth World Conference on Information Security Education","author":"Bishop Matt","year":"2005"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.56"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.159"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1595676.1595678"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2009.104"},{"key":"e_1_2_1_14_1","first-page":"198","volume-title":"30th Annual 1996 International Carnahan Conference","author":"Boebert William E","year":"1996"},{"key":"e_1_2_1_15_1","article-title":"Some Thoughts on the Occasion of the NSA Linux Release","author":"Boebert Earl","year":"2004","journal-title":"Linux Journal"},{"volume-title":"Simms","year":"1937","author":"Borges Jorge Luis","key":"e_1_2_1_16_1"},{"volume-title":"The New York Times","year":"2009","author":"Broad William J","key":"e_1_2_1_17_1"},{"volume-title":"RSA Conferences","year":"2009","author":"Cappelli Dawn M","key":"e_1_2_1_18_1"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455840"},{"key":"e_1_2_1_20_1","unstructured":"Cohen Fred \"Experiments with Computer Viruses\" 1984. http:\/\/all.net\/books\/virus\/part5.html (The very first computer virus experiment.)  Cohen Fred \"Experiments with Computer Viruses\" 1984. http:\/\/all.net\/books\/virus\/part5.html (The very first computer virus experiment.)"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCST.1991.202223"},{"volume-title":"Robert","year":"2002","author":"Coram","key":"e_1_2_1_22_1"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.8"},{"volume-title":"Information Warfare Monitor","year":"2009","author":"Deibert Ronald","key":"e_1_2_1_24_1"},{"volume-title":"Oct 18","year":"1999","author":"Denning Dorothy E","key":"e_1_2_1_25_1"},{"volume-title":"The New York Times","year":"2009","author":"Drew Christopher","key":"e_1_2_1_26_1"},{"volume-title":"Electronic Frontier Foundation","year":"2008","author":"Staff Unintended Consequences","key":"e_1_2_1_27_1"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.210303"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1506409.1506429"},{"volume-title":"American Scientist","year":"1977","author":"Harris I","key":"e_1_2_1_30_1"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/360303.360333"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/784592.784794"},{"key":"e_1_2_1_33_1","first-page":"A1","article-title":"Cadets Trade the Trenches for Firewalls","author":"Kilgannon Corey","year":"2009","journal-title":"New York Times"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.38"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.5555\/1387709.1387714"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.3322\/canjclin.20.6.360"},{"key":"e_1_2_1_37_1","first-page":"148","article-title":"To Manage is Not to Control: or the Folly of Type II Errors","author":"Stout","year":"1979","journal-title":"Public Administration Review"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/2699840.2699848"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/163359.163373"},{"volume-title":"Proceedings of the 21st National Information Systems Security Conference","year":"1998","author":"Loscocco Peter A","key":"e_1_2_1_40_1"},{"key":"e_1_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Mackenzie Donald Mechanizing Proof MIT Press 2001.   Mackenzie Donald Mechanizing Proof MIT Press 2001.","DOI":"10.7551\/mitpress\/4529.001.0001"},{"volume-title":"The New York Times","year":"2008","author":"Markoff John","key":"e_1_2_1_42_1"},{"volume-title":"Sunday Boston Globe","year":"2009","author":"Markoff John","key":"e_1_2_1_43_1"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0190(85)90065-1"},{"volume-title":"Security In Computing","year":"2007","author":"Pfleeger Charles P","key":"e_1_2_1_45_1"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/1498765.1498782"},{"volume-title":"Black Hat USA, 2007","year":"2007","author":"Quist Danny","key":"e_1_2_1_47_1"},{"volume-title":"Proceedings of the 9th USENIX Security Symposium","year":"2000","author":"Robin John Scott","key":"e_1_2_1_48_1"},{"volume-title":"Information Security","year":"2009","author":"Roiter Neil","key":"e_1_2_1_49_1"},{"volume-title":"FBI","year":"2008","author":"Rolden Raul","key":"e_1_2_1_50_1"},{"volume-title":"International Conference in Information Warfare and Security","year":"2006","author":"Rowe Neil C","key":"e_1_2_1_51_1"},{"volume-title":"Version 1.01","year":"2006","author":"Rutkowska Joanna","key":"e_1_2_1_52_1"},{"volume-title":"Black Hat DC 2007","year":"2007","author":"Rutkowska Joanna","key":"e_1_2_1_53_1"},{"volume-title":"EuSecWest","year":"2009","author":"Rutkowska Joanna","key":"e_1_2_1_54_1"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/357401.357402"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/1281421.1281430"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/1457516.1457528"},{"key":"e_1_2_1_58_1","unstructured":"Schneier Bruce \"CRYPTO-GRAM\" March 15 2009 (See the section \"Insiders\".) http:\/\/www.schneier.com\/crypto-gram-0903.htmll#4  Schneier Bruce \"CRYPTO-GRAM\" March 15 2009 (See the section \"Insiders\".) http:\/\/www.schneier.com\/crypto-gram-0903.htmll#4"},{"volume-title":"The Sneetches and Other Stories","year":"1961","author":"Seuss Dr.","key":"e_1_2_1_59_1"},{"volume-title":"Proceedings of the 19th National Information Systems Security Conference, 1996","year":"1996","author":"Sibert Olin W","key":"e_1_2_1_60_1"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/1516046.1516056"},{"volume-title":"BAE Systems Information Technology, LLC XTS-400 \/ STOP 6.1.E, CCEVS-VR-05 0094","year":"2005","author":"Staff Common Criteria","key":"e_1_2_1_62_1"},{"volume-title":"Ch. 7","year":"1991","author":"Stove David","key":"e_1_2_1_63_1"},{"volume-title":"Peter G. Neumann, moderator","author":"Summit Steve","key":"e_1_2_1_64_1"},{"key":"e_1_2_1_65_1","article-title":"Dissent Made Safer","author":"Talbot David","year":"2009","journal-title":"MIT Technology Review"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/358198.358210"},{"volume-title":"Trans. Thomas Cleary","year":"2003","author":"Tzu Sun","key":"e_1_2_1_67_1"},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/1506409.1506422"},{"key":"e_1_2_1_69_1","doi-asserted-by":"crossref","first-page":"286","DOI":"10.1109\/RISP.1992.213253","volume-title":"Proceedings Research in Security and Privacy, 1992, IEEE Computer Society Symposium on Research and Privacy","author":"Wiessman Clark","year":"1992"},{"volume-title":"November 8","year":"2008","author":"Wikipedia Contributors Biba","key":"e_1_2_1_70_1"},{"volume-title":"December 14","year":"2008","author":"Wikipedia Contributors Celestial","key":"e_1_2_1_71_1"},{"volume-title":"May 9","year":"2009","author":"Wikipedia Contributors Charles Sanders","key":"e_1_2_1_72_1"},{"volume-title":"June 9","year":"2009","author":"Wikipedia Contributors Wikipedia","key":"e_1_2_1_73_1"},{"volume-title":"June 4","year":"2009","author":"Wikipedia Contributors Wikipedia","key":"e_1_2_1_74_1"},{"volume-title":"April 2","year":"2009","author":"Wikipedia Contributors Wikipedia","key":"e_1_2_1_75_1"},{"volume-title":"The Free Encyclopedia","year":"2009","author":"Wikipedia Contributors","key":"e_1_2_1_76_1"},{"volume-title":"April 22","year":"2009","author":"Wikipedia Contributors OODA","key":"e_1_2_1_77_1"},{"volume-title":"May 27","year":"2009","author":"Wikipedia Contributors Wikipedia","key":"e_1_2_1_78_1"},{"volume-title":"May 23","year":"2009","author":"Wikipedia Contributors Wikipedia","key":"e_1_2_1_79_1"},{"volume-title":"The Free Encyclopedia","year":"2009","author":"Wikipedia Contributors Sony BMG","key":"e_1_2_1_80_1"},{"volume-title":"May 13","year":"2009","author":"Wikipedia Contributors Wikipedia","key":"e_1_2_1_81_1"},{"volume-title":"Albert","year":"2009","author":"Wohlstetter","key":"e_1_2_1_82_1"},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.5555\/863631.880529"},{"key":"e_1_2_1_84_1","unstructured":"Yodaiken Victor \"A short note on secure operating systems Linux and the Common Criteria FSMLabs Undated http:\/\/www.yodaiken.com\/papers\/wrongthreats.pdf  Yodaiken Victor \"A short note on secure operating systems Linux and the Common Criteria FSMLabs Undated http:\/\/www.yodaiken.com\/papers\/wrongthreats.pdf"}],"container-title":["ACM SIGSOFT Software Engineering Notes"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1640162.1655274","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1640162.1655274","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:17:56Z","timestamp":1750249076000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1640162.1655274"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,12,3]]},"references-count":84,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2009,12,3]]}},"alternative-id":["10.1145\/1640162.1655274"],"URL":"https:\/\/doi.org\/10.1145\/1640162.1655274","relation":{},"ISSN":["0163-5948"],"issn-type":[{"type":"print","value":"0163-5948"}],"subject":[],"published":{"date-parts":[[2009,12,3]]},"assertion":[{"value":"2009-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}