Many of our critical infrastructure systems and personal computing systems have a distributed computing systems structure. The incentives to attack them have been growing rapidly as has their attack surface due to increasing levels of connectedness. Therefore, we feel it is time to bring in rigorous reasoning to secure such systems. The distributed system security and the game theory technical communities can come together to effectively address this challenge. In this article, we lay out the foundations from each that we can build upon to achieve our goals. Next, we describe a set of research challenges for the community, organized into three categories -- analytical, systems, and integration challenges, each with "short term" time horizon (2-3 years) and "long term" (5-10 years) items. This article was conceived of through a community discussion at the 2022 NSF SaTC PI meeting.
翻译:许多关键基础设施系统和个人计算系统均采用分布式计算体系结构。随着互联程度的持续提升,攻击此类系统的动机及其攻击面正在快速增长。因此,我们认为有必要引入严谨的推理机制来保障此类系统的安全。分布式系统安全与博弈论技术社区可以协同合作,有效应对这一挑战。本文阐述了双方可共同利用的基础理论以实现研究目标。随后,我们系统阐述了面向该领域的研究挑战,将其归纳为分析类、系统类与集成类三大范畴,每类范畴均包含"短期"(2-3年)与"长期"(5-10年)研究议题。本文源于2022年美国国家科学基金会安全与可信计算首席研究员会议期间的社区讨论。