U-Eugene H. Spafford: I-Malware Nemesis

Phakathi U-Eugene H. Spafford‘s more than three years as professor of computer science at Inyuvesi yasePurdue, e-West Lafayette, Ind., Wenze iminikelo emikhulu ekuvikelekeni kwekhompiyutha nenethiwekhi. Ilungu le I-Cyber ​​Security Hall of Fameubhekwa njengomunye wabaholi abanethonya elikhulu kwezokuphepha kolwazi.

Kodwa akazange aqale ukuphokophela umsebenzi we-cybersecurity. Ngempela lo mkhakha wawungekho ngempela ngesikhathi ethweswa iziqu State University of New York eBrockport nge-bachelor’s degree kwizibalo ne-computer science ngo-1979. U-Spafford wabe eseya ku I-Georgia Tech ukuphishekela iziqu ze-master kwezolwazi nesayensi yekhompyutha.


Ekuqaleni kwawo-’80s, i-IEEE Fellow iyakhumbula, ukuphepha kwekhompuyutha kwakuhlanganisa ngokuyinhloko ukuqinisekiswa okusemthethweni-kusebenzisa amamodeli nezindlela zezibalo-kanye ne-cryptography, egxile kuma- mainframes.

“Sasingenazo izingosi zokuxhumana,” kusho uSpafford. “Amagciwane, uhlelo olungayilungele ikhompuyutha, nezinye izinsongo ze-inthanethi bezingakaveli. Ayengekho amathuluzi, ochwepheshe, noma imisebenzi—okwamanje.”

Nokho, ukuphepha kwekhompiyutha kwaba yinto yakhe yokuzilibazisa.

Uthi: “Ngafunda futhi ngafunda okuningi ngokuthi ama-computer angasetshenziswa kuphi nalapho engenza iphutha khona, ngafunda nezincwadi zezinganekwane zesayensi ezazihlola lokho okungenzeka.

Ngaleso sikhathi, umsebenzi wakhe othweswe iziqu kanye ne-postdoc wawuzungeza izindawo zendabuko zekhompiyutha. “Ikhono [at Georgia Tech] ngenze ukuba ngiklame futhi ngifundise ikilasi ekusekeleni i-hardware yezinhlelo zokusebenza,” uyakhumbula. “Ngangithanda ukufundisa kanye nezici zophenyo. Ngagcina ngokuhlala ukuze ngithole iPh.D. ngo-1986, icwaninga ngekhompyutha esabalalisiwe enokwethenjelwa.”

Umsebenzi wakhe we-postdoc ubunjiniyela besoftware: ephenya ukuthi ibhalwa kanjani isoftware eyenza lokho umthuthukisi afuna ikwenze.

Ukuphenya ukuhlasela kokuqala kwe-cybersecurity

Ngo-1987, u-Spafford wajoyina i-Purdue’s computer science faculty. Ngemva konyaka, wadonswa ophenyweni Isibungu sikaMorrisukuhlasela kokuqala okuphezulu kwe-cybersecurity.

Ikhodi idalwe ngumfundi wasekolishi okusolakala ukuthi wayeyihlosile ukuthi ibe isilingo socwaningo. Eyaziwa nangokuthi i-Internet worm, yenze izihloko zezindaba ngenkathi idala isigameko esikhulu sokunqatshelwa kwesevisi eyehlisa isivinini noma yaphahlaza inombolo ebalulekile yamakhompyutha axhunywe ku-inthanethi.

“Isidingo sabasebenzi be-cybersecurity asikaze sibe phezulu, uma abantu bethembele ekubaleni nasekugcinweni.”

U-Spafford ubeyingxenye yeqembu elithweswe icala lokuhlukanisa, ukuhlaziya, nokuhlanza ngemuva kwesibungu. Wayenomuzwa omkhulu wokuphuthuma, uyakhumbula, ngoba akekho owayazi ukuthi isibungu senzani, sasibhalwe ubani, nokuthi yayingaba yini imiphumela yaso ekugcineni. Ufake izinsuku ezingamahora angu-18 ehlakaza ikhodi, ebhala lokho ekwenzile, futhi ephendula imibuzo yabezindaba.

“Kuze kube umcimbi wezikelemu, ezokuphepha ezikhungweni zikahulumeni bezigxile kakhulu kuma-mainframes kanye nemfihlo yolwazi,” kusho yena. “Manje, futhi kwaba sobala ukuthi ukutholakala, ngisho nobuqotho, bezinhlelo kungaba sengozini—nokuthi sasingenawo amathuluzi amahle okuvikela nokuhlaziya. Kungazelelwe, wonke umuntu osuka kwabathanda izinto zokuzilibazisa uya kubasebenzi basePentagon wayekhathazekile ngokuthola amakhompyutha abo. ”

I-cybersecurity ivele kanjani

Ukuzibandakanya kuka-Spafford kusenesikhathi ekulweni nezinsongo ze-cybersecurity kwamholela emsebenzini onomvuzo wokuba uthisha, umcwaningi, isikhulumi, umbhali, umxhumanisi, nomakhi wenhlangano.

Wabhala iphepha lenkomfa, Isigameko se-Internet Worm, ngo-1989 ukuze athwebule okwenzekile nezifundo ezitholakele. Amanye amaphrojekthi akhe ezokuphepha afaka phakathi ukuthuthukisa amathuluzi okuphepha omthombo ovulekile AMAPHOYISA futhi I-Tripwire, kanye nama-firewall okuqala kanye nezinhlelo zokubona ukungena. Wayengomunye wabasunguli bomkhakha we-cyber forensics, obandakanya ukuqoqa nokuhlaziya idatha yedijithali ukuze kwenziwe uphenyo kanye nokuhlinzeka ngobufakazi obamukelekayo ngokomthetho. U-Spafford wabhala amaphepha okuqala ngesihloko.

Ibanga Lelungu: IEEE Mngane

Umqashi: Inyuvesi yasePurdue

Isihloko: Uprofesa wesayensi yekhompyutha

Imfundo: I-SUNY Brockport, Georgia Tech

Okushicilelwe: U-Spafford ubhale noma wahlanganisa izincwadi ezingaphezu kwe-150, izahluko, amaphepha, neminye imisebenzi yezazi. I-Cybersecurity Myths kanye Nemibono Engalungile: Ukugwema Izingozi Nezihibe Ezisididayo, Addison-Wesley Professional, 2023, kanye Leigh Metcalf kanye Josiah Dykstra;

Imisebenzi kahulumeni: Ufakaze ngaphambi kweCongress yase-US izikhathi eziyisishiyagalolunye, waba nesandla kwabangu-10 abakhulu amicus curiae kafushane ngaphambi kwezinkantolo zase-US, okuhlanganisa neNkantolo Ephakeme.

Ngo-1998, i-Spafford yasungula i-Purdue’s Centre for Education and Research in Information Assurance and Security, okuba umqondisi wayo ophethe uphuma ngo-2016.

Njengoba nje ukusebenza kwekhompyutha nokuvikeleka ku-inthanethi kuye kwavela, kanjalo nemfundiso yekhompiyutha kanye ne-cybersecurity, amanothi akwa-Spafford. “Ngesikhathi ngisaqala kulo mkhakha, ngangikwazi ukuchaza futhi ngifundise izifundo zokuthi uhlelo lwekhompiyutha lusebenza kanjani, kusukela ku-hardware kuya kunethiwekhi, nawo wonke amaphuzu lapho kufanele kubekwe ezokuphepha,” usho kanje. “Ngokushesha kuze kube namuhla, futhi uma sibheka noma yiluphi uhlelo olukhulu olusetshenziswayo, akekho umuntu ophilayo ongenza into efanayo. Amasistimu abe makhulu kakhulu futhi kukhona okuguquguqukayo okuningi kangangokuthi akekho noyedwa umuntu ongasiqonda sonke isitaki. Ukuze wenze kahle kwezokuphepha, udinga ukuqonda ukuthi kuyini ukuchichima kwesitaki kanye nesikhathi semiyalelo.”

Izinhlelo eziningi zesayensi yamakhompiyutha azisafundisi ulimi lokuhlangana noma ukuhlelwa kwemishini, uyaphawula.

Umsebenzi kaSpafford uye waqashelwa ngemiklomelo eminingi, kodwa udumo aziqhenya ngalo kakhulu I-Purdue University Morrill Awardawuthole ngo-2012. Lo mklomelo uhlonipha ubuhlakani abenze amagalelo amangalisayo emsebenzini wenyuvesi wokufundisa, ucwaningo kanye nokusiza umphakathi.

“Awunikezwanga kuphela umfundaze, kodwa futhi nokwenza kahle njengothisha, kanye nokusebenzela umphakathi,” kusho uSpafford. “Ngakho-ke bekumele ukuqashelwa wumphakathi wontanga yami ngezinto engizifezile ngezindlela eziningi. Ngiyakwazisa konke okunye ukuqashelwa engikutholile, kodwa yilokhu okuhlanganise ububanzi obubanzi bomsebenzi wami.”

Isimo se-cybersecurity namuhla

Zisebenza kahle kangakanani izinkampani kwezokuphepha namuhla? U-Spafford uthi abanye benza umsebenzi omuhle kakhulu ngokuhlukanisa izinhlelo zabo, ukuqasha abantu abalungile, nokwenza uhlobo olufanele lokuqapha. Kodwa, uthi, abanye abaqondi ukuthi kusho ukuthini ukuba nokuphepha okuhle noma abazimisele ukusebenzisa imali ekuvikeleni izinhlelo zabo.

“Sisendaweni yemakethe lapho imikhuba emihle eyisisekelo ivamise ukushaywa indiva ukuze sivune izengezo ezintsha nezici ezintsha,” usho kanje. “Esikhundleni sokusebenzisa izimiso eziphusile zobunjiniyela ukuze kwakhiwe izinhlelo eziqinile, eziqinile, imali eningi echithiwe nokunakwa okukhokhelwe sekuye kwengeza olunye ungqimba lwamapheshana nokwakha izandiso phezu kobuchwepheshe obuphuke kakhulu.”

Amathiphu omsebenzi

Uma kubhekwa ububanzi be-cybersecurity esabalele futhi esathuthukayo—manje sekusondele ezintweni eziyisipesheli ze-cybersecurity—u-Spafford weluleka labo abacabanga ngomsebenzi kuwo ukuze bathole umuzwa wokuthi yiziphi izici zokuphepha abazithola zijabulisa futhi ezithakazelisayo. Uthi uma usukwenzile lokho, lokho okudingeka ukufunde kuncike kulokho ozobe wenza.

Labo abanentshisekelo ku-cybersecurity forensics, ngokwesibonelo, bazodinga ukuqonda amasistimu okusebenza, amanethiwekhi, izakhiwo, idizayini ye-comiler, nobunjiniyela besofthiwe. “Lokhu kukusiza ukuthi uqonde ukuthi amasistimu asebenza kanjani, ukuthi izinto zihlangana kanjani, ukuthi amaphutha avela kanjani, nokuthi axhashazwa kanjani,” usho kanje.

Kwezinye izindawo ze-cybersecurity, ungadinga ukufunda i-psychology kanye nethiyori yokuphatha ukuze uqonde kangcono abantu abahilelekile, usho kanje. Labo abafuna ukufunda ngenqubomgomo kufanele bathole isizinda sezomthetho, ngoba abomthetho bafuna isethi ehlukile yamakhono.

Isidingo sabasebenzi be-cybersecurity asikaze sibe phezulu, uma kubhekwa ukwethembela kwabantu okukhulayo ekubaleni nasekugcinweni, kanye nokuxhumeka kwabo kwedijithali okukhulayo. “Konke lokhu kushintshile imvelo yalokho esikwenzayo ngekhompyutha futhi kwandise izindawo zokuhlasela ezingasetshenziswa yilabo abaphula ukuphepha,” kusho uSpafford. “Eminyakeni engu-30 edlule, izikhungo zokucwaninga zazixhumeke ku-inthanethi—imizi yethu nezimoto zethu kwakungezona izindawo zokuhlasela. Manje sekuyi-inthanethi Yazo Zonke Izinto.”