TAILIEUCHUNG - Security Analysis of the Diebold AccuVote-TS Voting Machine

Web applications provide end users with client access to server functionality through a set of Web pages. These pages often contain script code to be executed dynami- cally within the client Web browser. Most Web applications aim to enforce simple, intu- itive security policies, such as, forWeb-based email, dis- allowing any scripts in untrusted email messages. Even so, Web applications are currently subject to a plethora of successful attacks, such as cross-site scripting, cookie theft, session riding, browser hijacking, and the recent self-propagating worms in Web-based email and social networking sites [2, 17, 24]. Indeed, according to sur- veys, security issues in Web applications are the most commonly reported vulnerabilities on the Internet. | Security Analysis of the Diebold AccuVote-TS Voting Machine Ariel J. Feldman J. Alex Halderman and Edward W. Felten Center for Information Technology Policy and Dept. of Computer Science Princeton University Woodrow Wilson School of Public and International Affairs Princeton University ajfeldma jhalderm felten @ Abstract This paper presents a fully independent security study of a Diebold AccuVote-TS voting machine including its hardware and software. We obtained the machine from a private party. Analysis of the machine in light of real election procedures shows that it is vulnerable to extremely serious attacks. For example an attacker who gets physical access to a machine or its removable memory card for as little as one minute could install malicious code malicious code on a machine could steal votes undetectably modifying all records logs and counters to be consistent with the fraudulent vote count it creates. An attacker could also create malicious code that spreads automatically and silently from machine to machine during normal election activities a voting-machine virus. We have constructed working demonstrations of these attacks in our lab. Mitigating these threats will require changes to the voting machine s hardware and software and the adoption of more rigorous election procedures. 1 Introduction The Diebold AccuVote-TS and its newer relative the AccuVote-TSx are together the most widely deployed electronic voting platform in the United States. In the November 2006 general election these machines were used in 385 counties representing over 10 of registered voters 12 . The majority of these counties including all of Maryland and Georgia employed the AccuVote-TS model. More than 33 000 of the TS machines are in service nationwide 11 . This paper reports on our study of an AccuVote-TS which we obtained from a private party. We analyzed the machine s hardware and software performed experiments on it and considered whether real election .

TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.