Vice or virtue? Exploring the dichotomy of an offensive security engineer and government “hack back” policies
- Kim L. Withers,
- James L. Parrish,
- ,
- Timothy J. Ellis
- Nova Southeastern University,
- University of North Texas,
Related Event
Title
Event type
ConferenceDate
01/07/2020 - 01/10/2020Location
Abstract
In response to increasing cybersecurity threats, government and private agencies have increasingly hired offensive security experts: "red-hat” hackers. They differ from the better-known “white-hat” hackers in applying the methods of cybercriminals against cybercriminals and counter or preemptively attacking, rather than focusing on defending against attacks. Often considered the vigilantes of the hacker ecosystem, they work under the same rules as would be hackers, attackers, hacktivists, organized cybercriminals, and state-sponsored attackers-which can easily lead them into the unethical practices often associated with such groups. Utilizing the virtue (ethics) theory and cyber attribution, we argue that there exists a dichotomy among offensive security engineers, one that appreciates organizational security practices, but at the same time violates ethics in how to retaliate against a malicious attacker.
Publication Information
Output type
Original language
English (US)Pages from-to (Number of pages)
Pages 1813-1822 (10 pages)Publication milestones
- Published - 2020
Publication status
Publisher
IEEE Computer SocietyPublication series
- Publication series name: Proceedings of the Annual Hawaii International Conference on System Sciences
ISSN (Print): 1530-1605
Volume: 2020-January
ISBN (Electronic)
9780998133133Publication IDs
- Scopus: 85108144965
Host publication title
Proceedings of the 53rd Annual Hawaii International Conference on System Sciences, HICSS 2020Host publication editors
- Tung X. Bui
