TC: Medium: Collaborative Research: User-Controllable Policy Learning
TC: Medium: Collaborative Research: User-Controllable Policy Learning
批准号:
0905403
负责人:
Steven Bellovin
金额:
$45.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-10-01 至 2013-09-30
中文摘要
由于面向企业和面向消费者的应用程序都引入了新的功能,并增加了定制和委托的级别,它们不可避免地会产生更复杂的安全和隐私策略。然而,研究一再表明,外行和专家用户都不擅长配置策略,这使得人为因素成为一个重要的、但往往被忽视的脆弱性来源。该项目旨在开发和评估一系列新的用户可控策略学习技术,这些技术能够利用用户反馈,并就如何改进其安全或隐私政策向用户提供增量的、用户可理解的建议。与传统的机器学习技术相比,传统的机器学习技术通常配置为?黑盒吗?用户可控策略学习的目的是确保用户继续理解他们的策略,并保持对策略变化的控制。因此,这一系列策略学习技术为外行和专家用户更有效地配置广泛的安全和隐私策略提供了前景。在这个项目中开发的技术将在两个战略重要领域的背景下进行评估和完善,即社交网络中的隐私政策和防火墙政策。在此过程中,本项目中进行的工作也有望导致对以下方面有更深入的了解:(1)用户在试图指定和完善安全和隐私政策时遇到的困难,以及(2)克服这些困难需要什么。后者包括开发用户可以关联和利用的策略修改类型的模型,以及理解可用性与用户所看到的策略修改数量之间的权衡。它还包括理解用户可控策略学习的有效性如何受到底层策略语言的表现力、与用户的交互模式(例如图形与基于文本的)以及部署策略的拓扑结构的影响。
英文摘要
As both corporate and consumer-oriented applications introduce new functionality and increased levels of customization and delegation, they inevitably give rise to more complex security and privacy policies. Yet, studies have repeatedly shown that both lay and expert users are not good at configuring policies, rendering the human element an important, yet often overlooked source of vulnerability. This project aims to develop and evaluate a new family of user-controllable policy learning techniques capable of leveraging user feedback and presenting them with incremental, user-understandable suggestions on how to improve their security or privacy policies. In contrast to traditional machine learning techniques, which are generally configured as ?black boxes? that take over from the user, user-controllable policy learning aims to ensure that users continue to understand their policies and remain in control of policy changes. As a result, this family of policy learning techniques offers the prospect of empowering lay and expert users to more effectively configure a broad range of security and privacy policies. The techniques to be developed in this project will be evaluated and refined in the context of two strategically important domains, namely privacy policies in social networks and firewall policies. In the process, work to be conducted in this project is also expected to lead to a significantly deeper understanding of (1) the difficulties experienced by users as they try to specify and refine security and privacy policies, and (2) what it takes to overcome these difficulties. The latter includes developing models of the types of policy modifications users can relate to and exploit as well as an understanding of the tradeoffs between usability and the number of policy modifications users are presented with. It also includes understanding how the effectiveness of user-controllable policy learning is impacted by the expressiveness of underlying policy languages, modes of interaction with the user (e.g. graphical versus text-based), and the topologies across which policies are deployed,
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: Conference: Workshop on Advanced Automated Systems, Contestability, and the Law
-
批准号:2349804
-
项目类别:Standard Grant
-
资助金额:$2.96万
-
财政年份:2023
-
负责人:Steven Bellovin
-
依托单位:
SaTC: TTP: Small: Easy Email Encryption
-
批准号:1717801
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2017
-
负责人:Steven Bellovin
-
依托单位:
TWC: Small: Virtual Private Social Networks
-
批准号:1318415
-
项目类别:Standard Grant
-
资助金额:$49.83万
-
财政年份:2013
-
负责人:Steven Bellovin
-
依托单位:
Collaborative Research: Planning Grant: A Clean-Slate Design for the Next-Generation Secure Internet
-
批准号:0540274
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2005
-
负责人:Steven Bellovin
-
依托单位:
海外基金