Measuring the Security Posture of Large Financial Enterprises: An EAGER Proposal to NSF CCF
衡量大型金融企业的安全状况:向 NSF CCF 提出的迫切建议
基本信息
- 批准号:0950373
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2009
- 资助国家:美国
- 起止时间:2009-09-01 至 2012-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
To develop computer security as a science and engineering discipline, metrics need to be defined to evaluate the safety and security of alternative system designs. Security policies are often specified by large organizations but there are no direct means to evaluate how well these policies are followed by human users. The proposed project explores fundamental means of measuring the security posture of large enterprises. Risk management and risk mitigation requires measurement to assess alternative outcomes in any decision process. The project is intended to devise metrics and measurement methods, and test and evaluate these in a real institution, to evaluate how human users behave in a security context. Financial institutions in particular require significant controls over the handling of confidential financial information and employees must adhere to these policies to protect assets, which are subject to continual adversarial attack by thieves and fraudsters. Hence, financial institutions are the primary focus of the measurement work. The technical means of measuring user actions that may violate security policy is performed in a non-intrusive manner. The measurement system uses specially crafted decoy documents and email messages that signal when they have been opened or copied by a user in violation of policy. The project will develop collaborations with financial experts to devise risk models associated with users of information technology within large enterprises. This line of work extends traditional research in computer security by opening up a new area focused on the human aspect of security.
为了将计算机安全发展为一门科学和工程学科,需要定义度量标准来评估替代系统设计的安全性和可靠性。安全策略通常由大型组织指定,但没有直接的方法来评估人类用户遵守这些策略的情况。拟议的项目探讨衡量大企业安全状况的基本手段。风险管理和风险缓解需要衡量,以评估任何决策过程中的替代结果。该项目旨在设计指标和测量方法,并在真实的机构中测试和评估这些指标和方法,以评估人类用户在安全环境中的行为。金融机构尤其需要对机密财务信息的处理进行严格控制,员工必须遵守这些政策以保护资产,这些资产可能会受到小偷和欺诈者的持续攻击。因此,金融机构是衡量工作的主要重点。测量可能违反安全策略的用户操作的技术手段以非侵入式方式执行。测量系统使用特制的诱饵文档和电子邮件,当用户违反策略打开或复制它们时发出信号。该项目将与金融专家合作,设计与大型企业内信息技术用户有关的风险模型。这项工作扩展了计算机安全的传统研究,开辟了一个新的领域,专注于安全的人的方面。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Salvatore Stolfo其他文献
Salvatore Stolfo的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Salvatore Stolfo', 18)}}的其他基金
National Cyber Defense Initiative Financial Services Workshop
国家网络防御计划金融服务研讨会
- 批准号:
0946107 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Workshop on Resilient Financial Information Systems
弹性金融信息系统研讨会
- 批准号:
0522217 - 财政年份:2005
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Email Mining Toolkit Supporting Law Enforcement Forensic Analyses
支持执法取证分析的电子邮件挖掘工具包
- 批准号:
0429323 - 财政年份:2004
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
SGER: Mitigating Access Risks of Browsing Government Date and Websites by Secure Private Portals
SGER:降低通过安全私人门户浏览政府日期和网站的访问风险
- 批准号:
0140304 - 财政年份:2002
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Scalable Data Mining by Meta-Learning
通过元学习进行可扩展的数据挖掘
- 批准号:
9632225 - 财政年份:1996
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Scalable Parallel and Distributed Expert Database Systems
可扩展的并行分布式专家数据库系统
- 批准号:
9313847 - 财政年份:1994
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
相似海外基金
Fair Game: valuing the bio-cultural heritage of fallow deer and their venison for food security, sustainable woodlands and biodiversity
公平游戏:重视小鹿及其鹿肉的生物文化遗产,以促进粮食安全、可持续林地和生物多样性
- 批准号:
AH/Z505675/1 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Research Grant
CAREER: Verifying Security and Privacy of Distributed Applications
职业:验证分布式应用程序的安全性和隐私
- 批准号:
2338317 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CAP: AI-Ready Institution Transforming Tomorrow's Research and Education with AI Focused on Health and Security (Jag-AI)
CAP:人工智能就绪机构通过专注于健康和安全的人工智能改变未来的研究和教育 (Jag-AI)
- 批准号:
2334243 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
I-Corps: Networked Autonomous-humanoid Security Robot
I-Corps:网络化自主人形安全机器人
- 批准号:
2348931 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CAREER: Foundational Principles for Harnessing Provenance Analytics for Advanced Enterprise Security
职业:利用来源分析实现高级企业安全的基本原则
- 批准号:
2339483 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Scripps Center for Oceans and Human Health: advancing the science of marine contaminants and seafood security
斯克里普斯海洋与人类健康中心:推进海洋污染物和海鲜安全的科学
- 批准号:
2414798 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
REU Site: Enhancing Undergraduate Experiences in Data and Mobile Cloud Security
REU 网站:增强本科生在数据和移动云安全方面的经验
- 批准号:
2349233 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CAREER: Toward Power Delivery Network-aware Hardware Security
职业:迈向电力传输网络感知硬件安全
- 批准号:
2338069 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Implementation Security of Quantum Cryptography
量子密码学的实现安全
- 批准号:
2907696 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Studentship
Computational approach to security dilemma: understanding state rivalry through multilingual longitudinal analysis of foreign news
解决安全困境的计算方法:通过外国新闻的多语言纵向分析来理解国家竞争
- 批准号:
23K25490 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Grant-in-Aid for Scientific Research (B)