课题基金 / 基金详情

CAREER: Control of Information Security Risk Using Economic Incentives

CAREER: Control of Information Security Risk Using Economic Incentives
职业:利用经济激励控制信息安全风险
批准号:
0954234
负责人:
Terrence August
金额:
$42.22万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-02-15 至 2016-01-31

项目摘要

项目成果

Terrence August的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Security risks associated with software that communicates over networks have become an increasingly costly problem for consumers, firms, and governments. A key characteristic of any interconnected system (e.g., network software such as Apache HTTP server, the smart grid, and airline baggage operations) is that choices made in the design, deployment, and usage of these systems can have significant implications for security risk. Because these choices are often driven by economic tradeoffs, both firm and consumer incentives can be designed to encourage the development of systems that are less vulnerable. Further, due to the fact that seemingly disparate systems are connected through the network, security weaknesses in one system can rapidly cause major problems for another. Because of these negative externalities, governments may need to intervene through regulation or legislation to ensure the security of critical components of the public infrastructure (e.g., the Internet). This project develops a research framework to analyze the relationship between government policy, economic incentives of firms and consumers, and software security risks of networks. The goal of the project is to gain new insights into how the efforts of firms, consumers, and government can be coordinated to improve software security. To better understand this socio-technical problem, the research will generate formal economic theory to analyze the complex interactions between these entities, each of whom has varying economic incentives. Three important aspects of the software security landscape are studied: software liability, the impact of software deployment models, and open source software incentives for security. To clarify the interplay between public and private forces on security, this research program rigorously studies the role of government in setting policy on software liability, security investment, and technology-specific subsidization to help control software security risks. It will provide guidelines on how software liability should be employed in a context with security interdependence. Also, since design choices by software firms partially determine a given product?s risk exposure to both directed and undirected security attacks, a modeling framework is built to examine how each type of attack distinctly influences software security in consideration of user behavior; the results have important implications for optimal software design. An important outcome of the work is to combine for the first time research on the economics of open source software with that on security risk, two significant streams of research in the literature. In this dimension, the project investigates whether open source software can lower security risks and lead to socially preferable outcomes.By advancing one?s understanding of how to manage software security risk, this project will have wideranging impacts. First, the results will provide guidance to policy makers on how to craft policies which account for firm and user behavior while mitigating the enormous social and economic losses from security attacks on software. Since software security is critical to national defense, one priority is to keep an open dialogue with appropriate government agencies on the project?s outcomes. Second, this work can advise software firms on improved software design and using source code strategy to achieve greater security. Third, society can benefit substantially from improved software and reduced economic losses. By involving undergraduate and graduate students in the research process, the project will provide mentorship on economic modeling and quantitative analysis. As part of the educational activities, a case study that focuses on the interaction between open source incentives and security risk will be generated.By integrating the research findings and the case study with IT curricula, the project will educate future business leaders on IT strategy and security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Student Travel Grant for 2017 Workshop on the Economics of Information Security (WEIS)
  • 批准号:
    1733956
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.2万
  • 财政年份:
    2017
  • 负责人:
    Terrence August
  • 依托单位:
国内基金
海外基金
Cortical control of internal state in the insular cortex-claustrum region