CAREER: Contextual Protection for Private Data Storage and Retrieval
CAREER: Contextual Protection for Private Data Storage and Retrieval
批准号:
1351058
负责人:
Christopher Kanich
金额:
$59.7万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-02-01 至 2020-01-31
中文摘要
这项研究旨在了解哪些数据对攻击者有用,哪些数据对其合法所有者是私有的,以便安全系统可以将这些价值纳入数据驱动的深度防御方法中,以保护我们的数字生活。我们正在利用这样一个事实,即用户和攻击者都必须筛选大量数据以找到有用的信息。这个系统被称为上下文数据保护,使用户能够以最小的开销被动地管理他们的私人和潜在的利润丰厚的存储数据,为私人数据增加额外的保护,大大降低了长期档案所固有的风险。同时,我们正在通过提高对网络犯罪、信息使用习惯和数据访问可接受的可用性权衡的理解,为数据创建有效的防御。基于先前对基于垃圾邮件的网络犯罪的经济成功的研究,我们正在开发一种方法和设备来理解被盗信息的非法价值。通过了解对攻击者来说什么是可发现的和有价值的,我们可以开发技术,将安全工作集中在有利可图的信息上,从而防止网络罪犯从中获利。最终,我们的目标是创建一组通用技术,这些技术使用密码学中的工具,通过更深入地了解用户和攻击者的数据价值来保护用户的数据。这项研究将阐明在这个长期数字存储的时代,信息价值、所有权和保护的意义。
英文摘要
This research is building an understanding of what data is useful to attackers and what data is private for its legitimate owners so that security systems can incorporate these values into a data-driven, defense-in-depth approach to securing our digital lives. We are exploiting the fact that both users and attackers must sift through vast amounts of data to find useful information. This system, called contextual data protection, enables users to passively manage their private and potentially lucrative stored data with minimal overhead, adding extra protection to private data which greatly lowers the risk inherent in long lived archives. Simultaneously, we are creating effective defenses for data by improving our understanding of cybercrime, information use habits, and acceptable usability tradeoffs for data access. Building on previous research analyzing the financial successes of spam-based cybercrime, we are developing a methodology and apparatus for understanding the illicit value of stolen information. By understanding what is discoverable and valuable to attackers, we can develop techniques to focus security efforts on lucrative information, thereby preventing cybercriminals from turning a profit. Ultimately, our goal is to create a set of general techniques that use tools from cryptography that defend users' data by exploiting a deeper understanding of its value to both the users and the attackers. This research will shed light on the meaning of information value, ownership, and protection in this era of long-lived digital storage.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: Conference: 2024 Aspiring PIs in Secure and Trustworthy Cyberspace
-
批准号:2404951
-
项目类别:Standard Grant
-
资助金额:$2.57万
-
财政年份:2024
-
负责人:Christopher Kanich
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
-
批准号:2247953
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2023
-
负责人:Christopher Kanich
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Understanding and Combatting Impersonation Attacks and Data Leakage in Online Advertising
-
批准号:2247515
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2023
-
负责人:Christopher Kanich
-
依托单位:
SaTC: CORE: Medium: Collaborative: Enabling Long-Term Security and Privacy through Retrospective Data Management
-
批准号:1801644
-
项目类别:Continuing Grant
-
资助金额:$79.93万
-
财政年份:2018
-
负责人:Christopher Kanich
-
依托单位:
II-New: Enabling Security Analysis at Scale
-
批准号:1405886
-
项目类别:Standard Grant
-
资助金额:$3.57万
-
财政年份:2014
-
负责人:Christopher Kanich
-
依托单位:
海外基金