EAGER: Cybercrime Susceptibility in the Sociotechnical System: Exploration of Integrated Micro- and Macro-Level Sociotechnical Models of Cybersecurity
EAGER: Cybercrime Susceptibility in the Sociotechnical System: Exploration of Integrated Micro- and Macro-Level Sociotechnical Models of Cybersecurity
批准号:
1519243
负责人:
Saman Zonouz
金额:
$13.86万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-08-14 至 2017-03-31
中文摘要
该项目开发了一种社会技术系统安全的整体方法,结合了犯罪学和工程学/计算机科学的创新。我们设计了统一的社会技术安全模型,该模型捕获了针对系统的社会和技术方面的社会技术入侵(即,被建模为系统安全状态的隐藏序列)如何导致观察到的硬数据,例如安全传感器警报,以及由人类/社会传感器产生的软数据,例如关于机器运行缓慢的报告。为了模拟社会技术安全模型的社会层面,(1)我们从嵌套在一个社会技术系统(大学校园)中的一个特定的亚群(员工)收集了大量的社会调查数据;(2)我们利用几个犯罪学和社会学的理论来识别各种社会和社会心理因素,以降低以计算机为中心的犯罪的易感性;(3)我们用组织层面的数据来补充社会调查数据,以探索组织单位的特征对个人水平的员工因以计算机为中心的犯罪而受害的影响以及此类网络犯罪威胁在组织单位中的比率。我们通过应用独特的集成社会技术分析方法来分析收集到的数据,这些方法使用随机马尔可夫决策过程和概率数据生产模型来概括对手的行为和随后的回报/成本。我们的研究为其他希望将社会科学方法和模型纳入工程系统的研究人员提供了指导,并为许多其他研究人员提供了犯罪学/社会学方面的使用研究。这项工作将改变研究人员处理社会技术安全问题的方式,因为我们认识到社会和技术因素的整体观点将变得普遍。
英文摘要
This project develops a holistic approach to sociotechnical system security that combines innovations in both criminology and engineering/computer science. We design unified sociotechnical security models that capture how sociotechnical intrusions against social as well as technical aspects of the system (i.e., modeled as hidden sequences of system security states) result in observed hard data such as security sensor alerts and soft data produced by human/social sensors such as reports about slow machines. To model the social aspect of the sociotechnical security models, (1) we collect extensive social survey data from one specific subpopulation (employees) nested within one sociotechnical system (the university campus); (2) we identify various social and social-psychological factors reducing susceptibility to victimization by computer-focused crime drawing on several criminological and sociological theories; (3) we supplement social survey data with organizational-level data to explore influences of characteristics of organizational units on individual-level employee victimization by computer-focused crimes as well as rates of such cybercrime threats in organizational units. We analyze the collected data by applying unique integrated sociotechnical analytical approaches that encapsulate the adversarial actions and subsequent rewards/costs using stochastic Markov decisions processes and probabilistic data production models. Our research provides guidelines for other researchers looking to incorporate social science methods and models into engineering systems, with the criminological/sociological aspect of the study of use to many other researchers. This work will transform how researchers approach the problem of sociotechnical security, in that our holistic view cognizant of both social and technical factors will become widespread.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Towards Deceptive and Domain-Specific Cyber-Physical Honeypots
-
批准号:2231651
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Saman Zonouz
-
依托单位:
Collaborative Research: Next Big Research Challenges in Cyber-Physical Systems
-
批准号:2240222
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2022
-
负责人:Saman Zonouz
-
依托单位:
CPS: Medium: Collaborative Research: Srch3D: Efficient 3D Model Search via Online Manufacturing-specific Object Recognition and Automated Deep Learning-Based Design Classification
-
批准号:2240733
-
项目类别:Standard Grant
-
资助金额:$59.5万
-
财政年份:2022
-
负责人:Saman Zonouz
-
依托单位:
Collaborative Research: Next Big Research Challenges in Cyber-Physical Systems
-
批准号:2131695
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2021
-
负责人:Saman Zonouz
-
依托单位:
CPS: Medium: Collaborative Research: Srch3D: Efficient 3D Model Search via Online Manufacturing-specific Object Recognition and Automated Deep Learning-Based Design Classification
-
批准号:1932146
-
项目类别:Standard Grant
-
资助金额:$59.5万
-
财政年份:2019
-
负责人:Saman Zonouz
-
依托单位:
I-Corps: Data Analytics and Automated Candidate Assessment
-
批准号:1744294
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2017
-
负责人:Saman Zonouz
-
依托单位:
SaTC: CORE: Medium: Collaborative: Privacy-Aware Trustworthy Control as a Service for the Internet of Things (IoT)
-
批准号:1703782
-
项目类别:Standard Grant
-
资助金额:$34.14万
-
财政年份:2017
-
负责人:Saman Zonouz
-
依托单位:
CPS: Medium: Collaborative Research: Trustworthy Cyber-Physical Additive Manufacturing with Untrusted Controllers
-
批准号:1739467
-
项目类别:Standard Grant
-
资助金额:$62.45万
-
财政年份:2017
-
负责人:Saman Zonouz
-
依托单位:
CPS: Synergy: Collaborative Research: Distributed Just-Ahead-Of-Time Verification of Cyber-Physical Critical Infrastructures
-
批准号:1446471
-
项目类别:Standard Grant
-
资助金额:$57.95万
-
财政年份:2015
-
负责人:Saman Zonouz
-
依托单位:
CAREER: Trustworthy and Adaptive Intrusion Tolerance Capabilities in Cyber-Physical Critical Infrastructures
-
批准号:1453046
-
项目类别:Continuing Grant
-
资助金额:$50.83万
-
财政年份:2015
-
负责人:Saman Zonouz
-
依托单位:
EAGER: Cybercrime Susceptibility in the Sociotechnical System: Exploration of Integrated Micro- and Macro-Level Sociotechnical Models of Cybersecurity
-
批准号:1343430
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2013
-
负责人:Saman Zonouz
-
依托单位:
海外基金