NSFSaTC-BSF: TWC: Small: Using Individual Differences to Personalize Security Mitigations
NSFSaTC-BSF:TWC:小:利用个体差异来个性化安全缓解措施
基本信息
- 批准号:1528070
- 负责人:
- 金额:$ 49.97万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2015
- 资助国家:美国
- 起止时间:2015-09-01 至 2019-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Over the past decade, people have realized that failure to account for human factors has resulted in many software security problems. Yet, when software does feature user-centric design, it takes into account average user behavior rather than catering to the individual. Thus, systems designers have gone from designing for security experts to now appealing to the least common denominator. The goal of this project is to examine the ways in which security mitigations can be tailored to individuals, and how this is likely to result in even greater security compliance than what has been previously achieved through user-centric design. Specifically, this research focuses on demonstrating how security mitigations can be tailored to individuals through indirect measurements and inferences of individual differences. This research could help security and privacy engineers develop more personalized and salient means to alert users to security and privacy risks, which could increase users' compliance with security messaging and therefore reduce threats to users and their organizations.The challenge to personalizing security mitigations is to infer the individual differences between users that are predictive of whether they are likely to respond more favorably to one mitigation design over another. This approach relies on using well-studied individual differences in the psychology and decision-making literature that are predictive of compliance to computer security mitigations. Building on extensive work on choice architecture and "nudges," this research aims to personalize security mitigations to specific user traits in order to be able to dynamically present each user with the security "nudge" that would be most effective for her. For example, if the target user measures high on decision-making "dependence" (i.e., looking to others for advice), the system might state the number of experts who selected the recommended option. Specifically, the researchers focus on framing the following types of security mitigations based on users' psychometric traits: smartphone/tablet lock screen enrollment, password creation instructions, web browser warnings, and software update notices. Their goal is to implement systems that infer the ways in which users are likely to respond to particular security mitigation designs and then tailor security environments accordingly.
在过去的十年中,人们意识到未能考虑人为因素,导致了许多软件安全问题。但是,当软件确实具有以用户为中心的设计时,它会考虑到平均用户行为而不是迎合个人的行为。因此,系统设计师已经从为安全专家设计到现在吸引最不常见的分母。该项目的目的是检查对个人量身定制安全性缓解的方式,以及与以用户为中心的设计相比,这可能会导致更大的安全合规性。具体而言,这项研究重点是证明如何通过间接测量和推断个体差异来为个人量身定制安全性缓解。这项研究可以帮助安全和隐私工程师开发更个性化和显着的手段,以提醒用户了解安全性和隐私风险,从而增加用户对安全消息的依从性,从而减少对用户及其组织的威胁。对安全性缓解的挑战是,个性化安全性的挑战是推断用户之间的个体差异,这些用户可以预测他们是否对某人对某人的响应更为良好地响应了一种对某人的响应。这种方法依赖于在心理学和决策文献中使用良好的个体差异,这些文献可预测遵守计算机安全性缓解。这项研究旨在在选择体系结构和“轻推”上进行广泛的工作,旨在个性化对特定用户特征的安全性缓解,以便能够动态地向每个用户展示对她最有效的安全性“ Nudge”。例如,如果目标用户在决策“依赖性”(即寻求其他建议)方面的测量很高,则系统可能会说明选择了推荐选项的专家数量。具体来说,研究人员专注于基于用户心理测量特征来构建以下类型的安全性缓解类型:智能手机/平板电脑锁定屏幕注册,密码创建指令,Web浏览器警告和软件更新通知。他们的目标是实施系统,以推断用户可能对特定安全缓解设计的响应方式,然后相应地量身定制安全环境。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Serge Egelman其他文献
The Accuracy of the Demographic Inferences Shown on Google's Ad Settings
Google 广告设置中显示的人口统计推断的准确性
- DOI:
10.1145/3267323.3268962 - 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Michael Carl Tschantz;Serge Egelman;Jaeyoung Choi;N. Weaver;G. Friedland - 通讯作者:
G. Friedland
Nudge Me Right: Personalizing Online Security Nudges to People's Decision-Making Styles
推动我正确:个性化在线安全推动人们的决策风格
- DOI:
10.2139/ssrn.3324907 - 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Eyal Péer;Serge Egelman;Marian Harbach;Nathan Malkin;Arunesh Mathur;Alisa Frik - 通讯作者:
Alisa Frik
Information Design in An Aged Care Context: Views of Older Adults on Information Sharing in a Care Triad
老年护理背景下的信息设计:老年人对护理三合会信息共享的看法
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
L. Nurgalieva;Alisa Frik;Francesco Ceschel;Serge Egelman;M. Marchese - 通讯作者:
M. Marchese
The Myth of the Average User: Improving Privacy and Security Systems through Individualization
普通用户的神话:通过个性化改进隐私和安全系统
- DOI:
10.1145/2841113.2841115 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Serge Egelman;Eyal Péer - 通讯作者:
Eyal Péer
THE ANATOMY OF SMARTPHONE UNLOCKING: Why and How Android Users Around the World Lock their Phones
智能手机解锁剖析:世界各地的 Android 用户为何以及如何锁定手机
- DOI:
10.1145/3036699.3036712 - 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Nathan Malkin;Marian Harbach;A. D. Luca;Serge Egelman - 通讯作者:
Serge Egelman
Serge Egelman的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Serge Egelman', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
合作研究:SaTC:核心:小型:测量、验证和改进基于应用程序的隐私营养标签
- 批准号:
2247951 - 财政年份:2023
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
Collaborative Research: DASS: Developer Implementation of Privacy in Software Systems
合作研究:DASS:开发人员在软件系统中实施隐私
- 批准号:
2217771 - 财政年份:2022
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
SaTC: NSF-BSF: CORE: Small: Increasing Users' Cyber-Security Compliance by Reducing Present Bias
SaTC:NSF-BSF:核心:小型:通过减少当前偏差来提高用户的网络安全合规性
- 批准号:
1817249 - 财政年份:2018
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
Student Travel Support for the 17th Workshop on the Economics of Information Security (WEIS 2018)
第 17 届信息安全经济学研讨会 (WEIS 2018) 的学生旅行支持
- 批准号:
1832821 - 财政年份:2018
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
SaTC: TTP: Small: Mobile Dynamic Privacy and Security Analysis at Scale
SaTC:TTP:小型:大规模移动动态隐私和安全分析
- 批准号:
1817248 - 财政年份:2018
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Contextual Integrity: From Theory to Practice
SaTC:核心:媒介:协作:上下文完整性:从理论到实践
- 批准号:
1801501 - 财政年份:2018
- 资助金额:
$ 49.97万 - 项目类别:
Continuing Grant
Student Support for the 15th Workshop on the Economics of Information Security (WEIS 2016)
第 15 届信息安全经济学研讨会 (WEIS 2016) 的学生支持
- 批准号:
1560940 - 财政年份:2016
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Security and Privacy for Wearable and Continuous Sensing Platforms
TWC:媒介:协作:可穿戴和连续传感平台的安全和隐私
- 批准号:
1514211 - 财政年份:2015
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
EAGER: Designing Individualized Privacy and Security Systems
EAGER:设计个性化的隐私和安全系统
- 批准号:
1343433 - 财政年份:2013
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
相似国自然基金
枯草芽孢杆菌BSF01降解高效氯氰菊酯的种内群体感应机制研究
- 批准号:31871988
- 批准年份:2018
- 资助金额:59.0 万元
- 项目类别:面上项目
基于掺硼直拉单晶硅片的Al-BSF和PERC太阳电池光衰及其抑制的基础研究
- 批准号:61774171
- 批准年份:2017
- 资助金额:63.0 万元
- 项目类别:面上项目
B细胞刺激因子-2(BSF-2)与自身免疫病的关系
- 批准号:38870708
- 批准年份:1988
- 资助金额:3.0 万元
- 项目类别:面上项目
相似海外基金
NSFSaTC-BSF: TWC: Small: Cryptography and Communication Complexity
NFSaTC-BSF:TWC:小型:密码学和通信复杂性
- 批准号:
1619348 - 财政年份:2016
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
NSFSaTC-BSF: TWC: Small: Practical Succinct Proof Systems without Trusted Setup
NSFSaTC-BSF:TWC:小型:无需可信设置的实用简洁证明系统
- 批准号:
1617676 - 财政年份:2016
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
NSFSaTC-BSF: TWC: Small: Practical Plausibly Deniable Encryption through Low-Level Storage Device Behavior
NSFSaTC-BSF:TWC:小:通过低级存储设备行为实现实用的合理可否认加密
- 批准号:
1526707 - 财政年份:2015
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant
NSFSaTC-BSF: TWC: Small: Enabling Secure and Private Cloud Computing using Coresets
NFSaTC-BSF:TWC:小型:使用核心集实现安全和私有云计算
- 批准号:
1526815 - 财政年份:2015
- 资助金额:
$ 49.97万 - 项目类别:
Continuing Grant
NSFSaTC-BSF: TWC: Small: Horizons of Symmetric-Key Cryptography
NFSaTC-BSF:TWC:小:对称密钥密码学的视野
- 批准号:
1527736 - 财政年份:2015
- 资助金额:
$ 49.97万 - 项目类别:
Standard Grant