NSFSaTC-BSF: TWC: Small: Using Individual Differences to Personalize Security Mitigations
NSFSaTC-BSF: TWC: Small: Using Individual Differences to Personalize Security Mitigations
批准号:
1528070
负责人:
Serge Egelman
金额:
$49.97万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2019-08-31
中文摘要
在过去的十年里,人们已经意识到没有考虑到人为因素导致了许多软件安全问题。然而,当软件确实以用户为中心的设计时,它会考虑用户的平均行为,而不是迎合个人。因此,系统设计师已经从为安全专家设计到现在吸引最不常见的因素。这个项目的目标是研究可以为个人量身定做安全缓解的方式,以及这可能如何导致比以前通过以用户为中心的设计实现的更高的安全合规性。具体地说,这项研究侧重于演示如何通过间接测量和推断个体差异来针对个人定制安全缓解措施。这项研究可以帮助安全和隐私工程师开发更个性化和更突出的方法来提醒用户安全和隐私风险,这可能会提高用户对安全消息传递的遵从性,从而减少对用户及其组织的威胁。个性化安全缓解的挑战是推断用户之间的个体差异,这些差异可以预测他们是否可能对一种缓解设计做出比另一种更有利的响应。这种方法依赖于使用心理学和决策文献中经过充分研究的个体差异,这些差异预测了计算机安全缓解措施的遵从性。在对选择架构和“轻推”的广泛研究的基础上,这项研究旨在根据特定的用户特征个性化安全缓解,以便能够动态地向每个用户呈现对她来说最有效的安全“推”。例如,如果目标用户对决策“依赖性”的评价很高(即向他人寻求建议),则系统可能会说明选择推荐选项的专家数量。具体地说,研究人员专注于根据用户的心理特征制定以下类型的安全缓解措施:智能手机/平板电脑锁屏注册、密码创建说明、网络浏览器警告和软件更新通知。他们的目标是实施系统,以推断用户可能对特定安全缓解设计做出响应的方式,然后相应地定制安全环境。
英文摘要
Over the past decade, people have realized that failure to account for human factors has resulted in many software security problems. Yet, when software does feature user-centric design, it takes into account average user behavior rather than catering to the individual. Thus, systems designers have gone from designing for security experts to now appealing to the least common denominator. The goal of this project is to examine the ways in which security mitigations can be tailored to individuals, and how this is likely to result in even greater security compliance than what has been previously achieved through user-centric design. Specifically, this research focuses on demonstrating how security mitigations can be tailored to individuals through indirect measurements and inferences of individual differences. This research could help security and privacy engineers develop more personalized and salient means to alert users to security and privacy risks, which could increase users' compliance with security messaging and therefore reduce threats to users and their organizations.The challenge to personalizing security mitigations is to infer the individual differences between users that are predictive of whether they are likely to respond more favorably to one mitigation design over another. This approach relies on using well-studied individual differences in the psychology and decision-making literature that are predictive of compliance to computer security mitigations. Building on extensive work on choice architecture and "nudges," this research aims to personalize security mitigations to specific user traits in order to be able to dynamically present each user with the security "nudge" that would be most effective for her. For example, if the target user measures high on decision-making "dependence" (i.e., looking to others for advice), the system might state the number of experts who selected the recommended option. Specifically, the researchers focus on framing the following types of security mitigations based on users' psychometric traits: smartphone/tablet lock screen enrollment, password creation instructions, web browser warnings, and software update notices. Their goal is to implement systems that infer the ways in which users are likely to respond to particular security mitigation designs and then tailor security environments accordingly.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
-
批准号:2247951
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2023
-
负责人:Serge Egelman
-
依托单位:
Collaborative Research: DASS: Developer Implementation of Privacy in Software Systems
-
批准号:2217771
-
项目类别:Standard Grant
-
资助金额:$43.94万
-
财政年份:2022
-
负责人:Serge Egelman
-
依托单位:
SaTC: NSF-BSF: CORE: Small: Increasing Users' Cyber-Security Compliance by Reducing Present Bias
-
批准号:1817249
-
项目类别:Standard Grant
-
资助金额:$49.97万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
Student Travel Support for the 17th Workshop on the Economics of Information Security (WEIS 2018)
-
批准号:1832821
-
项目类别:Standard Grant
-
资助金额:$1.2万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
SaTC: TTP: Small: Mobile Dynamic Privacy and Security Analysis at Scale
-
批准号:1817248
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
SaTC: CORE: Medium: Collaborative: Contextual Integrity: From Theory to Practice
-
批准号:1801501
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
Student Support for the 15th Workshop on the Economics of Information Security (WEIS 2016)
-
批准号:1560940
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2016
-
负责人:Serge Egelman
-
依托单位:
TWC: Medium: Collaborative: Security and Privacy for Wearable and Continuous Sensing Platforms
-
批准号:1514211
-
项目类别:Standard Grant
-
资助金额:$39.97万
-
财政年份:2015
-
负责人:Serge Egelman
-
依托单位:
EAGER: Designing Individualized Privacy and Security Systems
-
批准号:1343433
-
项目类别:Standard Grant
-
资助金额:$10.1万
-
财政年份:2013
-
负责人:Serge Egelman
-
依托单位:
国内基金
海外基金
枯草芽孢杆菌BSF01降解高效氯氰菊酯的种内群体感应机制研究
-
批准号:31871988
-
项目类别:面上项目
-
资助金额:59.0万元
-
批准年份:2018
-
负责人:钟国华
-
依托单位:
基于掺硼直拉单晶硅片的Al-BSF和PERC太阳电池光衰及其抑制的基础研究
-
批准号:61774171
-
项目类别:面上项目
-
资助金额:63.0万元
-
批准年份:2017
-
负责人:艾斌
-
依托单位:
B细胞刺激因子-2(BSF-2)与自身免疫病的关系
-
批准号:38870708
-
项目类别:面上项目
-
资助金额:3.0万元
-
批准年份:1988
-
负责人:吴厚生
-
依托单位: