NSFSaTC-BSF: TWC: Small: Using Individual Differences to Personalize Security Mitigations
NSFSaTC-BSF: TWC: Small: Using Individual Differences to Personalize Security Mitigations
批准号:
1528070
负责人:
Serge Egelman
金额:
$49.97万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2019-08-31
中文摘要
在过去的十年中,人们已经意识到没有考虑到人为因素导致了许多软件安全问题。然而,当软件以用户为中心设计时,它考虑的是普通用户的行为,而不是迎合个人。因此,系统设计人员已经从为安全专家设计转向现在吸引最小公分母。这个项目的目标是研究为个人量身定制安全缓解措施的方法,以及这如何可能导致比以前通过以用户为中心的设计实现的更大的安全遵从性。具体来说,本研究侧重于展示如何通过对个体差异的间接测量和推断来为个体量身定制安全缓解措施。这项研究可以帮助安全和隐私工程师开发出更加个性化和突出的方法来提醒用户注意安全和隐私风险,从而提高用户对安全消息的遵从性,从而减少对用户及其组织的威胁。个性化安全缓解的挑战在于推断用户之间的个体差异,这些差异可预测用户是否可能对一种缓解设计做出更有利的响应。这种方法依赖于使用心理学和决策文献中经过充分研究的个体差异,这些差异预测了对计算机安全缓解措施的遵守。基于对选择架构和“助推”的广泛研究,本研究旨在针对特定用户特征个性化安全缓解措施,以便能够动态地向每个用户提供对其最有效的安全“助推”。例如,如果目标用户对决策的“依赖性”(即向他人寻求建议)的衡量很高,系统可能会说明选择推荐选项的专家数量。具体来说,研究人员根据用户的心理特征重点构建了以下类型的安全缓解措施:智能手机/平板电脑锁屏注册、密码创建说明、网络浏览器警告和软件更新通知。他们的目标是实现能够推断用户可能对特定安全缓解设计做出反应的方式的系统,然后相应地定制安全环境。
英文摘要
Over the past decade, people have realized that failure to account for human factors has resulted in many software security problems. Yet, when software does feature user-centric design, it takes into account average user behavior rather than catering to the individual. Thus, systems designers have gone from designing for security experts to now appealing to the least common denominator. The goal of this project is to examine the ways in which security mitigations can be tailored to individuals, and how this is likely to result in even greater security compliance than what has been previously achieved through user-centric design. Specifically, this research focuses on demonstrating how security mitigations can be tailored to individuals through indirect measurements and inferences of individual differences. This research could help security and privacy engineers develop more personalized and salient means to alert users to security and privacy risks, which could increase users' compliance with security messaging and therefore reduce threats to users and their organizations.The challenge to personalizing security mitigations is to infer the individual differences between users that are predictive of whether they are likely to respond more favorably to one mitigation design over another. This approach relies on using well-studied individual differences in the psychology and decision-making literature that are predictive of compliance to computer security mitigations. Building on extensive work on choice architecture and "nudges," this research aims to personalize security mitigations to specific user traits in order to be able to dynamically present each user with the security "nudge" that would be most effective for her. For example, if the target user measures high on decision-making "dependence" (i.e., looking to others for advice), the system might state the number of experts who selected the recommended option. Specifically, the researchers focus on framing the following types of security mitigations based on users' psychometric traits: smartphone/tablet lock screen enrollment, password creation instructions, web browser warnings, and software update notices. Their goal is to implement systems that infer the ways in which users are likely to respond to particular security mitigation designs and then tailor security environments accordingly.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Small: Measuring, Validating and Improving upon App-Based Privacy Nutrition Labels
-
批准号:2247951
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2023
-
负责人:Serge Egelman
-
依托单位:
Collaborative Research: DASS: Developer Implementation of Privacy in Software Systems
-
批准号:2217771
-
项目类别:Standard Grant
-
资助金额:$43.94万
-
财政年份:2022
-
负责人:Serge Egelman
-
依托单位:
SaTC: NSF-BSF: CORE: Small: Increasing Users' Cyber-Security Compliance by Reducing Present Bias
-
批准号:1817249
-
项目类别:Standard Grant
-
资助金额:$49.97万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
Student Travel Support for the 17th Workshop on the Economics of Information Security (WEIS 2018)
-
批准号:1832821
-
项目类别:Standard Grant
-
资助金额:$1.2万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
SaTC: TTP: Small: Mobile Dynamic Privacy and Security Analysis at Scale
-
批准号:1817248
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
SaTC: CORE: Medium: Collaborative: Contextual Integrity: From Theory to Practice
-
批准号:1801501
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2018
-
负责人:Serge Egelman
-
依托单位:
Student Support for the 15th Workshop on the Economics of Information Security (WEIS 2016)
-
批准号:1560940
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2016
-
负责人:Serge Egelman
-
依托单位:
TWC: Medium: Collaborative: Security and Privacy for Wearable and Continuous Sensing Platforms
-
批准号:1514211
-
项目类别:Standard Grant
-
资助金额:$39.97万
-
财政年份:2015
-
负责人:Serge Egelman
-
依托单位:
EAGER: Designing Individualized Privacy and Security Systems
-
批准号:1343433
-
项目类别:Standard Grant
-
资助金额:$10.1万
-
财政年份:2013
-
负责人:Serge Egelman
-
依托单位:
国内基金
海外基金
枯草芽孢杆菌BSF01降解高效氯氰菊酯的种内群体感应机制研究
-
批准号:31871988
-
项目类别:面上项目
-
资助金额:59.0万元
-
批准年份:2018
-
负责人:钟国华
-
依托单位:
基于掺硼直拉单晶硅片的Al-BSF和PERC太阳电池光衰及其抑制的基础研究
-
批准号:61774171
-
项目类别:面上项目
-
资助金额:63.0万元
-
批准年份:2017
-
负责人:艾斌
-
依托单位:
B细胞刺激因子-2(BSF-2)与自身免疫病的关系
-
批准号:38870708
-
项目类别:面上项目
-
资助金额:3.0万元
-
批准年份:1988
-
负责人:吴厚生
-
依托单位: