EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
批准号:
1623246
负责人:
Giovanni Vigna
金额:
$14.54万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2018-08-31
中文摘要
美国正面临网络安全危机。最近的研究预测,到2020年,全球信息安全岗位缺口将达到150万。缺乏合格的网络安全人员导致了引人注目的安全事件。此外,对国家关键基础设施的攻击可能造成的破坏性影响远远超出我们今天所看到的经济损失。示例目标包括航空控制软件、电网,甚至网络本身,随着新兴的以网络为中心的技术(如软件定义网络)的出现。因此,教育下一代网络安全专业人员至关重要。在网络安全练习中,学生分析软件以发现缺陷并减轻缺陷,这是有效提高保护、检测和响应安全技能的一种极好的教学方法。安全培训要求开发人员掌握在软件中发现安全漏洞所必需的技能,以及修复现有有缺陷软件的技能。通过研究漏洞和漏洞模式获得的知识为学生提供了实际操作的专业知识,以补充理论上的安全技能。实时网络安全练习是教授和加强学生安全概念的绝佳工具。然而,现场网络安全竞赛给组织者带来了大量的时间和精力负担,因为一旦在竞赛中使用了故意易受攻击的软件,就不能再使用了。因此,所有用于创建故意易受攻击的软件的时间和精力都用在了单一的竞争中。此外,举办现场网络安全竞赛需要技术技能(例如,网络和服务器管理),这可能超出了教育工作者的专业知识范围。这个项目允许任何教育工作者或学生,无论他们的技术水平如何,都可以举办自己的安全竞赛。此外,参与者将能够创建故意易受攻击的软件,这将激发创造力和建设性行为。最后,该项目将开发一个故意易受攻击软件的存储库,允许教育工作者从不同的易受攻击类别中选择易受攻击的软件样本,进一步实现教师的教育目标。
英文摘要
The United States is facing a cyber-security crisis. Recent studies predict a shortfall of 1.5M global information security jobs by 2020. The lack of qualified cyber-security workforce gives rise to high-profile security incidents. In addition, attacks against the nation's critical infrastructure can have devastating effect that go well beyond the financial losses that we are witnessing today. Example targets include aviation control software, the power grid, and even the networks themselves, with the advent of new and emerging network-centric technologies such as software-defined networks. Therefore, it is crucial to educate the next generation of cyber-security professionals. Cyber-security exercises, in which students analyze software to discover flaws and mitigate them, are an excellent instructional method to effectively improve the security skills of protection, detection, and response.Security training requires that developers acquire both the skills necessary to find security vulnerabilities in software, as well as the skills to fix existing flawed software. The knowledge that comes from studying vulnerabilities and vulnerability patterns provides students with the hands-on expertise to complement theoretical security skills. Live cyber-security exercises are an excellent tool to teach and reinforce security concepts in students. However, live cyber-security competitions place a significant time and effort burden on the organizers, because as soon as an intentionally-vulnerable software is used in a competition it cannot be used again. Therefore, all the time and effort spent creating the intentionally-vulnerable software is used on a single competition. In addition, running a live cyber-security competition requires technical skills (e.g., networking and server administration) that may be outside the expertise of educators. This project allows any educator or student, regardless of their technical skills, to host their own security competition. In addition, the participants will be able to create the intentionally-vulnerable software, which stimulates creativity and constructive behavior. Finally, this project will develop a repository of intentionally-vulnerable software, which allows educators to select sample vulnerable software from different vulnerability classes, furthering the educational goals of the instructor.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
AI Institute for Agent-based Cyber Threat Intelligence and Operation
-
批准号:2229876
-
项目类别:Cooperative Agreement
-
资助金额:$1999.42万
-
财政年份:2023
-
负责人:Giovanni Vigna
-
依托单位:
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
-
批准号:1704253
-
项目类别:Continuing Grant
-
资助金额:$110.16万
-
财政年份:2017
-
负责人:Giovanni Vigna
-
依托单位:
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
-
批准号:1408632
-
项目类别:Standard Grant
-
资助金额:$106.61万
-
财政年份:2014
-
负责人:Giovanni Vigna
-
依托单位:
Organization of Grand Challenges in Cyber Security
-
批准号:0939188
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2009
-
负责人:Giovanni Vigna
-
依托单位:
SGER: Grand Challenges in Cyber Security
-
批准号:0820907
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2008
-
负责人:Giovanni Vigna
-
依托单位:
CT-ER: A Framework for Live Security Exercises and Challenges
-
批准号:0716753
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Modeling and Analyzing Trust in Service-Oriented Architectures
-
批准号:0716095
-
项目类别:Standard Grant
-
资助金额:$85.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Using Structural and Behavioral Models to Detect Malware
-
批准号:0627783
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2006
-
负责人:Giovanni Vigna
-
依托单位:
CT-ISG: Multi-Model Anomaly Detection for Web-Based Applications
-
批准号:0524853
-
项目类别:Continuing grant
-
资助金额:$45.0万
-
财政年份:2005
-
负责人:Giovanni Vigna
-
依托单位:
CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
-
批准号:0238492
-
项目类别:Continuing grant
-
资助金额:$39.99万
-
财政年份:2003
-
负责人:Giovanni Vigna
-
依托单位:
Collaborative Research: MASSA: Mobile Agent System Security Through Analysis
-
批准号:0209065
-
项目类别:Continuing grant
-
资助金额:$23.01万
-
财政年份:2002
-
负责人:Giovanni Vigna
-
依托单位:
海外基金