课题基金 / 基金详情

EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions

EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
EDU:协作:通过点播现场竞赛教育安全人员
批准号:
1623246
负责人:
Giovanni Vigna
金额:
$14.54万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2018-08-31

项目摘要

项目成果

Giovanni Vigna的其他基金

相似基金

相关文献

中文摘要
翻译
美国正面临一场网络安全危机。最近的研究预测,到2020年,全球信息安全工作岗位将短缺150万个。缺乏合格的网络安全工作人员导致了高调的安全事件。此外,对该国关键基础设施的袭击可能会产生毁灭性的影响,远远超出我们今天所看到的经济损失。例如,随着软件定义网络等以网络为中心的新技术的出现,目标包括航空控制软件、电网,甚至网络本身。因此,教育下一代网络安全专业人员至关重要。网络安全练习,即学生分析软件以发现漏洞并加以缓解,是有效提高保护、检测和响应安全技能的优秀教学方法。安全培训要求开发人员既掌握发现软件安全漏洞所需的技能,又掌握修复现有有缺陷软件的技能。通过研究漏洞和漏洞模式所获得的知识为学生提供了实践专业知识,以补充理论安全技能。实时网络安全练习是向学生传授和强化安全概念的极佳工具。然而,现场网络安全比赛给组织者带来了巨大的时间和精力负担,因为一旦在比赛中使用了故意易受攻击的软件,它就不能再次使用。因此,花在创建故意易受攻击的软件上的所有时间和精力都用于一场比赛。此外,举办现场网络安全竞赛需要技术技能(例如,网络和服务器管理),这可能超出了教育工作者的专业知识。该项目允许任何教育工作者或学生,无论他们的技术技能如何,都可以主办他们自己的安全竞赛。此外,参与者将能够创建故意易受攻击的软件,这将刺激创造力和建设性行为。最后,这个项目将开发一个故意易受攻击的软件库,使教育工作者能够从不同的易受攻击类别中选择易受攻击的软件样本,从而促进教师的教育目标。
英文摘要
The United States is facing a cyber-security crisis. Recent studies predict a shortfall of 1.5M global information security jobs by 2020. The lack of qualified cyber-security workforce gives rise to high-profile security incidents. In addition, attacks against the nation's critical infrastructure can have devastating effect that go well beyond the financial losses that we are witnessing today. Example targets include aviation control software, the power grid, and even the networks themselves, with the advent of new and emerging network-centric technologies such as software-defined networks. Therefore, it is crucial to educate the next generation of cyber-security professionals. Cyber-security exercises, in which students analyze software to discover flaws and mitigate them, are an excellent instructional method to effectively improve the security skills of protection, detection, and response.Security training requires that developers acquire both the skills necessary to find security vulnerabilities in software, as well as the skills to fix existing flawed software. The knowledge that comes from studying vulnerabilities and vulnerability patterns provides students with the hands-on expertise to complement theoretical security skills. Live cyber-security exercises are an excellent tool to teach and reinforce security concepts in students. However, live cyber-security competitions place a significant time and effort burden on the organizers, because as soon as an intentionally-vulnerable software is used in a competition it cannot be used again. Therefore, all the time and effort spent creating the intentionally-vulnerable software is used on a single competition. In addition, running a live cyber-security competition requires technical skills (e.g., networking and server administration) that may be outside the expertise of educators. This project allows any educator or student, regardless of their technical skills, to host their own security competition. In addition, the participants will be able to create the intentionally-vulnerable software, which stimulates creativity and constructive behavior. Finally, this project will develop a repository of intentionally-vulnerable software, which allows educators to select sample vulnerable software from different vulnerability classes, furthering the educational goals of the instructor.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
AI Institute for Agent-based Cyber Threat Intelligence and Operation
  • 批准号:
    2229876
  • 项目类别:
    Cooperative Agreement
  • 资助金额:
    $1999.42万
  • 财政年份:
    2023
  • 负责人:
    Giovanni Vigna
  • 依托单位:
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
Organization of Grand Challenges in Cyber Security
海外基金