EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
批准号:
1623269
负责人:
Adam Doupe
金额:
$15.46万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2018-08-31
中文摘要
美国正面临网络安全危机。最近的研究预测,到2020年,全球信息安全工作岗位将短缺150万个。缺乏合格的网络安全工作人员导致了引人注目的安全事件。此外,对国家关键基础设施的袭击可能造成的破坏性影响远远超出我们今天所目睹的财政损失。示例目标包括航空控制软件,电网,甚至网络本身,以及新兴的以网络为中心的技术(如软件定义网络)的出现。因此,培养下一代网络安全专业人才至关重要。网络安全练习是一种很好的教学方法,可以有效地提高保护、检测和响应的安全技能。安全培训要求开发人员既掌握发现软件安全漏洞所需的技能,又掌握修复现有缺陷软件的技能。来自研究漏洞和漏洞模式的知识为学生提供了实践专业知识,以补充理论安全技能。实时网络安全练习是教授和加强学生安全概念的绝佳工具。然而,实时网络安全竞赛给组织者带来了巨大的时间和精力负担,因为一旦在竞赛中使用了故意易受攻击的软件,就不能再次使用。因此,所有用于创建故意易受攻击的软件的时间和精力都用于单个竞争。此外,举办网络安全竞赛需要技术技能(例如,网络和服务器管理),这可能超出了教育工作者的专业知识。该项目允许任何教育工作者或学生,无论其技术技能如何,都可以举办自己的安全竞赛。此外,参与者将能够创建故意易受攻击的软件,从而激发创造力和建设性行为。最后,该项目将开发一个故意易受攻击的软件库,它允许教育工作者从不同的脆弱性类别中选择样本易受攻击的软件,促进教师的教育目标。
英文摘要
The United States is facing a cyber-security crisis. Recent studies predict a shortfall of 1.5M global information security jobs by 2020. The lack of qualified cyber-security workforce gives rise to high-profile security incidents. In addition, attacks against the nation's critical infrastructure can have devastating effect that go well beyond the financial losses that we are witnessing today. Example targets include aviation control software, the power grid, and even the networks themselves, with the advent of new and emerging network-centric technologies such as software-defined networks. Therefore, it is crucial to educate the next generation of cyber-security professionals. Cyber-security exercises, in which students analyze software to discover flaws and mitigate them, are an excellent instructional method to effectively improve the security skills of protection, detection, and response.Security training requires that developers acquire both the skills necessary to find security vulnerabilities in software, as well as the skills to fix existing flawed software. The knowledge that comes from studying vulnerabilities and vulnerability patterns provides students with the hands-on expertise to complement theoretical security skills. Live cyber-security exercises are an excellent tool to teach and reinforce security concepts in students. However, live cyber-security competitions place a significant time and effort burden on the organizers, because as soon as an intentionally-vulnerable software is used in a competition it cannot be used again. Therefore, all the time and effort spent creating the intentionally-vulnerable software is used on a single competition. In addition, running a live cyber-security competition requires technical skills (e.g., networking and server administration) that may be outside the expertise of educators. This project allows any educator or student, regardless of their technical skills, to host their own security competition. In addition, the participants will be able to create the intentionally-vulnerable software, which stimulates creativity and constructive behavior. Finally, this project will develop a repository of intentionally-vulnerable software, which allows educators to select sample vulnerable software from different vulnerability classes, furthering the educational goals of the instructor.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Collaborative: Taming Web Content Through Automated Reduction in Browser Functionality
-
批准号:1703644
-
项目类别:Standard Grant
-
资助金额:$40.61万
-
财政年份:2017
-
负责人:Adam Doupe
-
依托单位:
CAREER: Next Generation Black-Box Web Application Vulnerability Analysis
-
批准号:1651661
-
项目类别:Continuing Grant
-
资助金额:$41.66万
-
财政年份:2017
-
负责人:Adam Doupe
-
依托单位:
海外基金