CAREER: Developing Robust Longitudinal Indicators and Early Warnings of Cybercrime
CAREER: Developing Robust Longitudinal Indicators and Early Warnings of Cybercrime
批准号:
1652610
负责人:
Tyler Moore
金额:
$42.1万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-07-01 至 2023-06-30
中文摘要
网络犯罪的激增为研究人员创造了一个机会,他们可以使用数据驱动的、最终科学的方法来研究网络安全。该项目旨在改进网络犯罪数据收集和分析的过程,以减少其危害。基于努力的指标,衡量防御者行动的影响,如清理受损资源所花费的时间,正在构建用于分析从多种类型的网络犯罪中收集的数据。正在整个项目期间收集各项指标,以便进行纵向分析,例如衡量传播所带来的任何改善。此外,研究人员还在研究设计和部署一种原型预警系统是否可行,该系统可以主动向防御者发出足够快的警报,以阻止网络犯罪活动的集中高峰。该项目的教育目标是通过提供与其他研究人员共享的网络犯罪活动的公共数据集并将其纳入课程模块来推进网络安全科学。教学活动包括改进现有课程和出版可供他人采用的独立资源。该项目正在推进对如何构建可靠的网络犯罪指标的理解。基于努力的指标有助于缓解信息不对称,因此任何人都可以看到哪些防御者正在努力清理受损的资源。这反过来又可以通过解决个别防御者逃避责任的协调问题来改善对网络犯罪的总体反应。该项目还通过收集数年的数据,推进了对网络犯罪反应如何随时间变化的理解。如果广泛分享,这些指标可以帮助激励防御者长期打击网络犯罪。该项目不仅力求确定如何编制这些指标,而且力求确定分享这些指标的最有效方式。预警系统如果成功,可以帮助防御者抢在攻击者的战术变化之前,从而大大提高对抗的效率。在该项目支持的教育项目中,数据集被添加到教授网络安全科学方法的课程模块中。不仅为研究生和本科学位课程设计模块,还为初高中学生设计模块,与PI共同开发的免费在线课程,正在开发的安全经济学教科书。
英文摘要
The proliferation of cybercrime has created an opportunity for researchers to study cybersecurity using a data-driven, and ultimately scientific, approach. This project seeks to improve the process of cybercrime data collection and analysis for the purpose of reducing its harm. Effort-based indicators, which measure the impact of defender actions such as the time taken to clean a compromised resource, are being constructed for use in analyzing data gathered on multiple categories of cybercrime. Indicators are being collected throughout the duration of the project in order to enable longitudinal analysis, for example, to measure any improvements that result from dissemination. It is also being investigated whether it is feasible to devise and deploy a prototype early-warning system that proactively alerts defenders quickly enough to arrest concentrated spikes in cybercriminal activity. The project's educational objective is to advance the science of cybersecurity by contributing public datasets of cybercriminal activity to be shared with other researchers and incorporated into curriculum modules. Instructional initiatives include improving existing curricula and publishing stand-alone resources that can be adopted by others.The project is advancing understanding of how to construct reliable cybercrime indicators. Effort-based indicators help mitigate information asymmetries, so that anyone can see which defenders are working harder to clean up compromised resources. This could in turn improve the response to cybercrime overall by solving coordination problems in which individual defenders shirk responsibility. The project is also advancing understanding of how the response to cybercrime changes over time by collecting data for several years. If widely shared, the indicators can help incentivize defenders to fight cybercrime over the long term. The project seeks to identify not only how to construct the indicators, but also what is the most effective way to share them. The early-warning system, if successful, could greatly enhance the efficiency of countermeasures by helping defenders get ahead of the shifting tactics used by attackers. In the education program supported by the project, datasets are being added to curriculum modules that teach scientific approaches to cybersecurity. Modules are being designed for not only graduate and undergraduate degree programs, but also for middle and high school students, free online courses co-developed by the PI, and a security economics textbook under development.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
Ten years of attacks on companies using visual impersonation of domain names
使用域名视觉模仿对公司进行的十年攻击
DOI:
--
发表时间:
2020
期刊:
Proceedings of the APWG Symposium on Electronic Crime Research
影响因子:
--
作者:
[Simpson, Geoffrey, Moore, Tyler, Clayton, Richard]
通讯作者:
Clayton, Richard
Empirical analysis of losses from business-email compromise
商业电子邮件泄露造成的损失的实证分析
DOI:
--
发表时间:
2020
期刊:
Proceedings of the APWG Symposium on Electronic Crime Research
影响因子:
--
作者:
[Simpson, Geoffrey, Moore, Tyler]
通讯作者:
Moore, Tyler
The County Fair Cyber Loss Distribution: Drawing Inferences from Insurance Prices
县公平网络损失分布:从保险价格中推断
DOI:
10.1145/3434403
发表时间:
2021
期刊:
Digital Threats: Research and Practice
影响因子:
--
作者:
[Woods, Daniel W., Moore, Tyler, Simpson, Andrew C.]
通讯作者:
Simpson, Andrew C.
NSF-BSF: SaTC: CORE: Small: Evaluating Cybersecurity Precautions and Harms in Israeli Enterprises
-
批准号:2147505
-
项目类别:Standard Grant
-
资助金额:$49.45万
-
财政年份:2022
-
负责人:Tyler Moore
-
依托单位:
NSFSaTC-BSF: CORE: Small: Examining the Impact of Cybersecurity Shocks on Cryptocurrency Platforms
-
批准号:1714291
-
项目类别:Standard Grant
-
资助金额:$44.58万
-
财政年份:2017
-
负责人:Tyler Moore
-
依托单位:
Graduate Research Fellowship Program
-
批准号:0636782
-
项目类别:Fellowship Award
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Tyler Moore
-
依托单位:
海外基金