SaTC: CORE: Small: Collaborative: Information Disclosure and Security Policy Design: A Large-Scale Randomization Experiment in Trans-Pacific Region
SaTC:核心:小型:协作:信息披露和安全政策设计:跨太平洋地区的大规模随机化实验
基本信息
- 批准号:1718360
- 负责人:
- 金额:$ 9.15万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2017
- 资助国家:美国
- 起止时间:2017-08-01 至 2020-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
With more prominent data breaches and cybersecurity incidents, cyber insecurity is becoming a serious problem for every individual and the society. Such security incidents are partially due to the lack of relevant governmental polices and the insufficient security protection by organizations managing information assets. The investigators will design an independent Trans-Pacific cybersecurity evaluation institution that measures and reports organizations' security weaknesses. The proposed institution aims at effectively motivating organizations to achieve a desirable level of cybersecurity. An opt-in field experiment with a rigorous design will be employed to empirically evaluate the performance of organizations in the Trans-Pacific region to see how they will respond to the diversified security performance reports of malicious cybercrimes, including spam, phishing, and distributed denial of service (DDoS) attacks. Based on the experimental results, the project will provide practical and credible suggestions to policy makers and companies improve their security preparedness.As methods of data analyses, the researchers will employ potentially useful theoretical and empirical models: (i) a model that allows endogenous experiments, (ii) static and dynamic models with strategic interaction between defenders and attackers, and (iii) a cyber-insurance and reinsurance model which utilizes the PIs' comprehensive security evaluation metric. The PIs will estimate the policy relevant parameters in these models using both experimental and observational data. In addition to the existing dataset on defenders, important data sets that have been collected and will be used in the analyses of the data for attackers, such as data for phishing activity, outgoing spam mails, and real time DDoS information. Since the PIs seek to recover flexible heterogeneous effects of policies, as cybersecurity data typically exhibit a great deal of heterogeneity, they introduce semi-parametric identification and estimation methods developed in the recent econometrics literature. This work contributes to the literature on randomized field experiments in several ways: (i) to identify the problem of endogeneity in randomized field experiments due to the existence of external impact; (ii) in the context of cybersecurity, to redesign a previous experiment and by introducing empirical strategies that control for endogeneity using novel datasets on the attackers; (iii) to recover fully heterogeneous effects of treatments, which departs from a simple and restricted approach commonly taken in the literature; (iv) as some of the datasets are of high frequency (e.g., DDoS real time attack), to develop estimation methods that deal with big data issues. Theoretical models of this project contribute to cybersecurity literature by following novel features: (i) a dynamic cybersecurity game in the continuous-time framework by using stochastic analysis; (ii) a cyber-insurance model with reinsurance opportunity, and specification of the role of governments as the ultimate excessive risk taker, and a method for governments to control organization's cybersecurity investment level by altering the premium.
随着数据泄露和网络安全事件的日益突出,网络不安全正在成为每个人和社会的严重问题。此类安全事件的部分原因是缺乏相关的政府政策以及管理信息资产的组织的安全保护不足。调查人员将设计一个独立的跨太平洋网络安全评估机构,衡量和报告组织的安全弱点。拟议的机构旨在有效激励各组织实现理想的网络安全水平。将采用具有严格设计的选择性现场实验,以实证方式评估跨太平洋地区组织的性能,以了解他们将如何应对恶意网络犯罪的多样化安全性能报告,包括垃圾邮件,网络钓鱼和分布式拒绝服务(DDoS)攻击。根据实验结果,本项目将为政策制定者和企业提供切实可行的建议,以提高其安全防范能力。作为数据分析方法,研究人员将采用潜在有用的理论和经验模型:(i)允许内源性实验的模型,(ii)防御者和攻击者之间具有策略交互的静态和动态模型,以及(iii)利用PI的综合安全评估指标的网络保险和再保险模型。PI将使用实验和观测数据估计这些模型中的政策相关参数。除了现有的防御者数据集之外,还收集了重要的数据集,这些数据集将用于分析攻击者的数据,例如网络钓鱼活动数据、外发垃圾邮件数据和真实的DDoS信息。由于PI试图恢复政策的灵活异质性影响,因为网络安全数据通常表现出很大的异质性,因此它们引入了最近计量经济学文献中开发的半参数识别和估计方法。这项工作有助于随机现场实验的文献在几个方面:(一)确定随机现场实验中的问题,由于外部影响的存在;(二)在网络安全的背景下,重新设计以前的实验,并通过引入经验策略,控制使用新的数据集对攻击者的内隐攻击;(iii)恢复处理的完全异质性效应,这与文献中通常采用的简单且受限的方法不同;(iv)由于一些数据集具有高频率(例如,DDoS真实的时间攻击),以开发处理大数据问题的估计方法。该项目的理论模型通过以下新特征对网络安全文献做出了贡献:(i)通过使用随机分析在连续时间框架中进行动态网络安全博弈;(ii)具有再保险机会的网络保险模型,以及政府作为最终过度风险承担者的角色的规范,以及政府通过改变保费来控制组织的网络安全投资水平的方法。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Shu He其他文献
Analytical solutions and genuine multipartite entanglement of the three-qubit Dicke model
三量子位迪克模型的解析解和真正的多部分纠缠
- DOI:
10.1103/physreva.94.012317 - 发表时间:
2016-01 - 期刊:
- 影响因子:2.9
- 作者:
Yu-Yu Zhang;Xiang-You Chen;Shu He;Qing-Hu Chen - 通讯作者:
Qing-Hu Chen
A Wireless Control System for an Expanding-Extending Robotic Endoscope
伸缩式机器人内窥镜无线控制系统
- DOI:
10.4028/www.scientific.net/amm.602-605.1094 - 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Shu He;G. Yan;Wen Chen - 通讯作者:
Wen Chen
Editorial: Non-coding RNA and Coronary Heart Disease
- DOI:
10.3389/fcvm.2022.910396 - 发表时间:
2022 - 期刊:
- 影响因子:3.6
- 作者:
Shu He;Laiyuan Wang;Xiangming Ding;BuChun Zhang;En-Zhi Jia - 通讯作者:
En-Zhi Jia
Shedding Light on the Dark: The Impact of Legal Enforcement on Darknet Transactions
揭露黑暗:执法对暗网交易的影响
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:4.9
- 作者:
Jason Chan;Shu He;Dandan Qiao;Andrew Whinston - 通讯作者:
Andrew Whinston
Flexible, rapid self-healing and ultra-sensitive hydrogel sensor with dynamic multi-interactions for human motion detection
- DOI:
10.1016/j.eurpolymj.2024.113612 - 发表时间:
2025-01-06 - 期刊:
- 影响因子:
- 作者:
Shu He;Zeng Liu;Hongli Fang;Xinyu Wei;Zhiyue Cui;Wen Gu;Wei Shao - 通讯作者:
Wei Shao
Shu He的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
相似国自然基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
- 批准号:82371765
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
- 批准号:22303037
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
- 批准号:
- 批准年份:2020
- 资助金额:55 万元
- 项目类别:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
- 批准号:92053110
- 批准年份:2020
- 资助金额:70.0 万元
- 项目类别:重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
- 批准号:81902805
- 批准年份:2019
- 资助金额:20.5 万元
- 项目类别:青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
- 批准号:41973063
- 批准年份:2019
- 资助金额:65.0 万元
- 项目类别:面上项目
CORDEX-CORE区域气候模拟与预估研讨会
- 批准号:41981240365
- 批准年份:2019
- 资助金额:1.5 万元
- 项目类别:国际(地区)合作与交流项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
- 批准号:31900138
- 批准年份:2019
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
相似海外基金
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
- 批准号:
2327427 - 财政年份:2024
- 资助金额:
$ 9.15万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 9.15万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 9.15万 - 项目类别:
Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
- 批准号:
2343387 - 财政年份:2024
- 资助金额:
$ 9.15万 - 项目类别:
Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
- 批准号:
2341206 - 财政年份:2024
- 资助金额:
$ 9.15万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
- 批准号:
2413046 - 财政年份:2024
- 资助金额:
$ 9.15万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Socio-Technical Approaches for Securing Cyber-Physical Systems from False Claim Attacks
SaTC:核心:小型:保护网络物理系统免受虚假声明攻击的社会技术方法
- 批准号:
2310470 - 财政年份:2023
- 资助金额:
$ 9.15万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Study, Detection and Containment of Influence Campaigns
SaTC:核心:小型:影响力活动的研究、检测和遏制
- 批准号:
2321649 - 财政年份:2023
- 资助金额:
$ 9.15万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
- 批准号:
2317830 - 财政年份:2023
- 资助金额:
$ 9.15万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
- 批准号:
2318843 - 财政年份:2023
- 资助金额:
$ 9.15万 - 项目类别:
Continuing Grant