SaTC: CORE: Small: The Impacts of Human Decision-Making on Security and Robustness of Interdependent Systems

SaTC:核心:小:人类决策对相互依赖系统的安全性和鲁棒性的影响

基本信息

  • 批准号:
    1718637
  • 负责人:
  • 金额:
    $ 47.6万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2017
  • 资助国家:
    美国
  • 起止时间:
    2017-08-15 至 2022-07-31
  • 项目状态:
    已结题

项目摘要

There is a substantial body of work in behavioral economics and psychology showing that people are only partially rational, and thus consistently deviate from classical economic theory. People's perceptions of risks, rewards, and losses can differ substantially from their true values, and these perceptions can have a significant impact on the investments made to protect the systems that the individuals are managing. The objective of this research is to understand the decisions people make to protect their computer systems using realistic models of behavioral decision-making. The research encompasses formal theory to rigorously analyze and predict the outcomes that should be expected under alternative models of behavioral decision-making, and laboratory experiments with human subjects to evaluate the predictions made by the theory and to identify new behavioral models. The research will tackle two specific classes of problems. First, it will identify the impact of behavioral decision-making in settings where different components of a large interconnected cyber-physical system are owned by different stakeholders, each deciding how much to invest in securing their owned assets. Second, it will characterize how decision-makers choose among different security technologies, open source and public versus closed source and proprietary, based on their perceived risks and rewards. The research will lead to a more complete understanding of the vulnerabilities that arise in large-scale interconnected systems, and guide us to the design of more secure systems, with corresponding societal benefits. This research systematically and rigorously characterizes the impact of behavioral deviations from optimal and unbounded rational choice in security settings. The work includes models of decision-making under risk and uncertainty, such as prospect theory, and how such models affect the behavior of agents who manage interdependent systems. The research brings together game-theoretic analysis to predict outcomes based on models of interacting humans and systems, computer security concepts to model how vulnerabilities are exploited and how attacks spread, and behavioral economics experiments to test the theoretical predictions and refine the models. The research is organized in two parts. The first part considers a class of interdependent security games on networks, where each player chooses security investments to protect nodes under her control; this work models applications such as multi-stakeholder SCADA systems. The research will encompass general formulations of attack probabilities, epidemic risks, attack graph models of system interdependencies, and the optimal design of networks to mitigate security vulnerabilities introduced by humans' decision-making. The second part considers a general class of common-pool resource management games, whereby players choose to split their utilization among multiple resources, each of which provides a certain rate-of-return and has a certain probability of failure. This class of games represents conditions in which decision-makers must choose between different public and proprietary security technologies. The research will characterize the impacts of prospect-theoretic decision-making and how users react to incentives provided by the resource operators or vendors. In both parts of the work, the research will identify how Nash equilibrium security investments and resource utilizations are affected by skewed perceptions of risks and rewards. Both parts include controlled behavioral economics experiments using human subjects that will evaluate the theoretical predictions and potentially yield new models of decision-making.
行为经济学和心理学中有大量的研究表明,人们只是部分理性的,因此总是偏离经典经济理论。人们对风险、回报和损失的看法可能与他们的真实价值大不相同,这些看法可能对保护个人管理的系统的投资产生重大影响。 本研究的目的是了解人们使用现实的行为决策模型来保护计算机系统的决策。该研究包括严格分析和预测在行为决策的替代模型下应该预期的结果的正式理论,以及对人类受试者进行的实验室实验,以评估该理论的预测并确定新的行为模型。这项研究将解决两类具体问题。首先,它将确定行为决策的影响,在这种情况下,一个大型互联网络物理系统的不同组件由不同的利益相关者拥有,每个利益相关者决定投资多少来保护他们拥有的资产。其次,它将描述决策者如何根据他们感知的风险和回报在不同的安全技术中进行选择,开源和公共与闭源和专有。这项研究将使我们更全面地了解大规模互联系统中出现的漏洞,并指导我们设计更安全的系统,从而产生相应的社会效益。 这项研究系统而严格地描述了安全环境中行为偏离最佳和无界理性选择的影响。这项工作包括风险和不确定性下的决策模型,如前景理论,以及这些模型如何影响管理相互依赖系统的代理人的行为。该研究汇集了博弈论分析,以预测基于人类和系统交互模型的结果,计算机安全概念,以模拟漏洞如何被利用以及攻击如何传播,以及行为经济学实验,以测试理论预测并完善模型。研究分为两部分。第一部分考虑一类网络上相互依赖的安全游戏,每个玩家选择安全投资来保护她控制下的节点;这项工作模拟了多利益相关者SCADA系统等应用程序。该研究将包括攻击概率的一般公式,流行病风险,系统相互依赖性的攻击图模型,以及网络的最佳设计,以减轻人类决策带来的安全漏洞。 第二部分考虑了一类通用的公共池资源管理游戏,玩家选择将其利用率分配给多个资源,每个资源都提供一定的回报率,并具有一定的失败概率。这类博弈代表了决策者必须在不同的公共和专有安全技术之间做出选择的条件。该研究将描述前景理论决策的影响,以及用户如何对资源运营商或供应商提供的激励措施作出反应。在这两个部分的工作中,研究将确定如何纳什均衡安全投资和资源利用受到扭曲的风险和回报的看法。这两部分都包括使用人类受试者进行的受控行为经济学实验,这些实验将评估理论预测并可能产生新的决策模型。

项目成果

期刊论文数量(20)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Proactive privacy-preserving proximity prevention through bluetooth transceivers: poster abstract
Controlling Human Utilization of Failure-Prone Systems via Taxes
通过税收控制人类对易发生故障的系统的利用
Topology-based Host-Level Attribution for Multi-Stage Attacks in Enterprise Systems using Software Defined Networks
使用软件定义网络对企业系统中的多阶段攻击进行基于拓扑的主机级归因
TASHAROK: Using Mechanism Design for Enhancing Security Resource Allocation in Interdependent Systems
TASHAROK:利用机制设计增强相互依赖系统中的安全资源分配
  • DOI:
    10.1109/sp46214.2022.9833591
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Abdallah, Mustafa;Woods, Daniel;Naghizadeh, Parinaz;Khalil, Issa;Cason, Timothy;Sundaram, Shreyas;Bagchi, Saurabh
  • 通讯作者:
    Bagchi, Saurabh
Protecting Assets with Heterogeneous Valuations under Behavioral Probability Weighting
行为概率加权下的异质估值保护资产
  • DOI:
    10.1109/cdc40024.2019.9030279
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Abdallah, Mustafa;Naghizadeh, Parinaz;Cason, Timothy;Bagchi, Saurabh;Sundaram, Shreyas
  • 通讯作者:
    Sundaram, Shreyas
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Shreyas Sundaram其他文献

Error detection and correction in switched linear controllers via periodic and non-concurrent checks
  • DOI:
    10.1016/j.automatica.2005.10.011
  • 发表时间:
    2006-03-01
  • 期刊:
  • 影响因子:
  • 作者:
    Shreyas Sundaram;Christoforos N. Hadjicostis
  • 通讯作者:
    Christoforos N. Hadjicostis
C3D: Cascade Control with Change Point Detection and Deep Koopman Learning for Autonomous Surface Vehicles
C3D:用于自主地面车辆的具有变化点检测和深度库普曼学习的级联控制
  • DOI:
    10.48550/arxiv.2403.05972
  • 发表时间:
    2024
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jianwen Li;Hyunsang Park;Wenjian Hao;Lei Xin;Jalil Chavez;Ajinkya Chaudhary;Meredith Bloss;Kyle Pattison;Christopher Vo;Devesh Upadhyay;Shreyas Sundaram;Shaoshuai Mou;N. Mahmoudian
  • 通讯作者:
    N. Mahmoudian
Policies for risk-aware sensor data collection by mobile agents
  • DOI:
    10.1016/j.automatica.2022.110391
  • 发表时间:
    2022-08-01
  • 期刊:
  • 影响因子:
  • 作者:
    Amritha Prasad;Jeffrey Hudack;Shaoshuai Mou;Shreyas Sundaram
  • 通讯作者:
    Shreyas Sundaram
Pricing schemes in processor sharing systems
  • DOI:
    10.1007/s11235-015-0132-4
  • 发表时间:
    2015-12-28
  • 期刊:
  • 影响因子:
    2.300
  • 作者:
    Sharad Birmiwal;Ravi R. Mazumdar;Shreyas Sundaram
  • 通讯作者:
    Shreyas Sundaram
Robust Online Covariance and Sparse Precision Estimation Under Arbitrary Data Corruption
任意数据损坏下​​的鲁棒在线协方差和稀疏精度估计

Shreyas Sundaram的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Shreyas Sundaram', 18)}}的其他基金

Travel Support for the 2021 American Control Conference; New Orleans, Louisiana; May 26-28, 2021
2021 年美国控制会议的差旅支持;
  • 批准号:
    2110732
  • 财政年份:
    2021
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant
CAREER: Towards Secure Large-Scale Networked Systems: Resilient Distributed Algorithms for Coordination in Networks under Cyber Attacks
职业:迈向安全的大规模网络系统:网络攻击下协调网络的弹性分布式算法
  • 批准号:
    1653648
  • 财政年份:
    2017
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant
Collaborative Research: Algorithmic and Graph-Theoretic Approaches to Optimal Sensor Placement in Complex Dynamical Systems
协作研究:复杂动态系统中优化传感器放置的算法和图论方法
  • 批准号:
    1635014
  • 财政年份:
    2016
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant

相似国自然基金

胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
  • 批准年份:
    2022
  • 资助金额:
    52 万元
  • 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
  • 批准年份:
    2022
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
  • 批准号:
    92053110
  • 批准年份:
    2020
  • 资助金额:
    70.0 万元
  • 项目类别:
    重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
  • 批准号:
    81902805
  • 批准年份:
    2019
  • 资助金额:
    20.5 万元
  • 项目类别:
    青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
  • 批准号:
    41973063
  • 批准年份:
    2019
  • 资助金额:
    65.0 万元
  • 项目类别:
    面上项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
  • 批准号:
    31900138
  • 批准年份:
    2019
  • 资助金额:
    24.0 万元
  • 项目类别:
    青年科学基金项目
CORDEX-CORE区域气候模拟与预估研讨会
  • 批准号:
    41981240365
  • 批准年份:
    2019
  • 资助金额:
    1.5 万元
  • 项目类别:
    国际(地区)合作与交流项目

相似海外基金

SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
  • 批准号:
    2327427
  • 财政年份:
    2024
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
  • 批准号:
    2343387
  • 财政年份:
    2024
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
  • 批准号:
    2341206
  • 财政年份:
    2024
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
  • 批准号:
    2413046
  • 财政年份:
    2024
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Study, Detection and Containment of Influence Campaigns
SaTC:核心:小型:影响力活动的研究、检测和遏制
  • 批准号:
    2321649
  • 财政年份:
    2023
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Socio-Technical Approaches for Securing Cyber-Physical Systems from False Claim Attacks
SaTC:核心:小型:保护网络物理系统免受虚假声明攻击的社会技术方法
  • 批准号:
    2310470
  • 财政年份:
    2023
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
  • 批准号:
    2317830
  • 财政年份:
    2023
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
  • 批准号:
    2318843
  • 财政年份:
    2023
  • 资助金额:
    $ 47.6万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了