SaTC: CORE: Small: Thwarting the Malicious Insider Evolution Process: The Theory of Strained Betrayal

SaTC:核心:小:阻止恶意内部进化过程:紧张背叛理论

基本信息

  • 批准号:
    1912874
  • 负责人:
  • 金额:
    $ 29.77万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2019
  • 资助国家:
    美国
  • 起止时间:
    2019-10-01 至 2023-09-30
  • 项目状态:
    已结题

项目摘要

Data thefts by malicious insiders are a major threat to national security, as demonstrated by several recent high-profile data breaches attributed to government employees. Often, these breaches occur because loyal employees accumulate strain or become disgruntled due to a variety of psychological stressors such as social injustice, personal injustice, harassment, and overwork. Employees who reach a critical level of strain and who are unable to change their situation may develop negative feelings that can eventually lead to malicious behavior such as data theft. The Theory of Strained Betrayal, proposed by the project team, formalizes a model of this process of a loyal employee transforming into a malicious one that captures the dynamics of job strain manifestation and its culmination in malicious insider activity. This project's goal is to further develop both the theory and potential interventions to reduce employee strain, with the goal of both better understanding and ultimately reducing insider threat behavior. This project investigates insider threat activity in the context of situational factors that cause job strain in the employee who may then resort to malicious activity to reduce that strain, as described by the Theory of Strained Betrayal. In particular, the theory details the Insider Threat Kill Chain, which articulates two defining stages of the process: (1) the trigger point, when an employee is unable to find legitimate avenues for strain reduction and begins to seek opportunities for malicious activity such as data theft or sabotage; and (2) the tipping point, when the employee finds such an opportunity and conducts a malicious activity. Further, the theory posits that strain in individuals is moderated by dispositional factors and influenced by the individual's locus of control, culminating in malicious intentions and behaviors. To refine the theory, the research team will conduct a series of experimental studies designed to induce strain and measure people's willingness to exfiltrate insider data as a function of the amount of strain induced and any methods they have to release the strain, along with the dispositional factors described above. The team will also develop emotion-focused and problem-focused interventions aimed at disrupting the manifestation of malicious behavior originating from strain.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
恶意内部人员窃取数据是对国家安全的重大威胁,最近几起由政府雇员造成的备受瞩目的数据泄露事件就证明了这一点。通常,这些违规行为的发生是因为忠诚的员工因社会不公正、个人不公正、骚扰和过度工作等各种心理压力而积累压力或变得不满。压力达到临界水平且无法改变现状的员工可能会产生负面情绪,最终导致数据盗窃等恶意行为。项目团队提出的“紧张背叛理论”正式提出了一个忠诚员工转变为恶意员工这一过程的模型,该模型捕捉到了工作紧张表现的动态及其在恶意内部活动中的顶峰。该项目的目标是进一步发展理论和潜在的干预措施,以减轻员工的压力,以更好地理解并最终减少内部威胁行为。该项目在导致员工工作压力的情境因素的背景下调查内部威胁活动,然后员工可能会采取恶意活动来减轻压力,正如紧张背叛理论所描述的那样。该理论特别详细介绍了内部威胁杀伤链,它阐明了该过程的两个定义阶段:(1)触发点,即员工无法找到减少压力的合法途径,并开始寻找进行数据盗窃或破坏等恶意活动的机会; (2) 临界点,即员工发现此类机会并进行恶意活动时。此外,该理论认为,个人的压力会受到性格因素的调节,并受到个人控制点的影响,最终导致恶意的意图和行为。为了完善这一理论,研究小组将进行一系列实验研究,旨在诱发压力,并根据诱发的压力量、释放压力的方法以及上述性格因素来衡量人们泄露内部数据的意愿。该团队还将开发以情感为中心和以问题为中心的干预措施,旨在破坏源自压力的恶意行为的表现。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力优点和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Sanjay Goel其他文献

Integrating the global enterprise using Six Sigma: Business process reengineering at General Electric Wind Energy
  • DOI:
    10.1016/j.ijpe.2007.12.002
  • 发表时间:
    2008-06-01
  • 期刊:
  • 影响因子:
  • 作者:
    Sanjay Goel;Vicki Chen
  • 通讯作者:
    Vicki Chen
Direct oral anticoagulant (DOACs) prescribing practices of members of the Society of Gynecologic Oncology and American Society of Clinical Oncology (374)
  • DOI:
    10.1016/s0090-8258(22)01596-7
  • 发表时间:
    2022-08-01
  • 期刊:
  • 影响因子:
  • 作者:
    Lauren Scanlon;Sanjay Goel;Nicole Nevadunsky;Jason Wright;Gregory Gressel
  • 通讯作者:
    Gregory Gressel
Identifying distinct prognostic and predictive contributions of tumor epithelium versus tumor microenvironment in colorectal cancer
  • DOI:
    10.1186/s12885-025-13829-2
  • 发表时间:
    2025-03-12
  • 期刊:
  • 影响因子:
    3.400
  • 作者:
    Mingli Yang;Michael V. Nebozhyn;Michael J. Schell;Nishant Gandhi;Lance Pflieger;Andrey Loboda;W. Jack Pledger;Ramani Soundararajan;Michelle Maurin;Heiman Wang;Jetsen Rodriguez Silva;Ashley Alden;Domenico Coppola;Andrew Elliott;George Sledge;Moh’d Khushman;Emil Lou;Sanjay Goel;Timothy J. Yeatman
  • 通讯作者:
    Timothy J. Yeatman
Anesthetic considerations for a steroid-dependent high-risk patient undergoing minimally invasive cardiac surgery

Sanjay Goel的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Sanjay Goel', 18)}}的其他基金

SBE: Small: THE NEW SECURITY CALCULUS: Incentivizing Good User Security Behavior
SBE:小:新的安全演算:激励良好的用户安全行为
  • 批准号:
    1618212
  • 财政年份:
    2016
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Standard Grant
EDU: Flipping the Online Security Classroom - Improving Retention of Security Student Pipeline through Early Intervention
EDU:翻转在线安全课堂 - 通过早期干预提高安全学生渠道的保留率
  • 批准号:
    1318483
  • 财政年份:
    2013
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Standard Grant

相似国自然基金

胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 批准年份:
    2023
  • 资助金额:
    50 万元
  • 项目类别:
    面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
  • 批准年份:
    2022
  • 资助金额:
    52 万元
  • 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
  • 批准年份:
    2022
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
  • 批准号:
    92053110
  • 批准年份:
    2020
  • 资助金额:
    70.0 万元
  • 项目类别:
    重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
  • 批准号:
    81902805
  • 批准年份:
    2019
  • 资助金额:
    20.5 万元
  • 项目类别:
    青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
  • 批准号:
    41973063
  • 批准年份:
    2019
  • 资助金额:
    65.0 万元
  • 项目类别:
    面上项目
CORDEX-CORE区域气候模拟与预估研讨会
  • 批准号:
    41981240365
  • 批准年份:
    2019
  • 资助金额:
    1.5 万元
  • 项目类别:
    国际(地区)合作与交流项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
  • 批准号:
    31900138
  • 批准年份:
    2019
  • 资助金额:
    24.0 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
  • 批准号:
    2327427
  • 财政年份:
    2024
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
  • 批准号:
    2343387
  • 财政年份:
    2024
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
  • 批准号:
    2341206
  • 财政年份:
    2024
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
  • 批准号:
    2413046
  • 财政年份:
    2024
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Socio-Technical Approaches for Securing Cyber-Physical Systems from False Claim Attacks
SaTC:核心:小型:保护网络物理系统免受虚假声明攻击的社会技术方法
  • 批准号:
    2310470
  • 财政年份:
    2023
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Study, Detection and Containment of Influence Campaigns
SaTC:核心:小型:影响力活动的研究、检测和遏制
  • 批准号:
    2321649
  • 财政年份:
    2023
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
  • 批准号:
    2317830
  • 财政年份:
    2023
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
  • 批准号:
    2318843
  • 财政年份:
    2023
  • 资助金额:
    $ 29.77万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了