SaTc: EDU: Collaborative: An Assessment Driven Approach to Self-Directed Learning in Secure Programming (SecTutor)
SaTc:EDU:协作:安全编程中自我导向学习的评估驱动方法(SecTutor)
基本信息
- 批准号:1934279
- 负责人:
- 金额:$ 15.1万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2019
- 资助国家:美国
- 起止时间:2019-10-01 至 2024-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The field of software development needs developers to write secure code, as well as to continuously respond to evolving threats and adapt system designs to meet new security needs. This requires developers to gain a deep understanding of foundational concepts in secure programming, and continuously learn and practice defensive, secure, and robust coding. Given the current lack of consistent and comprehensive secure programming training in most computing programs, and the need for any training to evolve to meet new requirements, it is essential to have mechanisms that make secure programming training adaptive and intelligent. The goal for this project is to develop one such mechanism, named SecTutor, which is a dual-purpose adaptive testing and intelligent tutoring system. Using SecTutor, learners will be able to identify their current missing knowledge and areas of misunderstanding in secure programming, and access content to improve learning at their own pace. SecTutor will provide immediate feedback and learning analytics to motivate and guide learners.The project will take an assessment-driven approach for personalized, self-directed learning: a rigorous assessment tests the learner's level of knowledge and skill so that the intelligent tutoring system can calibrate the instruction directly to the learner. Specifically, the first step of the project will be to construct an adaptive test to diagnose learners' current level of foundational understanding in secure programming. This adaptive test will be based on a rigorously constructed secure programming concept inventory. This test will also diagnose what topics the learner is finding difficult or is fundamentally not understanding. The next step of the project will be to build an intelligent tutorial system that will provide both content and guidance for the learner to master secure programming concepts and skills. The third step will be to incorporate learning analytics into the system that will not only provide feedback to individual learners, but also provide mechanisms for instructors to gather information about their learners, compare them to other demographics, analyze secure programming questions, and adapt their curriculum to address specific challenges or customized requirements. SecTutor will eventually be integrated into other existing secure programming resources and will be adopted broadly for secure programming training.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
软件开发领域需要开发人员编写安全的代码,以及不断响应不断变化的威胁和调整系统设计以满足新的安全需求。这要求开发人员对安全编程中的基本概念有深入的理解,并不断学习和实践防御性、安全性和健壮性的编码。鉴于目前在大多数计算程序中缺乏一致和全面的安全编程培训,并且需要任何培训来发展以满足新的需求,因此有必要具有使安全编程培训自适应和智能化的机制。这个项目的目标是开发一个这样的机制,名为SecTutor,这是一个双重用途的自适应测试和智能辅导系统。使用SecTutor,学习者将能够识别他们目前在安全编程中缺少的知识和误解领域,并根据自己的进度访问内容以改进学习。SecTutor将提供即时反馈和学习分析,以激励和指导学习者。该项目将采用评估驱动的方法进行个性化、自主学习:严格的评估测试学习者的知识和技能水平,以便智能辅导系统可以直接对学习者进行校准指导。具体来说,该项目的第一步将是构建一个自适应测试,以诊断学习者目前对安全编程的基础理解水平。此自适应测试将基于严格构建的安全编程概念清单。这个测试也会诊断出哪些话题是学习者觉得困难或根本不理解的。该项目的下一步将是建立一个智能教程系统,为学习者掌握安全编程概念和技能提供内容和指导。第三步是将学习分析整合到系统中,这不仅将为个别学习者提供反馈,还将为教师提供机制,以收集有关学习者的信息,将他们与其他人口统计数据进行比较,分析安全编程问题,并调整他们的课程以应对特定挑战或定制需求。SecTutor最终会整合到其他现有的安全编程资源中,并广泛用于安全编程培训。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
SecTutor: An Intelligent Tutoring System for Secure Programming
SecTutor:安全编程智能辅导系统
- DOI:
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Ngambeki, Ida;Bishop, M.;Dai, Jun;Nico, Phillip;Mian, Shiven;Thao, Ong;Huynh, T. N.;Chance, Z.;Alhasan, Isslam;Afolabi, M.
- 通讯作者:Afolabi, M.
Validation of a Secure Programming Concept Inventory
安全编程概念清单的验证
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Ngambeki, I.;Bishop, M.;Dai, J.;Nico, P.
- 通讯作者:Nico, P.
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Matt Bishop其他文献
Effective Visualization Techniques for the Public Presentation of Transportation Projects
交通项目公开展示的有效可视化技术
- DOI:
- 发表时间:
2005 - 期刊:
- 影响因子:0
- 作者:
N. Garrick;P. Miniutti;Mark Westa;Jianhui Luo;Matt Bishop - 通讯作者:
Matt Bishop
Digital Forensics: Defining a Research Agenda
数字取证:定义研究议程
- DOI:
10.1109/hicss.2009.673 - 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
K. Nance;Bria N Hay;Matt Bishop - 通讯作者:
Matt Bishop
A Taxonomy of UNIX System and Network Vulnerabilities
- DOI:
- 发表时间:
1997 - 期刊:
- 影响因子:0
- 作者:
Matt Bishop - 通讯作者:
Matt Bishop
Matt Bishop的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Matt Bishop', 18)}}的其他基金
Collaborative Research: SaTC: EDU: Building an Electronic Voting Technology Inspired Interactive Teaching and Learning Framework for Cybersecurity Education
合作研究:SaTC:EDU:构建电子投票技术启发的网络安全教育互动教学框架
- 批准号:
2011175 - 财政年份:2020
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
CICI: CE: Improving the Security of a Science DMZ
CICI:CE:提高科学 DMZ 的安全性
- 批准号:
1739025 - 财政年份:2017
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Travel Support for Participants in the 2016 New Security Paradigms Workshop
为 2016 年新安全范式研讨会参与者提供差旅支持
- 批准号:
1644900 - 财政年份:2016
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Travel Support for Participants in the 2015 New Security Paradigms Workshop
为 2015 年新安全范式研讨会参与者提供差旅支持
- 批准号:
1550804 - 财政年份:2015
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative: Development and Testing of a Secure Programming Clinic
协作:安全编程诊所的开发和测试
- 批准号:
1303211 - 财政年份:2014
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
CC-NIE Integration: Improved Infrastructure for Data Movement and Monitoring
CC-NIE 集成:改进的数据移动和监控基础设施
- 批准号:
1246061 - 财政年份:2013
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Travel Support for Participants in the 2013 New Security Paradigms Workshop
为 2013 年新安全范式研讨会参与者提供差旅支持
- 批准号:
1313572 - 财政年份:2013
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
EAGER: Collaborative: Process-Based Technology to Support Comparison and Evaluation of the Security of Elections
EAGER:协作:基于流程的技术支持选举安全性的比较和评估
- 批准号:
1258577 - 财政年份:2012
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Auditing Voting Systems While Preserving Secrecy and Anonymity
审计投票系统,同时保持保密和匿名
- 批准号:
1049738 - 财政年份:2010
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
TC:Medium:Collaborative Research: Technological Support for Improving Election Processes
TC:中:合作研究:改善选举流程的技术支持
- 批准号:
0905503 - 财政年份:2009
- 资助金额:
$ 15.1万 - 项目类别:
Continuing Grant
相似国自然基金
EDU增强冬小麦O3抗性的生理生态学机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
- 批准号:
2312057 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: Adversarial Malware Analysis - An Artificial Intelligence Driven Hands-On Curriculum for Next Generation Cyber Security Workforce
协作研究:SaTC:EDU:对抗性恶意软件分析 - 下一代网络安全劳动力的人工智能驱动实践课程
- 批准号:
2230609 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC-EDU: Integrating Cybersecurity in Computing Curricula: A Software PBL-Driven Approach with Focus on Identity and Access Management (IAM)
合作研究:SaTC-EDU:将网络安全集成到计算课程中:以身份和访问管理 (IAM) 为重点的软件 PBL 驱动方法
- 批准号:
2302614 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: Creating Windows Advanced Memory Corruption Attack and Defense Teaching Modules
协作研究:SaTC:EDU:创建 Windows 高级内存损坏攻击和防御教学模块
- 批准号:
2325451 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
- 批准号:
2312058 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: A Comprehensive Training Program of AI for 5G and NextG Wireless Network Security
合作研究:SaTC:EDU:5G 和 NextG 无线网络安全人工智能综合培训项目
- 批准号:
2321271 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: Dual-track Role-based Learning for Cybersecurity Analysts and Engineers for Effective Defense Operation with Data Analytics
协作研究:SaTC:EDU:网络安全分析师和工程师基于角色的双轨学习,通过数据分析实现有效的防御操作
- 批准号:
2228002 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: Dual-track Role-based Learning for Cybersecurity Analysts and Engineers for Effective Defense Operation with Data Analytics
协作研究:SaTC:EDU:网络安全分析师和工程师基于角色的双轨学习,通过数据分析实现有效的防御操作
- 批准号:
2228001 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: Fire and ICE: Raising Security Awareness through Experiential Learning Activities for Building Trustworthy Deep Learning-based Applications
协作研究:SaTC:EDU:火灾和 ICE:通过体验式学习活动提高安全意识,构建值得信赖的基于深度学习的应用程序
- 批准号:
2244221 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant
Collaborative Research: EAGER: SaTC-EDU: Secure and Privacy-Preserving Adaptive Artificial Intelligence Curriculum Development for Cybersecurity
合作研究:EAGER:SaTC-EDU:安全和隐私保护的网络安全自适应人工智能课程开发
- 批准号:
2335624 - 财政年份:2023
- 资助金额:
$ 15.1万 - 项目类别:
Standard Grant