CAREER: Improving the Reliability of Human-Centered Secure-Development Research
职业:提高以人为本的安全开发研究的可靠性
基本信息
- 批准号:1943215
- 负责人:
- 金额:$ 55万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-10-01 至 2025-09-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Improving software security is a critical need for the U.S. and the world. Despite significant technical advances in software security, insecure software remains a common problem, sometimes with disastrous results. Solving this problem will require understanding how human decision-making interacts with technology in the process of secure software development. However, studying these human factors is typically expensive, time-consuming and difficult, for several reasons: professional developers are a small and hard-to-reach study population, professional software development is a complex task that can be hard to mimic in a study environment, and security is, despite its criticality, often a secondary goal that can be difficult to study directly. Researchers attempting to conduct such studies must make many choices about experimental design while balancing complexity, time and cost constraints, and validity or usefulness of expected results. Unfortunately, there is little evidence-based guidance as to how best to make these choices. By conducting a variety of experiments directly comparing the effects of different experimental design choices on studies of human-centered secure development, this project will help future researchers design better experiments and deploy their resources as effectively as possible.This project will improve the validity and reliability of developer-centered security research by empirically establishing best practices and tradeoffs, building on best practices from the usable security and empirical software engineering communities. Researchers will undertake a series of methodological studies and experiments in three key areas: (a) how to design appropriate programming tasks; (b) how to choose a study environment that effectively balances experimental control with ecological validity; and (c) how to measure relevant outcomes such as developer self-efficacy and API usability. Investigators will test these critical questions of study design across multiple underlying research questions, such as comparisons of APIs, documentation resources, and security tools. The results will provide deep insights into how tradeoffs among design decisions play out in different kinds of studies, allowing researchers to make informed choices that fit best in their context. The results will be synthesized into comprehensive guidelines to help researchers conduct better studies, acquire stronger evidence, and therefore improve the process of secure development.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
提高软件安全性是美国和世界的迫切需要。尽管在软件安全方面取得了重大的技术进步,但不安全的软件仍然是一个常见的问题,有时会造成灾难性的后果。解决这个问题需要了解在安全软件开发过程中人类决策如何与技术交互。然而,研究这些人为因素通常是昂贵的,耗时的和困难的,原因有几个:专业开发人员是一个小的和难以达到的研究人群,专业软件开发是一个复杂的任务,可以很难在学习环境中模仿,和安全性,尽管其关键性,往往是一个次要的目标,可以很难直接研究。试图进行此类研究的研究人员必须对实验设计做出许多选择,同时平衡复杂性,时间和成本限制以及预期结果的有效性或有用性。不幸的是,关于如何最好地做出这些选择,几乎没有基于证据的指导。本项目通过开展多种实验,直接比较不同实验设计选择对以人为中心的安全开发研究的影响,帮助未来的研究人员设计更好的实验,并尽可能有效地部署他们的资源。本项目将通过实证建立最佳实践和权衡,提高以开发人员为中心的安全研究的有效性和可靠性,基于可用的安全和经验软件工程社区的最佳实践。研究人员将在三个关键领域开展一系列方法研究和实验:(a)如何设计适当的编程任务;(B)如何选择有效平衡实验控制与生态有效性的研究环境;(c)如何衡量开发人员自我效能和API可用性等相关成果。研究人员将在多个基础研究问题中测试研究设计的这些关键问题,例如API,文档资源和安全工具的比较。研究结果将为不同类型的研究中设计决策之间的权衡提供深入的见解,使研究人员能够做出最适合其背景的明智选择。研究结果将被综合成全面的指导方针,以帮助研究人员进行更好的研究,获得更有力的证据,从而改善安全发展的过程。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability Discovery
- DOI:10.1109/sp46215.2023.10179478
- 发表时间:2023-05
- 期刊:
- 影响因子:0
- 作者:Kelsey R. Fulton;Samantha Katcher;Kevin Song;M. Chetty;Michelle L. Mazurek;Chloé Messdaghi;Daniel Votipka
- 通讯作者:Kelsey R. Fulton;Samantha Katcher;Kevin Song;M. Chetty;Michelle L. Mazurek;Chloé Messdaghi;Daniel Votipka
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Michelle Mazurek其他文献
Michelle Mazurek的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Michelle Mazurek', 18)}}的其他基金
CICI: USCC: Supporting Scientists as End-Users in Managing Security and Privacy
CICI:USCC:支持科学家作为最终用户管理安全和隐私
- 批准号:
2232863 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Beyond App-centric Privacy: Investigating Privacy Ecosystems among Vulnerable Populations
协作研究:SaTC:核心:媒介:超越以应用程序为中心的隐私:调查弱势群体的隐私生态系统
- 批准号:
2309277 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Medium: Methods and Tools for Effective, Auditable, and Interpretable Online Ad Transparency
协作研究:SaTC:核心:媒介:有效、可审核和可解释的在线广告透明度的方法和工具
- 批准号:
2151290 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Understanding Security in the Software Development Lifecycle: A Holistic, Mixed-Methods Approach
SaTC:核心:媒介:协作:了解软件开发生命周期中的安全性:整体的混合方法方法
- 批准号:
1801545 - 财政年份:2018
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
EAGER: Collaborative Research: Toward Informing Users About Algorithmic Fairness
EAGER:协作研究:向用户通报算法公平性
- 批准号:
1844462 - 财政年份:2018
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
相似国自然基金
Improving modelling of compact binary evolution.
- 批准号:10903001
- 批准年份:2009
- 资助金额:20.0 万元
- 项目类别:青年科学基金项目
相似海外基金
CISE-MSI : RCBP-ED: CCF-FET : Improving Reliability and Durability in Phase Change Main Memory (PCM)
CISE-MSI:RCBP-ED:CCF-FET:提高相变主存储器 (PCM) 的可靠性和耐用性
- 批准号:
2318553 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Improving Affordability and Reliability of Energy Access in Uganda with River Turbines
利用水轮机提高乌干达能源获取的可承受性和可靠性
- 批准号:
10040896 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Feasibility Studies
Improving Systems Reliability Through Record/Replay
通过记录/重放提高系统可靠性
- 批准号:
RGPIN-2018-04512 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Discovery Grants Program - Individual
A Synchrophasor-Assisted Control Framework for Improving Power Quality, Reliability, and Resiliency of Modern Power Systems
用于提高现代电力系统的电能质量、可靠性和弹性的同步相量辅助控制框架
- 批准号:
RGPIN-2021-02940 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Discovery Grants Program - Individual
Experimental and theoretical investigation of geometric and compositional factors in improving the off-state breakdown voltage, reliability, and enhancement-mode operation among GaN channel hetero-structure field effect transistors
几何和成分因素在提高 GaN 沟道异质结构场效应晶体管断态击穿电压、可靠性和增强模式操作方面的实验和理论研究
- 批准号:
RGPIN-2020-05656 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Discovery Grants Program - Individual
iRECs: improving Research Ethics Expertise and Competences to Ensure Reliability and Trust in Science
iRECs:提高研究伦理专业知识和能力,确保科学的可靠性和信任
- 批准号:
10041912 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
EU-Funded
improving Research Ethics Expertise and Competences to Ensure Reliability andTrust in Science (iRECS)
提高研究伦理专业知识和能力,确保科学的可靠性和信任 (iRECS)
- 批准号:
10055935 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
EU-Funded
Improving Research Ethics Expertise and Competences to Ensure Reliability and Trust in Science
提高研究伦理专业知识和能力,确保科学的可靠性和信任
- 批准号:
10037820 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
EU-Funded
Improving the reliability of neural networks for medical imaging
提高医学成像神经网络的可靠性
- 批准号:
2742370 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Studentship
Improving the reliability of eye tracking to diagnose concussion
提高眼动追踪诊断脑震荡的可靠性
- 批准号:
10683567 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别: