课题基金 / 基金详情

EAGER: SaTC-EDU: AI-based Humor-Integrated Social Engineering Training

EAGER: SaTC-EDU: AI-based Humor-Integrated Social Engineering Training
EAGER:SaTC-EDU:基于人工智能的幽默整合社会工程培训
批准号:
2039605
负责人:
Julia Rayz
金额:
$29.96万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-09-01 至 2024-08-31
关键词:

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
人工智能(AI)的进步为网络安全带来了新的机遇和挑战。社会工程虽然导致了大多数网络攻击,但由于多种因素的结合,它在网络安全方面构成了一个独特的难题。首先,社会工程成本低,涉及多种日益复杂和微妙的攻击模型。其次,大多数计算机用户不具备网络安全知识,只有不到30%的人被认为具备基本知识。第三,社会工程利用了人类的弱点,如习惯的形成和对说服技巧的敏感性。这一切都导致了安全方面的重大差距,因为个人没有准备好对抗社会工程。为了满足教育普通计算机用户免受社会工程攻击的需要,该项目提出了一种新的方法,该方法将利用人类心理学,就像攻击本身一样。项目团队建议创建一种易于访问且引人入胜的学习体验,通过教授计算机用户有关社会工程技术以及如何检测这些技术来促进计算机用户态度和行为的改变。该项目通过关注通常被当前网络安全教育工作边缘化的用户填补了一个重要空白,包括临时计算机用户或具有计算机焦虑症的用户,如老年人和低收入家庭。为了解决缺乏网络安全素养和日益增加的社会工程攻击的双重问题,多学科项目团队建议整合人工智能技术,利用娱乐教育的原则创建定制的社会工程教育体验。这项工作将针对非安全专业人员,并将使用借口设计地图来训练人工智能系统,以生成社会工程场景。 基于transformer的自然语言处理模型和幽默理论知识将被用来生成基于这些社会工程场景的可解释的幽默训练模式。然后,这些场景将被应用于课堂环境中,学习模式和特定的心理标记将被用于改进人工智能生成的场景。这些方法的结合将产生一个有效的网络安全教学工具,由人工智能驱动,为休闲计算机用户。该项目由安全和值得信赖的网络空间(SaTC)计划的一个特别倡议支持,以促进网络安全,人工智能和教育领域之间的新的,以前未探索的合作。SATC计划与联邦网络安全研究和发展战略计划和国家隐私研究战略保持一致,以保护和维护网络系统日益增长的社会和经济效益,同时确保安全和隐私。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Advances in artificial intelligence (AI) have introduced new opportunities and challenges in cybersecurity. Social engineering, while contributing to the majority of cyberattacks, poses a uniquely difficult problem in cybersecurity because of a combination of factors. First, social engineering is low cost and involves multiple increasingly complex and subtle attack models. Second, the majority of computer users are not cybersecurity-literate, with less than 30% judged competent on basic knowledge. Third, social engineering takes advantage of human vulnerabilities such as habit formation and susceptibility to persuasive techniques. This all results in a significant gap in security because individuals are unprepared to counteract social engineering. To address the need to educate casual computer users against social engineering attacks, this project proposes a novel approach that will take advantage of human psychology, just like the attacks themselves do. The project team proposes to create an accessible and engaging learning experience that will promote changes in attitude and behavior in computer users by teaching them about social engineering techniques and how to detect them. This project fills an important gap by focusing on users normally marginalized by current cybersecurity education efforts, including casual computer users or those with computer anxiety, such as the elderly and low-income families.To address the dual problems of a lack of cybersecurity literacy and increasing social engineering attacks, the multidisciplinary project team proposes to integrate AI techniques to create a customized social engineering education experience that utilizes the principles of entertainment education. This effort will target non-security professionals and will use pretext design maps to train AI systems to generate social engineering scenarios. Transformer-based natural language processing models and humor theory knowledge will be used to generate explainable humorous training schemas based on these social engineering scenarios. The scenarios will then be applied in a classroom setting, where learning patterns and specific psychological markers will be used to refine the AI-generated scenarios. The combination of these approaches will result in an effective cybersecurity pedagogical tool, powered by AI, for casual computer users.This project is supported by a special initiative of the Secure and Trustworthy Cyberspace (SaTC) program to foster new, previously unexplored, collaborations between the fields of cybersecurity, artificial intelligence, and education. The SaTC program aligns with the Federal Cybersecurity Research and Development Strategic Plan and the National Privacy Research Strategy to protect and preserve the growing social and economic benefits of cyber systems while ensuring security and privacy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金