CAREER: Describing and Quantifying "Adversarial Thinking" For Cybersecurity
CAREER: Describing and Quantifying "Adversarial Thinking" For Cybersecurity
批准号:
2146129
负责人:
Peter Peterson
金额:
$81.64万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-06-01 至 2027-05-31
中文摘要
该奖项全部或部分根据2021年美国救援计划法案(公法117-2)资助。对抗性思维(AT)被广泛认为是网络安全的一种至关重要的能力。AT的重要性在网络安全社区中得到了广泛的讨论,许多教育工作者已经创建了明确旨在加强学生AT的活动和练习,以提高他们的网络安全理解和能力。然而,除了将其描述为“像攻击者一样思考”的能力之外,对AT或其组件没有广泛接受的描述。“因此,没有测试来有意义地量化AT或旨在改善AT的干预措施的有效性。为了满足这一重要需求,这个为期五年的基础建设项目将创建AT核心组件的描述。该项目将利用网络安全界不同群体的知识和经验,采用协商一致的办法。该项目将创建并验证AT的非技术测试,并使用该测试1)识别个体AT,2)评估旨在改善AT的练习的有效性。该项目将揭示AT在网络安全中的基础知识,帮助识别下一代网络安全专业人员,并为网络安全教育工作者提供工具,以提高安全教育的有效性。基于AT对安全至关重要的普遍信念,该项目的假设是:1)可以识别AT对网络安全的关键组件,2)可以创建和验证测量这些组件的非技术测试,3)该测试可用于对AT进行严格的研究,以及4)该研究可以与网络安全教育相结合并为网络安全教育提供信息。为了测试这些假设,PI将与不同的网络安全专家在修改后的德尔菲过程中合作,以确定和描述AT最关键的元素,并公布结果。然后,PI将创建,筛选偏见,严格验证并发布对抗性思维评估(ATA),这是一种衡量AT能力的工具。该测试不需要技术网络安全知识,因此可以广泛管理。使用经过验证的ATA,PI将进行实验,以确定在不同群体的学生和专业人士的AT能力。PO还将开发和评估新的干预措施,以帮助个人发展AT技能。整个项目将推动明尼苏达大学杜卢斯的两门安全课程的迭代,五年AT为重点的课程开发。该项目的影响是围绕AT在网络安全教育背景下的关键概念进行研究的新基础。该职业奖部分由NSF的IUSE:EHR计划支持,该计划支持研究和开发项目,以提高所有学生的STEM教育的有效性。该项目还得到了安全和值得信赖的网络空间(SaTC)计划的支持,该计划为解决网络安全和隐私问题的提案提供资金,在这种情况下,特别是网络安全教育。SATC计划与联邦网络安全研究和发展战略计划和国家隐私研究战略保持一致,以保护和维护网络系统日益增长的社会和经济效益,同时确保安全和隐私。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This award is funded in whole or in part under the American Rescue Plan Act of 2021 (Public Law 117-2). Adversarial Thinking (AT) is widely recognized as a critically important ability for cybersecurity. The importance of AT has been widely discussed in the cybersecurity community, and many educators have created activities and exercises explicitly intended to strengthen AT in students to enhance their cybersecurity understanding and abilities. However, there is no broadly accepted description of AT or its components beyond describing it as the ability to “think like an attacker." As a result, there is no test to meaningfully quantify AT or the effectiveness of interventions designed to improve AT. To meet this important need, this foundation-building five-year project will create a description of the core components of AT. The project will use a consensus approach drawing on the knowledge and experience of a diverse group of individuals in the cybersecurity community. The project will create and validate a non-technical test for AT and use the test to 1) identify AT in individuals and 2) evaluate the effectiveness of exercises meant to improve AT. This project will shed light on fundamental knowledge about AT in cybersecurity, help identify the next generation of cybersecurity professionals, and give cybersecurity educators tools to improve the effectiveness of security education.Based on the widespread belief that AT is critical for security, the hypotheses of this project are that 1) critical components of AT for cybersecurity can be identified, 2) a non-technical test can be created and validated that measures these components, 3) the test can be used to perform rigorous research about AT, and 4) this research can be integrated with and inform cybersecurity education. To test these hypotheses, the PI will work with a diverse set of cybersecurity experts in a modified Delphi process to identify and describe AT's most crucial elements and publish the results. The PI will then create, screen for bias, rigorously validate, and publish the Adversarial Thinking Assessment (ATA), an instrument to measure AT ability. The test will not require technical cybersecurity knowledge and hence can be administered broadly. Using the validated ATA, the PI will conduct experiments to identify AT ability across various groups of students and professionals. The PO will also develop and evaluate new interventions to help individuals develop AT skills. The overall project will drive an iterative, five-year AT-focused curriculum development for a sequence of two security courses at the University of Minnesota Duluth. The impact of this project is a new foundation for research around the critical concept of AT in the context of cybersecurity education. This CAREER award is supported in part by NSF's IUSE:EHR Program which supports research and development projects to improve the effectiveness of STEM education for all students. This project is also supported by the Secure and Trustworthy Cyberspace (SaTC) program, which funds proposals that address cybersecurity and privacy, and in this case specifically cybersecurity education. The SaTC program aligns with the Federal Cybersecurity Research and Development Strategic Plan and the National Privacy Research Strategy to protect and preserve the growing social and economic benefits of cyber systems while ensuring security and privacy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Examining Pedagogy in Cybersecurity at Military Academies
-
批准号:2138934
-
项目类别:Standard Grant
-
资助金额:$6.14万
-
财政年份:2022
-
负责人:Peter Peterson
-
依托单位:
SaTC: EDU: RUI: Enabling a New Generation of Experts by Finding and Fixing Students' Persistent Misconceptions
-
批准号:1821788
-
项目类别:Standard Grant
-
资助金额:$31.6万
-
财政年份:2018
-
负责人:Peter Peterson
-
依托单位:
Genetics of Mobile Elements in Maize
-
批准号:8818646
-
项目类别:Standard Grant
-
资助金额:$10.4万
-
财政年份:1989
-
负责人:Peter Peterson
-
依托单位:
U.S.-Federal Republic of Germany Cooperative Research on Genetics of Mobile Elements in Maize
-
批准号:8722489
-
项目类别:Standard Grant
-
资助金额:$1.41万
-
财政年份:1988
-
负责人:Peter Peterson
-
依托单位:
Genetics of Transposable Elements in Maize
-
批准号:8021575
-
项目类别:Standard Grant
-
资助金额:$21.9万
-
财政年份:1981
-
负责人:Peter Peterson
-
依托单位:
Genetics of Mutable Loci in Maize
-
批准号:7622167
-
项目类别:Standard Grant
-
资助金额:$6.6万
-
财政年份:1976
-
负责人:Peter Peterson
-
依托单位:
海外基金