课题基金 / 基金详情

Making Security Work: Vulnerability Disclosure Programs (VDPs) and the Organizational Foundations of Cybersecurity

Making Security Work: Vulnerability Disclosure Programs (VDPs) and the Organizational Foundations of Cybersecurity
让安全发挥作用:漏洞披露计划 (VDP) 和网络安全的组织基础
批准号:
2203175
负责人:
Ryan Ellis
金额:
$34.13万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-06-01 至 2025-05-31

项目摘要

项目成果

Ryan Ellis的其他基金

相似基金

相关文献

中文摘要
翻译
网络安全现在是组织的当务之急。备受瞩目的数据泄露、勒索软件攻击和其他代价高昂的漏洞利用和攻击使网络安全成为各种公共和私人组织的优先事项。组织越来越多地采用漏洞披露计划(VDP)作为管理和减轻网络安全风险的关键策略。这些程序众包安全有效--他们邀请独立安全研究人员报告新发现的软件错误。然而,这些程序的采用和管理很少是简单或直接的。它们会在组织内部产生新的压力和复杂性。这个项目研究这些程序是如何工作的,重要的是,如何改进它们。保护数字网络、设备和软件是国家的一项重要优先事项。最终,该研究项目的见解将帮助组织提高其安全性。虽然组织长期依赖于内部信息技术专业知识和合同计算机服务的混合,但VDP是利用专业知识的不同方法。该项目揭示了在组织内集成这些新的软件评审直观模型所需的持续组织内工作;并评估了VDP在改善组织网络安全方面的最终有效性。具体而言,该项目涉及两个相关的研究问题:(一)需要何种形式的机构工作来创建和维持自愿发展方案?(ii)VP在提高安全性方面有多有效?为了回答这些问题,该项目创建并分析了一组新的定性和定量数据,这些数据来自选定的正在进行的VDP。收集的数据包括匿名计划数据、管理数据以及与管理VDP相关的员工的访谈。该项目提供了一个窗口:(i)组织内部如何采用,维护和转变新的网络安全实践;以及(ii)VDPs改善组织网络安全的有效性。探讨这些问题将有助于深入了解网络安全的更大组织层面以及VDP改善安全结果的有效性。更广泛地说,在解决这些研究问题时,该项目推进了对与采用和维持新的组织创新相关的经常被忽视的机构工作的深入了解。该奖项反映了NSF的法定使命,并被认为值得通过使用基金会的智力价值和更广泛的影响审查标准进行评估来支持。
英文摘要
Cybersecurity is now an organizational imperative. High-profile data breaches, ransomware attacks, and other costly exploits and attacks have made cybersecurity a priority for all manner of public and private organizations. Organizations are increasingly adopting vulnerability disclosure programs (VDPs) as a key strategy for managing and mitigating cybersecurity risk. These programs crowdsource security work—they invite independent security researchers to report newly identified software bugs. Yet, the adoption and management of these programs is rarely simple or straightforward. They can create new points of stress and complication within organization. This project examines how these programs work and, importantly, how they can be improved. Protecting digital networks, devices, and software is a key national priority. Ultimately, the research project’s insights will help organizations improve their security.While organizations have long relied on a blend of in-house information technology expertise and contracted computer services, VDPs are a different approach to harnessing expertise. This project uncovers the ongoing intra-organizational work required to integrate these new intuitional models of software review within organizations; and it assesses the ultimate effectiveness of VDPs to improve organizational cybersecurity. Specifically, the project addresses two related research questions: (i) What forms of institutional work are needed to create and sustain VDPs?; (ii) How effective are VDPs at improving security? To answer these questions, the project creates and analyzes a novel set of qualitative and quantitative data drawn from select ongoing VDPs. Collected data includes anonymized program data, administrative data, and interviews with staff associated with managing VDPs. This project provides a window into: (i) how new cybersecurity practices are adopted, maintained, and transformed by and within organizations; and (ii) the efficacy of VDPs to improve organizational cybersecurity. Answering these questions will provide insight into larger organizational dimensions of cybersecurity and the efficacy of VDPs to improve security outcomes. More broadly, in addressing these research questions, the project advances insights into the often-overlooked institutional work associated with adopting and sustaining new organizational innovations.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
RAPID International Type I: Collaborative Research: COVID Data Infrastructure Builders: Creating Resilient and Sustainable Research Collaborations
  • 批准号:
    2109966
  • 项目类别:
    Standard Grant
  • 资助金额:
    $6.99万
  • 财政年份:
    2021
  • 负责人:
    Ryan Ellis
  • 依托单位:
EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Improving the Bug Bounty System
  • 批准号:
    1915815
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2019
  • 负责人:
    Ryan Ellis
  • 依托单位:
海外基金