课题基金 / 基金详情

Making Security Work: Vulnerability Disclosure Programs (VDPs) and the Organizational Foundations of Cybersecurity

Making Security Work: Vulnerability Disclosure Programs (VDPs) and the Organizational Foundations of Cybersecurity
让安全发挥作用:漏洞披露计划 (VDP) 和网络安全的组织基础
批准号:
2203175
负责人:
Ryan Ellis
金额:
$34.13万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-06-01 至 2025-05-31

项目摘要

项目成果

Ryan Ellis的其他基金

相似基金

相关文献

中文摘要
翻译
网络安全现在是组织的当务之急。备受瞩目的数据泄露、勒索软件攻击以及其他代价高昂的利用和攻击使网络安全成为各种公共和私人组织的优先事项。组织越来越多地采用漏洞披露计划(VDP)作为管理和缓解网络安全风险的关键战略。这些程序将安全工作众包--它们邀请独立的安全研究人员报告新发现的软件漏洞。然而,这些项目的采用和管理很少是简单或直接的。它们会在组织内部制造新的压力点和复杂点。这个项目研究了这些计划是如何运作的,以及重要的是,如何改进它们。保护数字网络、设备和软件是国家的关键优先事项。最终,研究项目的见解将帮助组织提高其安全性。虽然组织长期以来一直依赖内部信息技术专业知识和签约计算机服务的混合,但VDPS是一种不同的利用专业知识的方法。该项目揭示了在组织内整合这些新的软件审查直观模型所需的持续的组织内工作;它还评估了VDPS改善组织网络安全的最终效力。具体地说,该项目涉及两个相关的研究问题:(1)需要何种形式的机构工作来创建和维持志愿人员保护方案;(2)志愿人员保护方案在改善安全方面有多有效?为了回答这些问题,该项目创建并分析了一组新的定性和定量数据,这些数据来自精选的正在进行的VDP。收集的数据包括匿名计划数据、管理数据以及与管理VDP相关的员工的访谈。该项目提供了一个窗口,了解:(1)各组织及其内部如何采用、维护和改造新的网络安全做法;(2)VDP在改善组织网络安全方面的效力。回答这些问题将有助于深入了解网络安全的更大组织层面以及VDP改善安全结果的有效性。更广泛地说,在解决这些研究问题时,该项目推进了对与采用和保持新的组织创新相关的经常被忽视的机构工作的洞察。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cybersecurity is now an organizational imperative. High-profile data breaches, ransomware attacks, and other costly exploits and attacks have made cybersecurity a priority for all manner of public and private organizations. Organizations are increasingly adopting vulnerability disclosure programs (VDPs) as a key strategy for managing and mitigating cybersecurity risk. These programs crowdsource security work—they invite independent security researchers to report newly identified software bugs. Yet, the adoption and management of these programs is rarely simple or straightforward. They can create new points of stress and complication within organization. This project examines how these programs work and, importantly, how they can be improved. Protecting digital networks, devices, and software is a key national priority. Ultimately, the research project’s insights will help organizations improve their security.While organizations have long relied on a blend of in-house information technology expertise and contracted computer services, VDPs are a different approach to harnessing expertise. This project uncovers the ongoing intra-organizational work required to integrate these new intuitional models of software review within organizations; and it assesses the ultimate effectiveness of VDPs to improve organizational cybersecurity. Specifically, the project addresses two related research questions: (i) What forms of institutional work are needed to create and sustain VDPs?; (ii) How effective are VDPs at improving security? To answer these questions, the project creates and analyzes a novel set of qualitative and quantitative data drawn from select ongoing VDPs. Collected data includes anonymized program data, administrative data, and interviews with staff associated with managing VDPs. This project provides a window into: (i) how new cybersecurity practices are adopted, maintained, and transformed by and within organizations; and (ii) the efficacy of VDPs to improve organizational cybersecurity. Answering these questions will provide insight into larger organizational dimensions of cybersecurity and the efficacy of VDPs to improve security outcomes. More broadly, in addressing these research questions, the project advances insights into the often-overlooked institutional work associated with adopting and sustaining new organizational innovations.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
RAPID International Type I: Collaborative Research: COVID Data Infrastructure Builders: Creating Resilient and Sustainable Research Collaborations
  • 批准号:
    2109966
  • 项目类别:
    Standard Grant
  • 资助金额:
    $6.99万
  • 财政年份:
    2021
  • 负责人:
    Ryan Ellis
  • 依托单位:
EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Improving the Bug Bounty System
  • 批准号:
    1915815
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2019
  • 负责人:
    Ryan Ellis
  • 依托单位:
海外基金