Authentic Learning Modules for DevOps Security Education
Authentic Learning Modules for DevOps Security Education
批准号:
2209637
负责人:
Fan Wu
金额:
$12.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-06-15 至 2025-05-31
中文摘要
信息技术(IT)组织使用开发和运营(DevOps)向最终用户快速提供基于软件的服务。在软件开发过程中,经常会创建各种文档。这些材料称为软件构件,可能包括设计文档、源代码、风险评估和其他项目计划或文档。DevOps中使用的软件构件为IT组织带来了巨大的好处。然而,如果没有这些构件的安全开发,部署的软件可能会包含安全漏洞,恶意用户可以利用这些漏洞给组织造成严重后果。因此,准备成为下一代专业人员的学生需要了解(I)DevOps构件中常见的安全漏洞的后果,以及(Ii)如何通过安全开发来缓解安全漏洞。该项目旨在创造一个引人入胜和激励的学习环境,鼓励所有计算机科学专业的学生学习将网络安全集成到DevOps使用的人工制品中。该项目有可能改变软件工程和网络安全交叉领域的计算机科学教育,培养一支精通安全软件开发做法和技术的网络安全队伍。来自田纳西理工大学、肯纳索州立大学和塔斯基吉大学的首席调查人员将合作开发和部署基于学习的DevOps安全教育(ALAMOSE)模块。ALAMOSE项目将利用真实的学习,为学生提供解决现实世界问题的实用知识。将包括实验前内容传播、动手练习和实验后活动。这些模块将部署在这三家机构现有的网络安全、软件工程和IT系统安全课程中,可能会影响来自不同背景的学生。将举办教师讲习班和外联网络研讨会,以促进采用这些单元,并收集和提供经验教训和经验反馈。此外,这些模块将通过GitHub和DockerHub等代码和容器共享平台提供给全国的教育工作者。这个项目得到了安全和值得信赖的网络空间(SATC)计划的支持,该计划为解决网络安全和隐私问题的提案提供资金,在这种情况下,特别是网络安全教育。SATC计划与联邦网络安全研究和发展战略计划和国家隐私研究战略保持一致,以保护和维护网络系统日益增长的社会和经济效益,同时确保安全和隐私。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Information technology (IT) organizations use development and operations (DevOps) to deliver software-based services rapidly to end-users. During software development, various documents are often created. These materials, referred to as software artifacts, may include design documents, source code, risk assessments, and other project plans or documentation. Software artifacts used in DevOps yield tremendous benefits for IT organizations. However, without the secure development of these artifacts, deployed software can contain security vulnerabilities which malicious users can exploit to cause serious consequences for organizations. Therefore, students who are poised to become next-generation professionals need to be educated on (i) the consequences of security weaknesses that are commonplace in DevOps artifacts and (ii) how security weaknesses can be mitigated through secure development. This project aims to create an engaging and motivating learning environment that encourages all computer science students to learn cybersecurity integration into artifacts used for DevOps. The project has the potential to transform computer science education in the cross-cutting areas of software engineering and cybersecurity and grow a cybersecurity workforce that is well-versed in secure software development practices and techniques. Principal investigators from Tennessee Tech University, Kennesaw State University, and Tuskegee University will collaborate on developing and deploying authentic learning-based modules for DevOps security education (ALAMOSE). The ALAMOSE project will leverage authentic learning, which provides students with practical knowledge to solve real-world problems. Pre-lab content dissemination, hands-on exercise, and post-lab activities will be included. The modules will be deployed in existing cybersecurity, software engineering, and IT system security courses across the three institutions, potentially impacting students from diverse backgrounds. Faculty workshops and outreach webinars will be employed to promote the adoption of the modules and to gather and present lessons learned and experiential feedback. In addition, the modules will be available to educators nationwide through code and container sharing platforms, such as GitHub and DockerHub. This project is supported by the Secure and Trustworthy Cyberspace (SaTC) program, which funds proposals that address cybersecurity and privacy, and in this case specifically cybersecurity education. The SaTC program aligns with the Federal Cybersecurity Research and Development Strategic Plan and the National Privacy Research Strategy to protect and preserve the growing social and economic benefits of cyber systems while ensuring security and privacy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2022
期刊:
2022 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW
影响因子:
--
作者:
[Faruk, M., Tasnim, M., Shahriar, H., Valero, M., Rahman, A., Wu, F.]
通讯作者:
Wu, F.
Case Study-Based Approach of Quantum Machine Learning in Cybersecurity: Quantum Support Vector Machine for Malware Classification and Protection
基于案例研究的网络安全量子机器学习方法:用于恶意软件分类和保护的量子支持向量机
DOI:
10.1109/compsac57700.2023.00161
发表时间:
2023
期刊:
and Applications Conference (COMPSAC
影响因子:
--
作者:
[Akter, Mst Shapna, Shahriar, Hossain, Iqbal Ahamed, Sheikh, Datta Gupta, Kishor, Rahman, Muhammad, Mohamed, Atef, Rahman, Mohammad, Rahman, Akond, Wu, Fan]
通讯作者:
Wu, Fan
Practitioner Perceptions of Ansible Test Smells
从业者对 Ansible 测试气味的看法
DOI:
10.1109/icsa-c57050.2023.00074
发表时间:
2023
期刊:
023 IEEE 20th International Conference on Software Architecture Companion (ICSA-C
影响因子:
--
作者:
[Zhang, Yue, Wu, Fan, Rahman, Akond]
通讯作者:
Rahman, Akond
Authentic Learning Approach for Artificial Intelligence Systems Security and Privacy
人工智能系统安全和隐私的真实学习方法
DOI:
10.1109/compsac57700.2023.00151
发表时间:
2023
期刊:
and Applications Conference (COMPSAC
影响因子:
--
作者:
[Akter, Mst Shapna, Shahriar, Hossain, Lo, Dan, Sakib, Nazmus, Qian, Kai, Whitman, Michael, Wu, Fan]
通讯作者:
Wu, Fan
DOI:
10.1109/compsac57700.2023.00284
发表时间:
2023-06
期刊:
2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC)
影响因子:
--
作者:
[Md Mostafizur Rahman;Aiasha Siddika Arshi;Md. Golam Moula Mehedi Hasan;Sumayia Farzana Mishu;Hossain Shahriar-Hossain-Sh]
通讯作者:
Md Mostafizur Rahman;Aiasha Siddika Arshi;Md. Golam Moula Mehedi Hasan;Sumayia Farzana Mishu;Hossain Shahriar-Hossain-Sh
共 7 条
Collaborative Research: CyberCorps Scholarship for Service (Renewal): Strengthening the National Cybersecurity Workforce with Integrated Learning of AI/ML and Cybersecurity
-
批准号:2234911
-
项目类别:Continuing Grant
-
资助金额:$286.35万
-
财政年份:2023
-
负责人:Fan Wu
-
依托单位:
Collaborative Research: CISE-MSI: RCBP-RF: SaTC: Building Research Capacity in AI Based Anomaly Detection in Cybersecurity
-
批准号:2131228
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2022
-
负责人:Fan Wu
-
依托单位:
Collaborative Research: SaTC: EDU: Authentic Learning of Machine Learning in Cybersecurity with Portable Hands-on Labware
-
批准号:2100134
-
项目类别:Standard Grant
-
资助金额:$12.0万
-
财政年份:2021
-
负责人:Fan Wu
-
依托单位:
Spokes: MEDIUM: SOUTH: Collaborative: Integrating Biological Big Data Research into Student Training and Education
-
批准号:1761735
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2018
-
负责人:Fan Wu
-
依托单位:
Collaborative Research: Broadening Secure Mobile Software Development (SMSD) Through Curriculum and Faculty Development
-
批准号:1723586
-
项目类别:Standard Grant
-
资助金额:$18.0万
-
财政年份:2017
-
负责人:Fan Wu
-
依托单位:
Collaborative Research: SFS Program: Strengthening the National Cyber Security Workforce
-
批准号:1663350
-
项目类别:Continuing Grant
-
资助金额:$177.61万
-
财政年份:2017
-
负责人:Fan Wu
-
依托单位:
Partnership to Provide Technology Experiences through Aerial Drones in High Schools of the Alabama Black Belt
-
批准号:1614845
-
项目类别:Standard Grant
-
资助金额:$119.26万
-
财政年份:2016
-
负责人:Fan Wu
-
依托单位:
Collaborative Project: Capacity Building in Mobile Security Through Curriculum and Faculty Development
-
批准号:1241670
-
项目类别:Standard Grant
-
资助金额:$9.92万
-
财政年份:2012
-
负责人:Fan Wu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
-
批准号:--
-
项目类别:合作创新研究团队
-
资助金额:--
-
批准年份:2024
-
负责人:姚韬
-
依托单位:
Understanding structural evolution of galaxies with machine learning
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:Nicola Rosario Napolitano
-
依托单位:
煤矿安全人机混合群智感知任务的约束动态多目标Q-learning进化分配
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:吉建娇
-
依托单位:
基于领弹失效考量的智能弹药编队短时在线Q-learning协同控制机理
-
批准号:62003314
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:沈剑
-
依托单位:
集成上下文张量分解的e-learning资源推荐方法研究
-
批准号:61902016
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2019
-
负责人:万珊珊
-
依托单位:
具有时序迁移能力的Spiking-Transfer learning (脉冲-迁移学习)方法研究
-
批准号:61806040
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2018
-
负责人:解修蕊
-
依托单位:
基于Deep-learning的三江源区冰川监测动态识别技术研究
-
批准号:51769027
-
项目类别:地区科学基金项目
-
资助金额:38.0万元
-
批准年份:2017
-
负责人:张大奇
-
依托单位:
具有时序处理能力的Spiking-Deep Learning(脉冲深度学习)方法研究
-
批准号:61573081
-
项目类别:面上项目
-
资助金额:64.0万元
-
批准年份:2015
-
负责人:屈鸿
-
依托单位:
基于有向超图的大型个性化e-learning学习过程模型的自动生成与优化
-
批准号:61572533
-
项目类别:面上项目
-
资助金额:66.0万元
-
批准年份:2015
-
负责人:孙雪冬
-
依托单位:
E-Learning中学习者情感补偿方法的研究
-
批准号:61402392
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2014
-
负责人:秦继伟
-
依托单位: