课题基金 / 基金详情

CAREER: Account Security Against Interpersonal Attacks

CAREER: Account Security Against Interpersonal Attacks
职业:针对人际攻击的帐户安全
批准号:
2339679
负责人:
Rahul Chatterjee
金额:
$68.64万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-07-01 至 2029-06-30

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
帐户安全日志是由在线服务设计的,以帮助用户检测是否有未经授权的登录他们的帐户。但是,当前帐户安全日志为用户提供了不可靠的粗粒度信息,以区分他们的登录和攻击者的登录。有限的数据,如设备型号和基于IP地址的近似城市或省份,很容易被攻击者欺骗,特别是在人际攻击的情况下。人际攻击者与受害者有私交;他们可能是亲密的伴侣、家庭成员、朋友或同事。人际攻击者可能与受害者住在同一所房子或城镇,并拥有与受害者相同型号的设备,这使得受害者很难最终检测到攻击者未经授权的登录。这里的关键问题是双重的:(a)没有唯一的、不可欺骗的设备标识符来保护用户隐私,(b)人和在线服务对物理设备的识别不同。在这个项目中,我们的目标是通过开发一个设备标识符框架来解决这些问题,该框架可以唯一地标识设备,同时保护用户的隐私,用户能够识别并将这些id与他们各自的物理设备相关联,弥合人类和软件识别设备方法之间的脱节。该项目正在设计、实现和评估改进帐户安全日志的新方法,以增强对未授权登录的检测。该项目的目标是(a)设计和实施一种协议,用于派生设备的唯一且保护隐私的标识符;(b)探索在不影响用户体验的情况下让用户熟悉此类设备标识符的方法,以及(c)重新设计帐户安全日志,以纳入此类标识符,并衡量其在检测未授权日志方面的有效性。项目的更广泛影响包括:(1)制定指南并与在线服务开发商合作,以加强账户安全机制;(2)在纽约市与麦迪逊技术诊所(MTC)和终止技术滥用诊所(CETA)一起部署未经授权的登录检测,以支持IA的幸存者;(3)向学生传授细微的威胁模型,如IA的威胁模型;(4)增加少数族裔学生的参与,如女性和LGBTQ+学生。通过提供一个空间来参与和影响对他们的生活产生现实影响的技术。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Account security logs are designed by online services to help users detect if there was an unauthorized login to their accounts. However, current account security logs offer unreliable and coarse-grained information for users to differentiate their logins from attackers' logins. Limited data, such as device model and approximate city or province based on IP addresses, can be easily spoofed by attackers, especially in cases of interpersonal attacks. Interpersonal attackers know the victims personally; they may be an intimate partner, family member, friend, or colleague. An interpersonal attacker may live in the same house or town and possess devices with identical models as the victim, making it challenging for victims to conclusively detect unauthorized logins by their attackers. The key problem here is twofold: (a) there is no unique and non-spoofable device identifier that preserves user privacy, and (b) humans and online services identify physical devices differently. In this project, we aim to tackle these issues by developing a framework of device identifiers that can uniquely identify a device while preserving users' privacy and users are able to recognize and associate those ids with their respective physical device, bridging the disconnect between the methods of identifying devices by humans and software.This project is designing, implementing, and evaluating novel ways to improve account security logs to enhance unauthorized login detection. The objectives of the project are to (a) design and implement a protocol for deriving unique yet privacy preserving identifiers of devices; (b) explore methods to familiarize users with such device identifiers without disrupting their user experience, and (c) redesign account security logs to incorporate such identifiers and measure their efficacy in detecting unauthorized logs. The broader impacts of the project include: (1) producing guidelines and engaging with developers of online services to enhance account security mechanisms, (2) deploying unauthorized login detection with Madison Tech Clinic (MTC) and Clinic to End Tech Abuse (CETA) in New York City to support survivors of IA, (3) teaching students about nuanced threat models, like those of IA, and (4) increasing the participation of students from minority backgrounds, such as women and LGBTQ+ students, by providing a space to engage and influence technologies with real-world impact on their lives.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金