COMMANDO-HUMANS: COMputational Modelling and Automatic Non-intrusive Detection Of HUMan behAviour based iNSecurity
COMMANDO-HUMANS: COMputational Modelling and Automatic Non-intrusive Detection Of HUMan behAviour based iNSecurity
批准号:
EP/N020111/1
负责人:
Shujun Li
金额:
$26.52万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2016
资助国家:
英国
项目状态:
已结题
起止时间:
2016 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
This project addresses mainly the Human Factors challenge of the joint Singapore-UK call, and it has an interdisciplinary team with expertise in cyber security, cognitive psychology, and human-computer interface (HCI). It aims at producing direct evidence that human behaviour related insecurity can be detected automatically by applying human cognitive models to model and simulate humans involved in security systems. A key outcome of the project will be a working software system that can be used for this purpose by researchers and practitioners. The project will focus on human user authentication systems as a representative use case and will produce new knowledge on the role of human behaviours in such systems and security systems in general. Both the software framework and new knowledge on human behaviours can also help address other challenges of the call (e.g., detection of intruders/extremists requires knowledge on how they behave; protection of user privacy require knowledge on how human users handle personal data; policy makers need to understand behaviours of their organisations' employees and human attackers targeting their organisations to make more informed decisions).It has been well known that human factors are a very important aspect of cyber security, as recognised by governments all over the world e.g., in the UK Cyber Security Strategy (2011), in Singapore's National Cyber Security Masterplan 2018 (2013), and in the US Federal Cybersecurity Research and Development Strategic Plan (2011). Human related insecurity is often related to intended or unintentional (maybe subconscious) insecure human behaviours. To conduct research on human behaviours (in cyber security, HCI, psychology and other related fields), researchers normally depend on involvement of real human users via surveys, interviews, simulated scenarios, observations of real cases, interactive games, or other specially designed user studies. Such approaches are often time-consuming and costly, and suffer from other issues like limited and/or biased samples, questionable ecological validity, difficulties in reproducing results, and impossibility of running some studies due to ethical/privacy/legal concerns.This project aims at developing the first (to the best our knowledge) general-purpose computational framework and supporting software tools that will enable automatic detection of human behaviour related insecurity at the HCI level without the need to involve real human users. The framework will be built on computational models of human cognitive processes, HCIs, human behaviour related attacks and (in)security measures. The framework will be non-intrusive: instead of evaluating the running system itself, the framework will evaluate an abstract executable model of the system and humans involved. Removing real human users from the process allows faster and more objective inspection of potential insecurity of a given security system. The automated process can still be combined with traditional user studies to make better use of limited resources in automatically detecting potential insecurity problems deserving further manual analysis.The framework and software tools developed will be of great value for cyber security researchers, security system designers/developers and security industry to deliver securer systems to end users. As a natural byproduct, they will also allow easier evaluation of usability of security and non-security related computer systems with an HCI. As we mentioned above in this summary, people having concerns on other challenges of the call can benefit from the project's outcomes as well.In this project we will focus mainly on HCI-level ("micro") human behaviours, but possible extensions to higher-level ("macro") behaviours (e.g., how human users adapt their behaviours over time via rehearsals and learning) will be looked at as well to pave the way for our future research.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1186/s42400-018-0009-4
发表时间:
2018-08
期刊:
Cybersecurity
影响因子:
3.1
作者:
[Bing Chang;Yingjiu Li;Qiongxiao Wang;W. Zhu;R. Deng]
通讯作者:
Bing Chang;Yingjiu Li;Qiongxiao Wang;W. Zhu;R. Deng
DOI:
10.1016/j.cose.2018.09.003
发表时间:
2018-10
期刊:
ArXiv
影响因子:
--
作者:
[Ximing Liu;Yingjiu Li;R. Deng;Bing Chang;Shujun Li]
通讯作者:
Ximing Liu;Yingjiu Li;R. Deng;Bing Chang;Shujun Li
DOI:
10.4108/eai.13-7-2018.162797
发表时间:
2019-08
期刊:
EAI Endorsed Trans. Security Safety
影响因子:
--
作者:
[S. Alqahtani;Shujun Li;Haiyue Yuan;P. Rusconi]
通讯作者:
S. Alqahtani;Shujun Li;Haiyue Yuan;P. Rusconi
Data-driven multimedia forensics and security
数据驱动的多媒体取证和安全
DOI:
10.1016/j.jvcir.2018.06.023
发表时间:
2018
期刊:
Journal of Visual Communication and Image Representation
影响因子:
2.6
作者:
[Rocha A]
通讯作者:
Rocha A
2nd International Workshop on Multimedia Privacy and Security
第二届多媒体隐私与安全国际研讨会
DOI:
10.1145/3243734.3243876
发表时间:
2018
期刊:
影响因子:
--
作者:
[Hallman R]
通讯作者:
Hallman R
共 9 条
PRIvacy-aware personal data management and Value Enhancement for Leisure Travellers (PriVELT)
-
批准号:EP/R033749/1
-
项目类别:Research Grant
-
资助金额:$54.67万
-
财政年份:2018
-
负责人:Shujun Li
-
依托单位:
Academic Centre of Excellence in Cyber Security Research - University of Kent
-
批准号:EP/S018964/1
-
项目类别:Research Grant
-
资助金额:$8.23万
-
财政年份:2018
-
负责人:Shujun Li
-
依托单位:
ACCEPT: Addressing Cybersecurity and Cybercrime via a co-Evolutionary aPproach to reducing human-relaTed risks
-
批准号:EP/P011896/1
-
项目类别:Research Grant
-
资助金额:$112.25万
-
财政年份:2017
-
负责人:Shujun Li
-
依托单位:
ACCEPT: Addressing Cybersecurity and Cybercrime via a co-Evolutionary aPproach to reducing human-relaTed risks
-
批准号:EP/P011896/2
-
项目类别:Research Grant
-
资助金额:$97.86万
-
财政年份:2017
-
负责人:Shujun Li
-
依托单位:
海外基金