课题基金 / 基金详情

Why Johnny doesn't write secure software? Secure software development by the masses

Why Johnny doesn't write secure software? Secure software development by the masses
为什么约翰尼不编写安全软件?
批准号:
EP/P011799/2
负责人:
Awais Rashid
金额:
$108.77万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --

项目摘要

项目成果

Awais Rashid的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Do you use mobile or web apps or have Internet of Things devices on your person, in your home or workplace? Have you thought about who developed the software that drives these apps and devices, what was their understanding of cyber security, how did they make design decisions that impact the cyber security of the resulting software, and what factors influenced their behaviour and design choices? Or perhaps you are one of the masses exploiting app development platforms and easy-to-program hardware devices such as Arduino and Raspberry Pi to develop applications and deploy them for personal use or distribute them to millions of people around the world? How do you make cyber security decisions when you write software? Do you consciously think about the security implications of your design choices, or are there other factors that are more critical? What will help you achieve your goals from the software that you are developing while ensuring that it is not vulnerable to attacks by malicious actors?This project aims to develop a deep foundational understanding of these issues. We recognise that developing software is no longer the preserve for the select few with deep technical skills, training, and knowledge. A wide range of people from diverse backgrounds are increasingly developing software for mobile and web apps and for programmable consumer devices. This diversity of developers is at the heart of many innovations in the digital economy. The software they produce can be, and is, deployed across systems embedded in many aspects of human activity, and is used by a global user base. However, little is currently understood about the security behaviours and decision-making processes of 'the masses' engaged in software development. We refer to these masses by the pseudonym 'Johnny' - based on a seminal work by Whitten and Tygar where they highlighted the challenges faced by Johnny, the prototypical user of encryption. In this project we aim to tackle the challenges faced by Johnny in a contemporary setting beyond encryption. We focus on the Johnnys with diverse backgrounds, know-how and cyber security expertise who can, and are, developing software used, potentially, by millions worldwide. Drawing on a research team of experts in cyber security, software engineering, and psychology, our aim in this project is to conduct empirically-grounded research to better understand the security implications of Johnny's behaviours and practices and develop effective support for secure software development by Johnny. We propose to achieve this by uncovering and characterising the security vulnerabilities that Johnny tends to introduce, by analysing how and why these vulnerabilities are introduced, and by identifying and evaluating a range of interventions to improve Johnny's security behaviours during software development. We will do this in collaboration with eminent international research partners, drawn from leading research and practitioner organisations around the world. This project will be the first to study the inter-relationship between the cognitive and social processes that shape Johnny's cyber security decisions, their impact on the security of the resultant software and the novel interventions that may steer Johnny towards more effective cyber security decisions during software development.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1007/978-3-030-95484-0_12
发表时间: 2022
期刊:
影响因子: --
作者: [Gardiner J]
通讯作者: Gardiner J
Influences of developers' perspectives on their engagement with security in code
开发人员的观点对其参与代码安全性的影响
DOI: 10.1145/3528579.3529180
发表时间: 2022
期刊:
影响因子: --
作者: [Rauf I]
通讯作者: Rauf I
DOI: 10.1145/3471930
发表时间: 2021-06
期刊: ACM Trans. Softw. Eng. Methodol.
影响因子: --
作者: [I. Rauf;M. Petre;T. Tun;Tamara Lopez;Paul Lunn;D. Linden;J. Towse;H. Sharp;M. Levine;A. Rashid;B. Nuseibeh]
通讯作者: I. Rauf;M. Petre;T. Tun;Tamara Lopez;Paul Lunn;D. Linden;J. Towse;H. Sharp;M. Levine;A. Rashid;B. Nuseibeh
"Do this! Do that!, and Nothing will Happen" Do Specifications Lead to Securely Stored Passwords?
“这样做!那样做!,什么都不会发生”规范是否会导致安全存储密码?
DOI: 10.1109/icse43902.2021.00053
发表时间: 2021
期刊:
影响因子: --
作者: [Hallett J]
通讯作者: Hallett J
8
    Securing Convergent Ultra-large Scale Infrastructures
    • 批准号:
      EP/Z531315/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $864.03万
    • 财政年份:
      2024
    • 负责人:
      Awais Rashid
    • 依托单位:
    Equitable privacy
    • 批准号:
      EP/W025361/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $129.56万
    • 财政年份:
      2022
    • 负责人:
      Awais Rashid
    • 依托单位:
    REPHRAIN: Research centre on Privacy, Harm Reduction and Adversarial Influence online
    • 批准号:
      EP/V011189/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $888.45万
    • 财政年份:
      2020
    • 负责人:
      Awais Rashid
    • 依托单位:
    DYPOSIT: Dynamic Policies for Shared Cyber-Physical Infrastructures under Attack
    • 批准号:
      EP/N021657/2
    • 项目类别:
      Research Grant
    • 资助金额:
      $24.93万
    • 财政年份:
      2018
    • 负责人:
      Awais Rashid
    • 依托单位:
    海外基金