Usable Secure Software Design and Development
可用的安全软件设计和开发
基本信息
- 批准号:RGPIN-2022-04887
- 负责人:
- 金额:$ 2.11万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2022
- 资助国家:加拿大
- 起止时间:2022-01-01 至 2023-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Cybersecurity is now a problem of urgent global importance. While secure technical infrastructure remains critical, many successful and devastating attacks involve exploiting inevitable human fallibilities. Some attackers focus on deception affecting human decision-making, where end-users are tricked into trusting fraudulent email or websites, or installing malware. These lead to compromises in privacy and confidentiality, as well as theft of resources and ransomware. Other attackers focus on vulnerabilities in software code, where decades of work in software design and process do not address the adversarial nature of security, and programmers can easily overlook necessary checks or dependencies. My research program is in the general area of Usable Security, involving both Cybersecurity and Human-Computer Interaction. The program involves two specific lines of research. The first addresses end-user security decision-making. The second addresses the usable security issues that affect software developers. The work on security decision-making involves mental models. Mental model theory dates back decades, and supposes cognitive models of cause and effect that predict possible consequences. There are several related problem areas where this work is needed: website legitimacy, where attackers create fraudulent websites to deceive users to obtain credentials or provide malware; email legitimacy, where phishing email deceives users into visiting fraudulent websites or downloading malware; and software legitimacy, where attackers create malware positioned as benign software. All require users to make decisions, and in all cases users are poorly supported. I propose studying ways to design user interaction to better support and develop mental models of security, thus helping users make better security decisions. Another source of cybersecurity weakness involves software development, where accidental code vulnerabilities go undetected in software and supply chains. My particular interest has been on the collaborative aspects of software development, and I propose to extend this work to focus on collaborations relating specifically to security. Concepts for addressing security issues early within the development process have long been proposed, and seem to suggest collaboration can be very helpful. However, recent studies show these are little used and have low impact. My work will explore methods such adversarial collaboration and diverse fault detection, and I will work with software development teams to identify ways to improve.
网络安全现在是一个紧迫的全球性问题。虽然安全的技术基础设施仍然至关重要,但许多成功的破坏性攻击都涉及利用不可避免的人为错误。一些攻击者专注于影响人类决策的欺骗,最终用户被欺骗,相信欺诈性的电子邮件或网站,或安装恶意软件。这些导致隐私和机密性的妥协,以及资源盗窃和勒索软件。其他攻击者关注软件代码中的漏洞,在软件设计和过程中数十年的工作没有解决安全性的对抗性本质,程序员很容易忽略必要的检查或依赖关系。我的研究项目是在可用安全的一般领域,涉及网络安全和人机交互。该项目涉及两个具体的研究方向。第一个部分涉及最终用户的安全决策。第二部分处理影响软件开发人员的可用安全性问题。安全决策方面的工作涉及到心理模型。心理模型理论可以追溯到几十年前,它假设因果关系的认知模型可以预测可能的结果。有几个相关的问题领域需要这项工作:网站合法性,攻击者创建欺诈性网站来欺骗用户获取凭据或提供恶意软件;电子邮件合法性,其中网络钓鱼邮件欺骗用户访问欺诈性网站或下载恶意软件;还有软件的合法性,攻击者创建的恶意软件被定位为良性软件。所有这些都需要用户做出决定,而且在所有情况下,用户都得不到很好的支持。我建议研究设计用户交互的方法,以更好地支持和开发安全的心理模型,从而帮助用户做出更好的安全决策。网络安全弱点的另一个来源涉及软件开发,在软件和供应链中,意外的代码漏洞无法被发现。我特别感兴趣的是软件开发的协作方面,我建议扩展这项工作,将重点放在与安全相关的协作上。在开发过程中尽早解决安全问题的概念早已被提出,并且似乎表明协作非常有帮助。然而,最近的研究表明,这些工具很少使用,影响也很低。我的工作将探索诸如对抗性协作和多种故障检测等方法,并且我将与软件开发团队一起确定改进的方法。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Biddle, Robert其他文献
Graphical Passwords: Learning from the First Twelve Years
- DOI:
10.1145/2333112.2333114 - 发表时间:
2012-08-01 - 期刊:
- 影响因子:16.6
- 作者:
Biddle, Robert;Chiasson, Sonia;Van Oorschot, P. C. - 通讯作者:
Van Oorschot, P. C.
Abstraction and Activity in Computer-Mediated Music Production
- DOI:
10.1162/comj_a_00023 - 发表时间:
2010-12-01 - 期刊:
- 影响因子:0
- 作者:
Duignan, Matthew;Noble, James;Biddle, Robert - 通讯作者:
Biddle, Robert
Video game values: Human-computer interaction and games
- DOI:
10.1016/j.intcom.2006.08.008 - 发表时间:
2007-03-01 - 期刊:
- 影响因子:1.3
- 作者:
Barr, Pippin;Noble, James;Biddle, Robert - 通讯作者:
Biddle, Robert
User Perception of Data Breaches
- DOI:
10.1109/tpc.2021.3110545 - 发表时间:
2021-12-01 - 期刊:
- 影响因子:1.7
- 作者:
Hassanzadeh, Zahra;Biddle, Robert;Marsen, Sky - 通讯作者:
Marsen, Sky
Biddle, Robert的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Biddle, Robert', 18)}}的其他基金
New Directions in Usable Security
可用安全性的新方向
- 批准号:
RGPIN-2016-06149 - 财政年份:2021
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
New Directions in Usable Security
可用安全性的新方向
- 批准号:
RGPIN-2016-06149 - 财政年份:2020
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
New Directions in Usable Security
可用安全性的新方向
- 批准号:
RGPIN-2016-06149 - 财政年份:2019
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
New Directions in Usable Security
可用安全性的新方向
- 批准号:
RGPIN-2016-06149 - 财政年份:2018
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
New Directions in Usable Security
可用安全性的新方向
- 批准号:
RGPIN-2016-06149 - 财政年份:2017
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
New Directions in Usable Security
可用安全性的新方向
- 批准号:
RGPIN-2016-06149 - 财政年份:2016
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Design for Usable Security Everywhere
为无处不在的可用安全性而设计
- 批准号:
RGPIN-2015-05629 - 财政年份:2015
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Software design beyond usable security
超越可用安全性的软件设计
- 批准号:
311982-2010 - 财政年份:2014
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Software design beyond usable security
超越可用安全性的软件设计
- 批准号:
311982-2010 - 财政年份:2013
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
Software design beyond usable security
超越可用安全性的软件设计
- 批准号:
311982-2010 - 财政年份:2012
- 资助金额:
$ 2.11万 - 项目类别:
Discovery Grants Program - Individual
相似海外基金
SAFER - Secure Foundations: Verified Systems Software Above Full-Scale Integrated Semantics
SAFER - 安全基础:高于全面集成语义的经过验证的系统软件
- 批准号:
EP/Y035976/1 - 财政年份:2024
- 资助金额:
$ 2.11万 - 项目类别:
Research Grant
AI-Based Real-Time Fraudulent and Suspicious Activity Detection on Secure Software-Defined Wireless Networks
安全软件定义无线网络上基于人工智能的实时欺诈和可疑活动检测
- 批准号:
10076403 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Grant for R&D
TRUSTED: SecuriTy SummaRies for SecUre SofTwarE Development
值得信赖:安全软件开发的安全摘要
- 批准号:
EP/X03688X/1 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Research Grant
Collaborative Research: CCRI: New: A Scalable Hardware and Software Environment Enabling Secure Multi-party Learning
协作研究:CCRI:新:可扩展的硬件和软件环境支持安全的多方学习
- 批准号:
2347617 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Standard Grant
Study of secure system software for attack prevention and data protection
攻击防范和数据保护的安全系统软件研究
- 批准号:
23K16882 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
TRUSTED: SecuriTy SummaRies for SecUre SofTwarE Development
值得信赖:安全软件开发的安全摘要
- 批准号:
EP/X037274/1 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Research Grant
Proto-OKN Theme 1: Knowledge Graph Construction for Resilient, Trustworthy, and Secure Software Supply Chains
Proto-OKN 主题 1:构建弹性、可信、安全的软件供应链的知识图谱
- 批准号:
2333736 - 财政年份:2023
- 资助金额:
$ 2.11万 - 项目类别:
Cooperative Agreement
Collaborative Research: CCRI: New: A Scalable Hardware and Software Environment Enabling Secure Multi-party Learning
协作研究:CCRI:新:可扩展的硬件和软件环境支持安全的多方学习
- 批准号:
2213701 - 财政年份:2022
- 资助金额:
$ 2.11万 - 项目类别:
Standard Grant
Development of Secure, Virtual Desktop access to CAD/CAM software for Dental clinics and Dental labs.
为牙科诊所和牙科实验室开发安全的虚拟桌面访问 CAD/CAM 软件。
- 批准号:
10043540 - 财政年份:2022
- 资助金额:
$ 2.11万 - 项目类别:
Grant for R&D
Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain
协作提案:SaTC:前沿:实现安全可信的软件供应链
- 批准号:
2206921 - 财政年份:2022
- 资助金额:
$ 2.11万 - 项目类别:
Continuing Grant