课题基金 / 基金详情

ITR: Usable Security: Towards a Trustable Information Infrastructure

ITR: Usable Security: Towards a Trustable Information Infrastructure
ITR:可用的安全性:迈向可信赖的信息基础设施
批准号:
0326105
负责人:
Paul Dourish
金额:
$60.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-09-15 至 2007-08-31

项目摘要

项目成果

Paul Dourish的其他基金

相似基金

相关文献

中文摘要
翻译
该项目正在开发一个基础设施,用于可视化软件系统安全的实时状态。信息可视化利用人类感知系统的各个方面来识别复杂信息空间的显著事实、相关性和特征。通过实时呈现可视化,允许用户将系统安全与他们自己的操作联系起来,从而更深入地了解如何作为其计算机系统使用体验的一部分来增强或降低安全性。可视化提供了一种将有关系统安全的信息整合到计算机系统使用的各个方面的方法。这一点至关重要,因为联网计算机系统中的信息安全依赖于许多不同系统、组件和应用程序之间的相互关系;没有一个控制点。任何成功的方法都必须是全面的。对安全的关注不是数学抽象,而是实际情况。在日常计算中,理论安全和有效安全之间存在差距。理论安全是一个人在理论上可以达到的信息安全水平,使用强加密、零知识系统和当前的技术状态。另一方面,有效的安全是人们在实践中所能达到的信息安全的实际水平。当安全机制的实现方式使用户困惑或困惑时,系统可能具有高理论安全性但低有效安全性。在他的经典文章《为什么密码系统失败》中,Ross Anderson(1993)概述了系统安全的两个范例。一种是“自动化”模式,在这种模式下,管理信息安全的工作是自动化的,并嵌入系统的机器中。另一种是“促进”模式,在这种模式下,人类可以监测和管理安全进程,使其适应不断变化的需求和环境。他认为,许多安全故障的根源在于占主导地位的自动化范例固有的脆弱性。然而,对于普通用户来说,常规应用程序和界面的设计系统地破坏了便利化方法。建议的研究通过可视化系统安全的方法来解决这一问题。这项工作不是简单地将可用性原则应用于安全应用程序;相反,它是关于使安全成为常规用户体验的一部分。这项工作建立在调查人员在系统体系结构、软件系统可视化和最终用户对安全的理解方面的现有探索之上。然而,这些因素的结合产生了一种基础设施,它不仅是技术上的新奇,而且还具有使日益增长的网络基础设施变得可访问和日常使用安全的重大前景。在科学层面上,这项研究在四个领域做出了新的贡献:互联网用户的心理模型,可视化技术在软件系统监控中的使用,交互系统中事件架构的使用,以及用户模型和系统架构之间的关系。此外,该项目将开发一个试验性基础设施,研究界可利用该基础设施进行互动可视化和安全方面的研究。在更广泛的层面上,这项研究为整个社会提供了显著的好处。互联网作为一种文化和经济现象的影响怎么强调都不为过,但目前支持用户安全交换信息的机制是脆弱的。这一问题的解决迫在眉睫,也是本研究的目标。
英文摘要
The project is developing an infrastructure for visualizing the real-time state of software system security. Information visualization exploits aspects of the human perceptual system to recognize salient facts, correlations, and features of a complex information space. By presenting visualizations in real time, allows users to relate system security to their own actions, and thereby gain a deeper understanding of how security can be enhanced-or compromised-as a part of their experience of using computer systems. Visualization offers a means by which one can incorporate information about system security into all aspects of computer system use. This is critically important since the security of information in a networked computer system depends on the interrelationships between many different systems, components, and applications; there is no one point of control. Any successful approach must be comprehensive.A concern with security is not with mathematical abstraction but with practical reality. There is a disparity between theoretical security and effective security in day-to-day computing. Theoretical security is the level of information security one can achieve in theory, using strong encryption, zero-knowledge systems, and the current state of the art. On the other hand, effective security is the actual level of information security one can achieve in practice. A system can have high theoretical security but low effective security when the security mechanisms are implemented in ways that confuse or confound users.In his classic article "Why Cryptosystems Fail," Ross Anderson (1993) outlines two paradigms for system security. One is the "automation" paradigm, in which the work of managing information security is automated and embedded in the machinery of the system. The other is the "facilitation" paradigm, in which humans can monitor and managing the security process, adapting it to changing needs and circumstances. He argues that many security failures have their roots in the inherent brittleness of the dominant automation paradigm. However, for regular users, the design of conventional applications and interfaces systematically undermines the facilitation approach. The proposed research addresses this problem with an approach to visualizing system security. This work is not simply applying usability principles to security applications; rather, it is about making security a part of the regular user experience.This work builds on the investigators' existing explorations in system architecture, software system visualization, and end-user understandings of security. The combination of these, however, yields an infrastructure that is not only technological novel but also holds significant promise for making the growing cyber-infrastructure accessible and secure for everyday use. On a scientific level, this research makes novel contributions in four areas: the mental models of Internet users, the use of visualization technologies for software system monitoring, the use of event architectures for interactive systems, and the relationship between user models and system architecture. In addition the project will develop an experimental infrastructure that the research community can exploit for research into interactive visualization and security. At a broader level, this research offers significant benefits to society at large. The impact of the Internet as a cultural and economic phenomenon is hard to overstate, and yet the current mechanisms that support users' secure exchange of information are brittle. A resolution to this problem is pressing, and is the goal of this research.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Standard Research Grant: Beautiful Code: Aesthetic Discourse and Aesthetic Practice in a Software Organization
  • 批准号:
    1946668
  • 项目类别:
    Standard Grant
  • 资助金额:
    $35.09万
  • 财政年份:
    2020
  • 负责人:
    Paul Dourish
  • 依托单位:
CHS:MEDIUM: Understanding Public Uses of Data and Dashboards
  • 批准号:
    1901367
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $81.43万
  • 财政年份:
    2019
  • 负责人:
    Paul Dourish
  • 依托单位:
Standard Research Grant: Representational Materialities of Internet Protocols
  • 批准号:
    1556091
  • 项目类别:
    Standard Grant
  • 资助金额:
    $19.39万
  • 财政年份:
    2016
  • 负责人:
    Paul Dourish
  • 依托单位:
SBE: Small: Security as an Everyday Practical Concern
  • 批准号:
    1525861
  • 项目类别:
    Standard Grant
  • 资助金额:
    $36.38万
  • 财政年份:
    2015
  • 负责人:
    Paul Dourish
  • 依托单位:
海外基金