CAREER: Control of Information Security Risk Using Economic Incentives
CAREER: Control of Information Security Risk Using Economic Incentives
批准号:
0954234
负责人:
Terrence August
金额:
$42.22万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-02-15 至 2016-01-31
中文摘要
与通过网络进行通信的软件相关的安全风险已经成为消费者、公司和政府日益昂贵的问题。任何互连系统(例如,网络软件,如Apache HTTP服务器、智能电网和航空行李操作)的一个关键特征是,在这些系统的设计、部署和使用中所做的选择可能会对安全风险产生重大影响。由于这些选择往往是由经济权衡所驱动的,因此可以设计企业和消费者的激励措施,以鼓励开发不那么脆弱的系统。此外,由于看似不同的系统通过网络连接在一起,一个系统中的安全弱点可能会迅速给另一个系统带来重大问题。由于这些负面的外部性,政府可能需要通过监管或立法进行干预,以确保公共基础设施(例如,互联网)的关键组成部分的安全。本项目开发了一个研究框架来分析政府政策、企业和消费者的经济激励以及网络软件安全风险之间的关系。该项目的目标是获得关于如何协调公司、消费者和政府的努力以改进软件安全性的新见解。为了更好地理解这一社会技术问题,研究将产生正式的经济理论来分析这些实体之间复杂的相互作用,每个实体都有不同的经济激励。本文研究了软件安全领域的三个重要方面:软件责任、软件部署模型的影响以及开源软件对安全的激励。为了明确公共和私人力量在安全方面的相互作用,本研究项目严格研究了政府在制定软件责任政策、安全投资和技术补贴方面的作用,以帮助控制软件安全风险。它将提供关于如何在安全相互依赖的环境中使用软件责任的指导方针。此外,由于软件公司的设计选择部分地决定了给定的产品?S暴露于有向和无向安全攻击的风险,构建了一个建模框架,以检查每种类型的攻击如何在考虑用户行为的情况下明显影响软件安全;研究结果对优化软件设计具有重要意义。这项工作的一个重要成果是首次将开源软件的经济学研究与安全风险研究结合起来,这是文献中两个重要的研究流。在这个维度中,项目调查开源软件是否可以降低安全风险,并导致社会上更可取的结果。通过推进一个?让我们了解如何管理软件安全风险,这个项目将产生广泛的影响。首先,研究结果将为政策制定者提供指导,指导他们如何制定政策,在考虑企业和用户行为的同时,减轻软件安全攻击造成的巨大社会和经济损失。既然软件安全对国防至关重要,那么首先要做的就是与适当的政府机构就这个项目保持公开的对话。年代的结果。其次,这项工作可以建议软件公司改进软件设计,并使用源代码策略来实现更大的安全性。第三,社会可以从改进的软件和减少的经济损失中获益。通过让本科生和研究生参与研究过程,该项目将提供经济建模和定量分析方面的指导。作为教育活动的一部分,将产生一个案例研究,重点关注开放源代码激励和安全风险之间的相互作用。通过将研究结果和案例研究与IT课程相结合,该项目将教育未来的商业领袖有关IT策略和安全的知识。
英文摘要
Security risks associated with software that communicates over networks have become an increasingly costly problem for consumers, firms, and governments. A key characteristic of any interconnected system (e.g., network software such as Apache HTTP server, the smart grid, and airline baggage operations) is that choices made in the design, deployment, and usage of these systems can have significant implications for security risk. Because these choices are often driven by economic tradeoffs, both firm and consumer incentives can be designed to encourage the development of systems that are less vulnerable. Further, due to the fact that seemingly disparate systems are connected through the network, security weaknesses in one system can rapidly cause major problems for another. Because of these negative externalities, governments may need to intervene through regulation or legislation to ensure the security of critical components of the public infrastructure (e.g., the Internet). This project develops a research framework to analyze the relationship between government policy, economic incentives of firms and consumers, and software security risks of networks. The goal of the project is to gain new insights into how the efforts of firms, consumers, and government can be coordinated to improve software security. To better understand this socio-technical problem, the research will generate formal economic theory to analyze the complex interactions between these entities, each of whom has varying economic incentives. Three important aspects of the software security landscape are studied: software liability, the impact of software deployment models, and open source software incentives for security. To clarify the interplay between public and private forces on security, this research program rigorously studies the role of government in setting policy on software liability, security investment, and technology-specific subsidization to help control software security risks. It will provide guidelines on how software liability should be employed in a context with security interdependence. Also, since design choices by software firms partially determine a given product?s risk exposure to both directed and undirected security attacks, a modeling framework is built to examine how each type of attack distinctly influences software security in consideration of user behavior; the results have important implications for optimal software design. An important outcome of the work is to combine for the first time research on the economics of open source software with that on security risk, two significant streams of research in the literature. In this dimension, the project investigates whether open source software can lower security risks and lead to socially preferable outcomes.By advancing one?s understanding of how to manage software security risk, this project will have wideranging impacts. First, the results will provide guidance to policy makers on how to craft policies which account for firm and user behavior while mitigating the enormous social and economic losses from security attacks on software. Since software security is critical to national defense, one priority is to keep an open dialogue with appropriate government agencies on the project?s outcomes. Second, this work can advise software firms on improved software design and using source code strategy to achieve greater security. Third, society can benefit substantially from improved software and reduced economic losses. By involving undergraduate and graduate students in the research process, the project will provide mentorship on economic modeling and quantitative analysis. As part of the educational activities, a case study that focuses on the interaction between open source incentives and security risk will be generated.By integrating the research findings and the case study with IT curricula, the project will educate future business leaders on IT strategy and security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Student Travel Grant for 2017 Workshop on the Economics of Information Security (WEIS)
-
批准号:1733956
-
项目类别:Standard Grant
-
资助金额:$1.2万
-
财政年份:2017
-
负责人:Terrence August
-
依托单位:
国内基金
海外基金
Cortical control of internal state in the insular cortex-claustrum region
-
批准号:--
-
项目类别:--
-
资助金额:25万元
-
批准年份:2020
-
负责人:Robert Konrad Naumann
-
依托单位: