Security Injections: Promoting Responsible Coding and Building a Community of Security Ambassadors
Security Injections: Promoting Responsible Coding and Building a Community of Security Ambassadors
批准号:
1241738
负责人:
Siddharth Kaza
金额:
$45.19万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-09-01 至 2016-08-31
中文摘要
信息保障(IA)要求所有计算机专业毕业生做好准备,以应对当前和未来的网络安全挑战。这方面的挑战是显著的:没有受过计算机安全培训的教师,缺乏教学资源,以及课程材料过载的入门课程。Security Injections@Towson项目包括40多个安全注入模块,这些模块针对的是计算机科学入门课程中使用的关键安全概念,包括整数溢出、缓冲区溢出和输入验证。研究结果表明,这些安全注入模块可以提高学生对安全编码原理的记忆、理解和应用能力。该项目建立在安全注入模块的成功基础之上。项目团队及其合作伙伴(来自ACM社区学院计算教育委员会,三个NSF先进技术教育中心和几个不同的机构)专注于社区建设和有效的全国传播,以接触更多的学生和教师。社区建设工作包括:1)一个安全大使项目,由教授并鼓励其他人教授负责任的编码;2)一个Build-A-Lab项目,增加教学资源,提高教师的参与度、知识和主人主人感;3)在ATE中心和教育会议上开设简短的IA教学法课程。项目传播与社区建设工作协同进行,利用会议、讲习班的短期课程、通过ATE中心的外联活动和安全大使促进两年制和四年制院校采用模块。所有资源也将提交给NSDL计算路径-集成和其他场所。社区建设和传播策略使用离散的一次性讲习班(短期课程),长期专业发展(Build-A-Lab),以及通过安全大使计划作为变革来源的参与教师。该团队在本科课程开发、教育研究、能力建设经验和不同机构(包括历史上的黑人大学和社区学院)的视角方面具有优势。
英文摘要
Information Assurance (IA) requires pervasive action to prepare all computing graduates to meet the current and future cybersecurity challenges. The challenges to this are significant: instructors who are untrained in computer security, lack of teaching resources, and introductory classes overloaded with course material. The Security Injections@Towson project includes over 40 security injection modules that target key security concepts including integer overflow, buffer overflow, and input validation to be used in introductory computer science courses. Research results show that these security injection modules lead to an increase in the ability of students to remember, comprehend, and apply secure coding principles. This project builds on the success of the security injection modules. The project team and its partners (from the ACM Committee for Computing Education in Community Colleges, three NSF Advanced Technological Education (ATE) centers, and several diverse institutions) focus on community building and effective national dissemination to reach more students and faculty. Community building efforts include 1) a Security Ambassadors program with faculty who teach and encourage others to teach responsible coding, 2) a Build-A-Lab program to grow teaching resources and increase faculty engagement, knowledge, and sense of ownership, and 3) Short IA pedagogy courses at ATE centers and educational conferences. Project dissemination is synergistic with community building efforts, using short courses at conferences, workshops, outreach through ATE centers, and the security ambassadors to facilitate module adoption at two and four year institutions. All resources will also be submitted to the NSDL Computing Pathway - Ensemble and other venues. The community-building and disseminating strategy uses discrete one-time workshops (short courses), long-range professional development (Build-A-Lab), and the involvement faculty as the source of change through the Security Ambassador program. The team brings strengths in undergraduate curriculum development, education research, capacity-building experience, and the perspective of diverse institutions, including a historically-black university and community colleges.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Cyber4All: An Interdisciplinary Cybersecurity Minor for all Undergraduates
-
批准号:1516113
-
项目类别:Standard Grant
-
资助金额:$28.07万
-
财政年份:2015
-
负责人:Siddharth Kaza
-
依托单位:
Collaborative Research: CyberWorkshops: Resources and Strategies for Teaching Cybersecurity in Computer Science (CReST)
-
批准号:1438864
-
项目类别:Standard Grant
-
资助金额:$12.7万
-
财政年份:2014
-
负责人:Siddharth Kaza
-
依托单位:
海外基金