课题基金 / 基金详情

TWC SBE: Small: Building the human firewall: Developing organizational resistance to semantic security threats

TWC SBE: Small: Building the human firewall: Developing organizational resistance to semantic security threats
TWC SBE:小:构建人体防火墙:增强组织对语义安全威胁的抵抗力
批准号:
1421580
负责人:
Matthew Jensen
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-08-01 至 2017-07-31

项目摘要

项目成果

Matthew Jensen的其他基金

相似基金

相关文献

中文摘要
翻译
语义攻击是其他人通过模仿可靠来源的电子通信来窃取有价值的信息的努力。语义攻击的一个常见示例是网络钓鱼,即网络钓鱼者向潜在目标发送未经请求的消息。当目标个人做出响应时,网络钓鱼者就会从该个人那里窃取有价值的信息。语义攻击通过已建立的通信渠道(例如,电子邮件、社交媒体)流动,很难与合法消息区分开来。虽然大量的注意力集中在培训和提高个人对语义攻击风险的敏感度上,但很少有研究集中于组织可能用来协调组织成员之间防御行动的策略。这项研究整合了理论驱动的项目设计中的专业知识,并使用包括调查、访谈和实验在内的多种研究方法来调查组织如何构建针对语义攻击的人工防火墙。该项目为理解如何开发组织对语义攻击的抵抗力做出了新的和重要的贡献。为此,本研究的第一阶段将采用一项调查和对行业从业者的一系列访谈,以定量和定性地评估组织目前用来对抗语义攻击的策略。除了对语义攻击防御的当前技术状态产生重要的见解外,这些发现还将指导第二阶段和第三阶段的实验研究。在第二阶段,包括众包、游戏化和其他在第一阶段确定的策略将在一系列对照实验中进行测试,以检验它们在利用组织成员的能力和注意力对抗语义攻击方面的有效性。该项目的第三阶段旨在审查第二阶段确定的有希望的战略的设计和执行情况。这一阶段的目标将是了解如何通过每项战略并使最多的人遵守这些战略,以巩固这些战略所提供的任何保护。同样,在这一阶段将使用受控实验,我们将检查个人级别的变量,以了解如何鼓励采用。通过利用集成的、多方法的方法来解决日益增长的语义攻击问题,我们提案中概述的一系列研究将为未来研究和传播为公共利益服务的经验教训带来新的理论和模型。智力优势:通过识别和系统测试对抗语义攻击的组织战略的有效性,将开发新的知识。组织范围内的策略依赖于众包,并集成游戏化和其他技术来对抗语义攻击,为开发人类防火墙提供了一种新的方法,其中个人作为集体而不是作为个人来对抗这些语义攻击。通过审查对有效战略的共同解释,我们不仅将有助于有效战略,而且将有助于为其有效性提供基本理论,这将成为今后组织应对安全威胁的创新的基础。这里开发的研究框架也可能与研究除语义攻击之外的其他安全威胁的缓解相关。更广泛的影响:这项研究的发现可能还会对组织领导人和普通公众进行有关对抗语义攻击的策略的教育具有重要的实践意义。为了传播这项研究的结果,我们计划举行两次从业者会议,并开发一个公共服务网站,在网站上我们将讨论在项目期间吸取的经验教训。此外,该网站将提供基础数据,访问研究报告,以及由该项目制作的教育计划。进行实验所需的理论和方法背景的结合将对研究生和本科生研究助理的研究培训做出不可估量的贡献。最后,将通过专业介绍和出版物分享项目成果。
英文摘要
Semantic attacks are efforts by others to steal valuable information by imitating electronic communications from a trustworthy source. A common example of a semantic attack is phishing where a phisher sends unsolicited messages to potential targets. When a targeted individual responds, the phisher then steals valuable information from the individual. Semantic attacks flow through established channels of communication (e.g., email, social media) and are difficult to distinguish from legitimate messages. While a great deal of attention has focused on training and sensitizing individuals to the risks of semantic attacks, little research has focused on strategies that organizations might use to coordinate defensive actions among organization members. This research integrates expertise in a project design that is theory-driven and uses multiple research methods, including surveys, interviewing, and experimentation to investigate how organizations can build a human firewall against semantic attacks. The project holds strong promise for making new and important contributions to understanding how to develop organizational resistance to semantic attacks. To this end, the first stage of this research will employ a survey and series of interviews with industry practitioners to quantitatively and qualitatively assess the strategies that organizations currently employ to counter semantic attacks. In addition to generating important insights about the current state of the art in semantic attack defense, the findings will guide experimental studies during stages two and three. During stage two, strategies including crowdsourcing, gamification, and other strategies identified during stage one will be tested in a series of controlled experiments to examine their effectiveness in harnessing the abilities and attention of organization members to counter semantic attacks. The third stage of the project aims to examine the design and execution of promising strategies identified in stage two. The objective of this stage will be to learn how each strategy can be adopted and followed by the greatest number of people so as to solidify any protection the strategies offer. Again, controlled experimentation will be used during this stage and we will examine individual-level variables to understand how to encourage adoption. By leveraging an integrated, multi-method approach to the growing problem of semantic attacks, the series of studies outlined in our proposal will lead to new theories and models for future research and dissemination of lessons learned serving public interests.Intellectual Merit: New knowledge will be developed by identifying and systematically testing the efficacy of organizational strategies for countering semantic attacks. The organization-wide strategies that rely on crowdsourcing and integrate gamificiation and other techniques to counter semantic attacks offer a novel approach to developing the human firewall where individuals fight these semantic attacks as a collective rather than as individuals. By examining shared explanations for effective strategies, we would contribute not only effective strategies but the underlying theory for their effectiveness, which would serve as the foundation of future innovations in organizational responses to security threats. The research framework developed here may also be relevant to studying the mitigation of other security threats in addition to semantic attacks. Broader Impacts: Findings from this research are likely to also have a number of important practical implications for educating organizational leaders and the general public about strategies for countering semantic attacks. To disseminate findings from this research, we plan to hold two practitioner meetings and develop a public service website in which we will discuss the lessons learned during the project. Additionally, the website will provide base data, access to research reports, and educational programs produced by this project. The combination of theoretical and methodological backgrounds required to conduct the experiments will contribute immeasurably to the research training of graduate and undergraduate research assistants. Finally, project results will be shared through professional presentations and publications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
EAGER: Opinion Spam in Digital Rulemaking: Techniques, Effects, and Interventions
  • 批准号:
    2232169
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2022
  • 负责人:
    Matthew Jensen
  • 依托单位:
国内基金
海外基金
转基因水稻中不同反义Sbe基因结构对抑制胚乳支链淀粉合成效果的比较
  • 批准号:
    30300226
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2003
  • 负责人:
    刘巧泉
  • 依托单位: