课题基金 / 基金详情

SBE: Small: THE NEW SECURITY CALCULUS: Incentivizing Good User Security Behavior

SBE: Small: THE NEW SECURITY CALCULUS: Incentivizing Good User Security Behavior
SBE:小:新的安全演算:激励良好的用户安全行为
批准号:
1618212
负责人:
Sanjay Goel
金额:
$49.79万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-15 至 2021-08-31

项目摘要

项目成果

Sanjay Goel的其他基金

相似基金

相关文献

中文摘要
翻译
网络安全漏洞的威胁和影响在整个社会都能感受到,给企业造成了巨大的经济损失,泄露了国家机密。人类行为越来越多地被视为一个基本的安全漏洞,是许多安全漏洞的核心。已经使用了几种方法来改善用户的安全行为,包括制定信息安全政策、提供安全意识培训以及对违反安全的行为进行惩罚;这些方法并不是非常有效。在这项研究中,我们通过直接的财务激励和行为干预来影响人类安全决策分析,使决策分析与经济理性保持一致。研究者用来提高信息安全的主要理论框架是保护动机理论和威慑理论。这些理论表明,用户通过在决策演算中认知地权衡与他们的选择相关的相对得失来做出理性的安全决策。它们假设用户将理性地对环境中感知到的安全威胁和对不遵守规定施加的制裁做出反应。用户应根据对安全威胁和危险行为的后果的了解,对其行为进行内部监管;然而,在日常活动过程中,用户通常会将与其行为相关的风险降至最低,并可能会认为合规的成本大于收益,从而使不合规行为合理化。我们寻求通过改变用户S的安全决策演算来提高安全合规性。根据行为经济学的原理,我们使用外部奖励(即财务激励)来启动合规,并使用心理操纵(轻推)来促进对安全行为的持续内部监管,从而使用户在外部激励不再到位时维持安全行为。这项工作的多学科性质加深了对许多信息安全问题的理解,并为行为安全和安全经济学的研究提供了一个新的视角。
英文摘要
The threat and impact of cybersecurity breaches are felt throughout society with massive financial losses to businesses and breach of national secrets. Human behavior is increasing seen as a fundamental security vulnerability that is at the center of many security breaches. Several approaches have been used for improving user security behavior, including enacting information security policies, providing security awareness training, and introducing penalties for security violations; these approaches have not been very effective. In this research, we are influencing human security decision analysis through direct financial incentives and behavioral interventions such that the decision analysis aligns with economic rationality. The dominant theoretical frameworks used by researchers to improve information security are Protection Motivation Theory and Deterrence Theory. These theories suggest that users make rational security decisions by cognitively weighing the relative gains and losses associated with their choices within a decision calculus. They assume that users will respond rationally to perceived security threats in the environment and to sanctions imposed on noncompliance. Users are expected to internally regulate their behavior based on an understanding of security threats and the consequences of risky behavior; however, in the course of daily activities users often minimize the risks associated with their behavior and may rationalize noncompliant behavior by perceiving that costs of compliance outweigh benefits. We seek to improve security compliance by changing the user?s security decision calculus. Drawing on principles of behavioral economics, we use extrinsic rewards (i.e. financial incentives) to initiate compliance, and psychological manipulations (nudges) to promote ongoing internal regulation of security behavior, such that users sustain secure behaviors when external incentives are no longer in place. The multidisciplinary nature of this work enhances understanding of many information security issues and provides a fresh perspective for research on behavioral security and security economics.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Thwarting the Malicious Insider Evolution Process: The Theory of Strained Betrayal
  • 批准号:
    1912874
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.77万
  • 财政年份:
    2019
  • 负责人:
    Sanjay Goel
  • 依托单位:
EDU: Flipping the Online Security Classroom - Improving Retention of Security Student Pipeline through Early Intervention
  • 批准号:
    1318483
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.82万
  • 财政年份:
    2013
  • 负责人:
    Sanjay Goel
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: