SaTC: CORE: Small: The Impacts of Human Decision-Making on Security and Robustness of Interdependent Systems
SaTC: CORE: Small: The Impacts of Human Decision-Making on Security and Robustness of Interdependent Systems
批准号:
1718637
负责人:
Shreyas Sundaram
金额:
$47.6万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2022-07-31
中文摘要
在行为经济学和心理学方面有大量的研究表明,人只是部分理性的,因此总是偏离经典的经济理论。人们对风险、回报和损失的看法可能与他们的真实价值有很大的不同,这些看法可能对保护个人正在管理的系统的投资产生重大影响。本研究的目的是了解人们使用行为决策的现实模型来保护他们的计算机系统的决策。该研究包括严格分析和预测行为决策替代模型下预期结果的正式理论,以及与人类受试者进行的实验室实验,以评估理论所做的预测并确定新的行为模型。这项研究将处理两类具体的问题。首先,它将确定在大型互联网络物理系统的不同组成部分由不同利益相关者拥有的情况下,行为决策的影响,每个利益相关者决定投资多少来保护自己的资产。其次,它将描述决策者如何根据他们感知到的风险和回报,在不同的安全技术(开源和公共与闭源和专有)之间做出选择。这项研究将使我们更全面地了解大规模互联系统中出现的漏洞,并指导我们设计更安全的系统,并带来相应的社会效益。本研究系统、严谨地刻画了安全环境中行为偏离最优和无界理性选择的影响。工作包括风险和不确定性下的决策模型,如前景理论,以及这些模型如何影响管理相互依赖系统的代理的行为。该研究汇集了博弈论分析,以人类和系统相互作用的模型为基础预测结果,计算机安全概念,以模拟漏洞如何被利用和攻击如何传播,以及行为经济学实验,以测试理论预测和完善模型。本研究分为两部分。第一部分考虑网络上的一类相互依赖的安全博弈,其中每个参与者选择安全投资来保护其控制下的节点;这项工作为应用程序建模,例如多利益相关者SCADA系统。研究将包括攻击概率的一般公式、流行风险、系统相互依赖的攻击图模型,以及网络的优化设计,以减轻由人类决策引入的安全漏洞。第二部分考虑的是一类公共池资源管理游戏,玩家选择将自己的资源分配给多个资源,每个资源提供一定的回报率,并具有一定的失败概率。这类博弈代表了决策者必须在不同的公共和专有安全技术之间做出选择的情况。该研究将描述前景理论决策的影响,以及用户如何对资源运营商或供应商提供的激励作出反应。在这两个部分的工作中,研究将确定纳什均衡安全投资和资源利用是如何受到风险和回报的扭曲观念的影响的。这两个部分都包括使用人类受试者的受控行为经济学实验,这些实验将评估理论预测,并可能产生新的决策模型。
英文摘要
There is a substantial body of work in behavioral economics and psychology showing that people are only partially rational, and thus consistently deviate from classical economic theory. People's perceptions of risks, rewards, and losses can differ substantially from their true values, and these perceptions can have a significant impact on the investments made to protect the systems that the individuals are managing. The objective of this research is to understand the decisions people make to protect their computer systems using realistic models of behavioral decision-making. The research encompasses formal theory to rigorously analyze and predict the outcomes that should be expected under alternative models of behavioral decision-making, and laboratory experiments with human subjects to evaluate the predictions made by the theory and to identify new behavioral models. The research will tackle two specific classes of problems. First, it will identify the impact of behavioral decision-making in settings where different components of a large interconnected cyber-physical system are owned by different stakeholders, each deciding how much to invest in securing their owned assets. Second, it will characterize how decision-makers choose among different security technologies, open source and public versus closed source and proprietary, based on their perceived risks and rewards. The research will lead to a more complete understanding of the vulnerabilities that arise in large-scale interconnected systems, and guide us to the design of more secure systems, with corresponding societal benefits. This research systematically and rigorously characterizes the impact of behavioral deviations from optimal and unbounded rational choice in security settings. The work includes models of decision-making under risk and uncertainty, such as prospect theory, and how such models affect the behavior of agents who manage interdependent systems. The research brings together game-theoretic analysis to predict outcomes based on models of interacting humans and systems, computer security concepts to model how vulnerabilities are exploited and how attacks spread, and behavioral economics experiments to test the theoretical predictions and refine the models. The research is organized in two parts. The first part considers a class of interdependent security games on networks, where each player chooses security investments to protect nodes under her control; this work models applications such as multi-stakeholder SCADA systems. The research will encompass general formulations of attack probabilities, epidemic risks, attack graph models of system interdependencies, and the optimal design of networks to mitigate security vulnerabilities introduced by humans' decision-making. The second part considers a general class of common-pool resource management games, whereby players choose to split their utilization among multiple resources, each of which provides a certain rate-of-return and has a certain probability of failure. This class of games represents conditions in which decision-makers must choose between different public and proprietary security technologies. The research will characterize the impacts of prospect-theoretic decision-making and how users react to incentives provided by the resource operators or vendors. In both parts of the work, the research will identify how Nash equilibrium security investments and resource utilizations are affected by skewed perceptions of risks and rewards. Both parts include controlled behavioral economics experiments using human subjects that will evaluate the theoretical predictions and potentially yield new models of decision-making.
期刊论文(20)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3384419.3430608
发表时间:
2020-11
期刊:
Proceedings of the 18th Conference on Embedded Networked Sensor Systems
影响因子:
--
作者:
[Kavit Patel;Kyle Massa;N. Raghunathan;Heng Zhang-;Ananth V. Iyer;S. Bagchi]
通讯作者:
Kavit Patel;Kyle Massa;N. Raghunathan;Heng Zhang-;Ananth V. Iyer;S. Bagchi
Controlling Human Utilization of Failure-Prone Systems via Taxes
通过税收控制人类对易发生故障的系统的利用
DOI:
10.1109/tac.2020.3042481
发表时间:
2020
期刊:
IEEE Transactions on Automatic Control
影响因子:
6.8
作者:
[Hota, Ashish R., Sundaram, Shreyas]
通讯作者:
Sundaram, Shreyas
Topology-based Host-Level Attribution for Multi-Stage Attacks in Enterprise Systems using Software Defined Networks
使用软件定义网络对企业系统中的多阶段攻击进行基于拓扑的主机级归因
DOI:
10.1007/978-3-319-78813-5_36
发表时间:
2018
期刊:
Social Informatics and Telecommunications Engineering
影响因子:
--
作者:
[Kannan, S, Wood, P, Deatrick, L, Beane, P, Chaterji, S, Bagchi, S]
通讯作者:
Bagchi, S
TASHAROK: Using Mechanism Design for Enhancing Security Resource Allocation in Interdependent Systems
TASHAROK:利用机制设计增强相互依赖系统中的安全资源分配
DOI:
10.1109/sp46214.2022.9833591
发表时间:
2022
期刊:
2022 IEEE Symposium on Security and Privacy (SP
影响因子:
--
作者:
[Abdallah, Mustafa, Woods, Daniel, Naghizadeh, Parinaz, Khalil, Issa, Cason, Timothy, Sundaram, Shreyas, Bagchi, Saurabh]
通讯作者:
Bagchi, Saurabh
Protecting Assets with Heterogeneous Valuations under Behavioral Probability Weighting
行为概率加权下的异质估值保护资产
DOI:
10.1109/cdc40024.2019.9030279
发表时间:
2019
期刊:
IEEE Conference on Decision and Control
影响因子:
--
作者:
[Abdallah, Mustafa, Naghizadeh, Parinaz, Cason, Timothy, Bagchi, Saurabh, Sundaram, Shreyas]
通讯作者:
Sundaram, Shreyas
共 20 条
Travel Support for the 2021 American Control Conference; New Orleans, Louisiana; May 26-28, 2021
-
批准号:2110732
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2021
-
负责人:Shreyas Sundaram
-
依托单位:
CAREER: Towards Secure Large-Scale Networked Systems: Resilient Distributed Algorithms for Coordination in Networks under Cyber Attacks
-
批准号:1653648
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2017
-
负责人:Shreyas Sundaram
-
依托单位:
Collaborative Research: Algorithmic and Graph-Theoretic Approaches to Optimal Sensor Placement in Complex Dynamical Systems
-
批准号:1635014
-
项目类别:Standard Grant
-
资助金额:$24.46万
-
财政年份:2016
-
负责人:Shreyas Sundaram
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: