课题基金 / 基金详情

SaTC: EDU: Educating STEM Students and Teachers about the Relevance of Social Engineering in Cyberattacks and Cybersecurity

SaTC: EDU: Educating STEM Students and Teachers about the Relevance of Social Engineering in Cyberattacks and Cybersecurity
SaTC:EDU:教育 STEM 学生和教师了解社会工程在网络攻击和网络安全中的相关性
批准号:
2032292
负责人:
Aunshul Rege
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-02-01 至 2025-01-31

项目摘要

项目成果

Aunshul Rege的其他基金

相似基金

相关文献

中文摘要
翻译
社会工程(SE)是网络犯罪分子使用的一种技术,它使用心理操纵来获取敏感信息,并获得对受限区域或系统的未经授权的访问。2017年,近70%的美国组织经历了SE,导致运营停机和收入损失276万美元。人为因素通常被认为是网络攻击中最薄弱的一环,这使得SE成为网络安全的主要担忧。尽管SE攻击构成了重大威胁,但教育、培训和对SE作为网络犯罪工具的普遍认识很低。这是因为SE被认为超出了技术领域的范围,因此应该由其他学科来解决,包括心理学、犯罪学和社会学。工程学和计算机科学学科已经在主要以技术为重点的网络安全教育项目上投入巨资。虽然这种技术方法很重要,但由此产生的学生人数太少,太单一,无法支持我们这个依赖技术的社会所需的解决方案的全面发展。扩大和多样化学习SE的学生(以及接受SE教育的教师)将撒下更大的网,以招收最有才华的学生,并在他们进入网络安全大军时培养他们的创造潜力。此外,该项目将反映国家科学基金会在其战略规划中确定的两个方面扩大参与的承诺:(I)扩大努力,扩大代表不足的群体和所有地理区域的不同机构的参与,以及(Ii)培养一支多样化和积极参与的STEM工作人员队伍。因此,这个项目将促进多样性,并为未来的SE教育和研究开发和共享资源和可持续的工具,在一个安全、道德和有参与性的学习环境中。首先,它将通过实践课程项目和每年一次的校际SE捕获旗帜竞赛和培训活动来教育学生。其次,该项目将通过举办跨多个STEM学科的在线和面对面培训讲习班来教育教育工作者。最后,该项目将传播免费资源,如SE课程项目、数据集和用于研究和教育的分析框架。该项目还将与教学促进中心共同开发一套新的评估工具(调查和焦点小组),以衡量学生和教育工作者针对SE的学习情况。该项目计划通过在人口结构各不相同的美国社区学院和大学招聘多个STEM学科来扩大学生和教育工作者的人才库并使之多样化。少数族裔服务机构、历史上的黑人学院和大学以及军队/退伍军人友好学校将特别参与。此外,项目团队将积极寻求属于这些机构中代表性不足群体的教职员工参与。这个项目得到了安全和值得信赖的网络空间(SATC)计划的支持,该计划为解决网络安全和隐私问题的提案提供资金,在这种情况下,特别是网络安全教育。SATC计划与联邦网络安全研究和发展战略计划和国家隐私研究战略保持一致,以保护和维护网络系统日益增长的社会和经济效益,同时确保安全和隐私。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Social engineering (SE) is a technique employed by cybercriminals that uses psychological manipulation to obtain sensitive information and gain unauthorized access to restricted areas or systems. Nearly 70% of U.S. organizations experienced SE in 2017, resulting in a $2.76 million loss in operational downtime and revenues. The human factor is often regarded as the weakest link in cyberattacks, making SE a major concern for cybersecurity. Despite the significant threat posed by SE attacks, education, training and general awareness of SE as a tool for cybercrime is low. This is because SE is considered to be outside the scope of the technical domain and thus should be addressed by other disciplines, including psychology, criminology, and sociology. The engineering and computer science disciplines are already investing heavily in cybersecurity education programs that have a primarily technical focus. While this technical approach is important, the resulting pool of students is too small and homogeneous to support the holistic development of the solutions needed by our technologically dependent society. Enlarging and diversifying the pool of students learning about (and teachers educating on) SE will cast a wider net to recruit the most talented students as well as fostering their creative potential as they enter the cybersecurity workforce. Furthermore, the project will reflect the National Science Foundation’s commitment to broadening participation along two fronts identified in its Strategic Plan: (i) Expanding efforts to broaden participation from underrepresented groups and diverse institutions across all geographical regions, and (ii) Preparing a diverse and engaged STEM workforce. Thus, this project will promote diversity, and develop and share resources and sustainable tools for future SE education and research in a safe, ethical, and engaging learning environment.This project has three objectives. First, it will educate students via hands-on course projects and a yearly intercollegiate SE Capture the Flag competition and training event. Second, the project will educate educators by hosting online and in-person training workshops across multiple STEM disciplines. Finally, the project will disseminate free resources such as SE course projects, datasets and analytic frameworks for research and education. The project will also develop a new set of assessment tools (surveys and focus groups) with the Center for the Advancement of Teaching to measure student and educator learning specific to SE. This project proposes to enlarge and diversify the pool of students and educators by recruiting across multiple STEM disciplines at community colleges and universities in the U.S. with varying demographics. Minority serving institutions, historically black colleges and universities, and military/veteran friendly schools will be specifically engaged. In addition, the project team will actively seek participation from faculty belonging to underrepresented groups at these institutions. This project is supported by the Secure and Trustworthy Cyberspace (SaTC) program, which funds proposals that address cybersecurity and privacy, and in this case specifically cybersecurity education. The SaTC program aligns with the Federal Cybersecurity Research and Development Strategic Plan and the National Privacy Research Strategy to protect and preserve the growing social and economic benefits of cyber systems while ensuring security and privacy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
Educating educators on social engineering: Experiences developing and implementing a social engineering workshop for all education levels
对教育工作者进行社会工程教育:为所有教育级别开发和实施社会工程研讨会的经验
DOI: --
发表时间: 2022
期刊: IEEE Integrated STEM Education Conference (ISEC
影响因子: --
作者: [Williams, K.]
通讯作者: Williams, K.
DOI: --
发表时间: 2022
期刊: IEEE Cyber Science Conference
影响因子: --
作者: [Bleiman, R.]
通讯作者: Bleiman, R.
The Relevance of Social Engineering Competitions in Cybersecurity Education
社会工程竞赛在网络安全教育中的相关性
DOI: --
发表时间: 2023
期刊: Situational Awareness and Social Media
影响因子: --
作者: [Rege, A.]
通讯作者: Rege, A.
Collegiate Social Engineering Capture the Flag Competition
大学生社会工程学夺旗比赛
DOI: --
发表时间: 2022
期刊: 2021 IEEE eCrime Researchers Summit
影响因子: --
作者: [Rege, A, Bleiman, R.]
通讯作者: Bleiman, R.
EAGER: Collaborative: A Criminology-Based Simulation of Dynamic Adversarial Behavior in Cyberattacks
  • 批准号:
    1742747
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.04万
  • 财政年份:
    2017
  • 负责人:
    Aunshul Rege
  • 依托单位:
CAREER: Applying a Criminological Framework to Understand Adaptive Adversarial Decision-Making Processes in Critical Infrastructure Cyberattacks
  • 批准号:
    1453040
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $45.0万
  • 财政年份:
    2015
  • 负责人:
    Aunshul Rege
  • 依托单位:
国内基金
海外基金
EDU增强冬小麦O3抗性的生理生态学机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    代碌碌
  • 依托单位: