Reconfiguring Citizen Participation in Cybersecurity
Reconfiguring Citizen Participation in Cybersecurity
批准号:
BB/T018593/1
负责人:
Julia Slupska
金额:
$2.56万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2020
资助国家:
英国
项目状态:
已结题
起止时间:
2020 至 --
中文摘要
网络安全中有哪些威胁?作为一个领域,网络安全对外人来说可能显得晦涩难懂,令人望而生畏,这是黑客、网络斗士和技术专家的领域,他们往往是男性。然而,每个人都暴露在潜在的易受攻击的技术之下。这一研究项目开创了公民参与网络安全的模式,既增强了公民在自己的网络安全实践中的能力,又通过纳入他们的观点和个人经验推动了网络安全领域的发展。女权主义理论家挑战了传统安全研究中个人/政治暴力的二元论,认为这些二元论忽视或减少了基于性别的暴力和对妇女安全的威胁。不幸的是,网络安全领域没有纳入这些关于个人和政治之间关系的见解,因此有可能从研究人员调查安全挑战的“威胁模型”中遗漏许多形式的技术滥用。网络安全中的威胁建模程序通常依赖专家来识别漏洞和潜在攻击者。尽管这一过程被描述为抽象和公正的,但它往往反映了对精英技术用户不安全原因的假设。例如,我们在牛津互联网研究所(OII)和伦敦大学学院科学、技术、工程和公共政策系(STEaPP)之间进行的试点研究发现,在安全分析和智能家居设备的设计中,亲密威胁被忽略,而是专注于黑客或窃贼等威胁(Slupska 2019)。新兴的物联网和智能家居设备可能会使人们容易受到来自国内合作伙伴的新类别威胁(Leitão 2019;Tanczer等人。通过邀请公民参与定义什么会让他们在网上感到威胁,以及他们如何感到有能力应对这些威胁,该项目将使网络安全方法人性化,并为公民创造新的机会,让他们参与塑造他们认为在网络安全中重要的研究问题。该项目将通过举办八个关于公民网络安全的联合设计讲习班来做到这一点。每个研讨会都将通过提供免费的数字安全培训,重新调整对技术专长的假设,使公民能够反思自己的做法,并应对新类型的威胁,以促进网络安全知识。主持人还将领导选择加入小组讨论和重点小组,讨论个人经验和网络安全知识之间的关系。我们的目标是通过反思性讨论改进现有做法,促进公民积极参与自己的网络安全,并为塑造和完善学术领域的方向征求意见。研讨会将免费向所有人开放,并将与牛津、伦敦和巴黎大都会地区的社区组织共同主办。每个学员在离开研讨会时都将带着如何改进其网络安全实践的实用建议。参与者还将有机会在开放和安全的环境中自愿与研究人员一起贡献他们的观察、经验和故事,为研究做出贡献。我们还将招募志愿者对数据进行编码和分析,并努力开发如何利用研讨会参与者来培训其他人。该项目将汇集牛津互联网研究所、牛津大学网络安全博士培训中心、伦敦大学学院科学、技术和公共政策系的性别和物联网项目、女权主义活动家剧院公司Power Play和网络防御公司DarkTRACE的合作伙伴。我们还将与牛津、伦敦和巴黎的社区团体合作,主办和宣传每个研讨会,并招募潜在的参与者。
英文摘要
What threats count in cybersecurity? As a field, cybersecurity can seem obscure and daunting to outsiders, a domain for hackers, cyber-warriors and technical experts, who are more often than not male. Yet, everyone is exposed to potentially vulnerable technology. This research project pioneers a model of citizen participation in cybersecurity both to empower citizens in relation to their own cybersecurity practices and advance the field of cybersecurity by incorporating their perspectives and personal experiences.Feminist theorists have challenged binaries of personal/political violence in conventional security studies, arguing these ignore or diminish the threat of gender-based violence and threats to women's security. Unfortunately, the field of cybersecurity has not incorporated these insights on the relationship between the personal and the political and therefore risks omitting many forms of technological abuse from the "threat models" that shape where researchers investigate challenges to security. Threat modelling procedures in cybersecurity often rely on experts to identify vulnerabilities and potential attackers. Despite being presented as abstract and impartial, this process often reflects assumptions about the causes of insecurity among elite technology users. For example, our pilot research conducted between the Oxford Internet Institute (OII) and UCL Department of Science, Technology, Engineering and Public Policy (STEaPP) found that intimate threats are ignored in the security analyses and the design of smart home devises, which focus instead on threats like hackers or burglars (Slupska 2019). Emerging Internet of Things and smart home devices can leave people vulnerable to new classes threats from their domestic partners (Leitão 2019; Tanczer et al. 2018).By inviting citizens to participate in defining both what makes them feel threatened online, and how they could feel empowered to counter those threats, this project will humanise cybersecurity methods and create new opportunities for citizens to engage with shaping the research questions that they think should matter within cybersecurity. This project will do this by running eight co-design workshops on citizen cybersecurity. Each workshop will reconfigure assumptions about technical expertise by providing free digital security training to empower citizens to reflect on their own practices and to surface new types of threats to contribute to cybersecurity knowledge. Facilitators will also lead opt-in group discussions and focus groups on the relationships between personal experience and cybersecurity knowledge. Our objectives are to improve existing practices through reflective discussion, promote citizens' active involvement in their own cybersecurity, and solicit input for shaping and refining the directions of the academic field. The workshops will be free and open to all and will be hosted in conjunction with community organisations in the Oxford, London and Paris metro areas. Each participant will leave the workshop with practical advice on how to improve their cybersecurity practices. Participants will also have the opportunity to voluntarily contribute their observations, experiences, and stories with researchers in an open and safe environment to contribute to research. We will also elicit volunteers for coding and analysing data, and work to develop how we might use workshop participants to train others.This project will bring together partners in the Oxford Internet Institute; the Centre for Doctoral Training in Cybersecurity at the University of Oxford; the Gender and IoT project at the UCL Science, Technology and Public Policy Department; Power Play, a feminist activist theatre company, and Darktrace, a cyber-defence company. We will also work with community groups in Oxford, London and Paris in hosting and publicising each workshop and recruiting potential participants.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
Reconfigure: Feminist Action Research in Cybersecurity
重新配置:网络安全中的女权主义行动研究
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[J Slupska]
通讯作者:
J Slupska
Participatory Threat Modelling: Exploring Paths to Reconfigure Cybersecurity
参与式威胁建模:探索重新配置网络安全的路径
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[Julia Slupska]
通讯作者:
Julia Slupska
Participatory Threat Modelling
参与式威胁建模
DOI:
10.1145/3411763.3451731
发表时间:
2021
期刊:
影响因子:
--
作者:
[Slupska J]
通讯作者:
Slupska J
海外基金