Why Johnny doesn't write secure software? Secure software development by the masses
Why Johnny doesn't write secure software? Secure software development by the masses
批准号:
EP/P011799/1
负责人:
Awais Rashid
金额:
$128.48万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --
中文摘要
你是否使用移动或网络应用程序,或者在你的身上、家里或工作场所有物联网设备?你有没有想过是谁开发了驱动这些应用程序和设备的软件,他们对网络安全的理解是什么,他们是如何做出影响最终软件网络安全的设计决策的,哪些因素影响了他们的行为和设计选择?或者,您是利用应用程序开发平台和易于编程的硬件设备(如Arduino和Raspberry Pi)开发应用程序并将其部署到个人使用或分发给全球数百万人的大众中的一员?当你编写软件时,你是如何做出网络安全决策的?您是否有意识地考虑设计选择的安全性含义,或者是否存在其他更关键的因素?什么将帮助您从正在开发的软件中实现您的目标,同时确保它不容易受到恶意行为者的攻击?本项目旨在加深对这些问题的基本理解。我们认识到,开发软件不再是少数拥有深厚技术技能、培训和知识的人的专利。越来越多来自不同背景的人正在为移动和网络应用程序以及可编程消费设备开发软件。开发者的多样性是数字经济中许多创新的核心。他们生产的软件可以,并且已经部署在嵌入到人类活动的许多方面的系统中,并且被全球用户群使用。然而,目前对从事软件开发的“大众”的安全行为和决策过程知之甚少。我们用“Johnny”这个笔名来称呼这些人——这是基于Whitten和Tygar的开创性著作,他们在书中强调了Johnny(加密的原型用户)所面临的挑战。在这个项目中,我们的目标是解决Johnny在当代环境中所面临的挑战,而不是加密。我们关注的是拥有不同背景、专业知识和网络安全专业知识的约翰尼,他们能够并且正在开发全球数百万人使用的软件。利用网络安全、软件工程和心理学专家组成的研究团队,我们在这个项目中的目标是进行基于经验的研究,以更好地理解Johnny的行为和实践的安全含义,并为Johnny的安全软件开发提供有效的支持。我们建议通过揭示和描述Johnny倾向于引入的安全漏洞,通过分析这些漏洞是如何以及为什么引入的,以及通过识别和评估一系列干预措施来改善Johnny在软件开发过程中的安全行为来实现这一目标。为此,我们将与来自世界各地领先研究和实践组织的知名国际研究伙伴合作。该项目将首次研究影响Johnny网络安全决策的认知和社会过程之间的相互关系,它们对最终软件安全性的影响,以及可能引导Johnny在软件开发过程中做出更有效网络安全决策的新干预措施。
英文摘要
Do you use mobile or web apps or have Internet of Things devices on your person, in your home or workplace? Have you thought about who developed the software that drives these apps and devices, what was their understanding of cyber security, how did they make design decisions that impact the cyber security of the resulting software, and what factors influenced their behaviour and design choices? Or perhaps you are one of the masses exploiting app development platforms and easy-to-program hardware devices such as Arduino and Raspberry Pi to develop applications and deploy them for personal use or distribute them to millions of people around the world? How do you make cyber security decisions when you write software? Do you consciously think about the security implications of your design choices, or are there other factors that are more critical? What will help you achieve your goals from the software that you are developing while ensuring that it is not vulnerable to attacks by malicious actors?This project aims to develop a deep foundational understanding of these issues. We recognise that developing software is no longer the preserve for the select few with deep technical skills, training, and knowledge. A wide range of people from diverse backgrounds are increasingly developing software for mobile and web apps and for programmable consumer devices. This diversity of developers is at the heart of many innovations in the digital economy. The software they produce can be, and is, deployed across systems embedded in many aspects of human activity, and is used by a global user base. However, little is currently understood about the security behaviours and decision-making processes of 'the masses' engaged in software development. We refer to these masses by the pseudonym 'Johnny' - based on a seminal work by Whitten and Tygar where they highlighted the challenges faced by Johnny, the prototypical user of encryption. In this project we aim to tackle the challenges faced by Johnny in a contemporary setting beyond encryption. We focus on the Johnnys with diverse backgrounds, know-how and cyber security expertise who can, and are, developing software used, potentially, by millions worldwide. Drawing on a research team of experts in cyber security, software engineering, and psychology, our aim in this project is to conduct empirically-grounded research to better understand the security implications of Johnny's behaviours and practices and develop effective support for secure software development by Johnny. We propose to achieve this by uncovering and characterising the security vulnerabilities that Johnny tends to introduce, by analysing how and why these vulnerabilities are introduced, and by identifying and evaluating a range of interventions to improve Johnny's security behaviours during software development. We will do this in collaboration with eminent international research partners, drawn from leading research and practitioner organisations around the world. This project will be the first to study the inter-relationship between the cognitive and social processes that shape Johnny's cyber security decisions, their impact on the security of the resultant software and the novel interventions that may steer Johnny towards more effective cyber security decisions during software development.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Challenges of Privacy Requirements Modelling in V2X Applications: A Telematic Insurance Case Study
V2X 应用中隐私要求建模的挑战:远程信息处理保险案例研究
DOI:
10.1109/rew.2017.48
发表时间:
2017
期刊:
影响因子:
--
作者:
[Mukisa S]
通讯作者:
Mukisa S
DOI:
10.1109/msec.2022.3204364
发表时间:
2022-08
期刊:
IEEE Security & Privacy
影响因子:
1.9
作者:
[Mohammad Tahaei;Kami Vaniea;A. Rashid]
通讯作者:
Mohammad Tahaei;Kami Vaniea;A. Rashid
Usability Smells: An Analysis of Developers' Struggle With Crypto Libraries
可用性的味道:开发者与加密库的斗争分析
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
[Patnaik N.]
通讯作者:
Patnaik N.
Security but not for security's sake
安全但不是为了安全
DOI:
10.1145/3387940.3392230
发表时间:
2020
期刊:
影响因子:
--
作者:
[Rauf I]
通讯作者:
Rauf I
Influences of developers' perspectives on their engagement with security in code
开发人员的观点对其参与代码安全性的影响
DOI:
10.1145/3528579.3529180
发表时间:
2022
期刊:
影响因子:
--
作者:
[Rauf I]
通讯作者:
Rauf I
共 7 条
Securing Convergent Ultra-large Scale Infrastructures
-
批准号:EP/Z531315/1
-
项目类别:Research Grant
-
资助金额:$864.03万
-
财政年份:2024
-
负责人:Awais Rashid
-
依托单位:
Equitable privacy
-
批准号:EP/W025361/1
-
项目类别:Research Grant
-
资助金额:$129.56万
-
财政年份:2022
-
负责人:Awais Rashid
-
依托单位:
REPHRAIN: Research centre on Privacy, Harm Reduction and Adversarial Influence online
-
批准号:EP/V011189/1
-
项目类别:Research Grant
-
资助金额:$888.45万
-
财政年份:2020
-
负责人:Awais Rashid
-
依托单位:
Why Johnny doesn't write secure software? Secure software development by the masses
-
批准号:EP/P011799/2
-
项目类别:Research Grant
-
资助金额:$108.77万
-
财政年份:2018
-
负责人:Awais Rashid
-
依托单位:
DYPOSIT: Dynamic Policies for Shared Cyber-Physical Infrastructures under Attack
-
批准号:EP/N021657/2
-
项目类别:Research Grant
-
资助金额:$24.93万
-
财政年份:2018
-
负责人:Awais Rashid
-
依托单位:
DYPOSIT: Dynamic Policies for Shared Cyber-Physical Infrastructures under Attack
-
批准号:EP/N021657/1
-
项目类别:Research Grant
-
资助金额:$46.21万
-
财政年份:2015
-
负责人:Awais Rashid
-
依托单位:
MUMBA: Multi-faceted Metrics for ICS Business Risk Analysis
-
批准号:EP/M002780/1
-
项目类别:Research Grant
-
资助金额:$50.19万
-
财政年份:2014
-
负责人:Awais Rashid
-
依托单位:
Academic Centre of Excellence in Cyber Security Research - Lancaster University
-
批准号:EP/K003607/1
-
项目类别:Research Grant
-
资助金额:$6.3万
-
财政年份:2012
-
负责人:Awais Rashid
-
依托单位:
Industrial CASE Account - Lancaster 2010
-
批准号:EP/I501487/1
-
项目类别:Training Grant
-
资助金额:$25.55万
-
财政年份:2010
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P505585/1
-
项目类别:Training Grant
-
资助金额:$113.13万
-
财政年份:2010
-
负责人:Awais Rashid
-
依托单位:
Social Media, Social Good: Ultra-Large Scale Public Engagement Systems to Challenge Anti-Social Behaviour
-
批准号:EP/I016546/1
-
项目类别:Research Grant
-
资助金额:$25.53万
-
财政年份:2010
-
负责人:Awais Rashid
-
依托单位:
IDS - Lancaster University
-
批准号:EP/P505232/1
-
项目类别:Training Grant
-
资助金额:$8.41万
-
财政年份:2009
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P505194/1
-
项目类别:Training Grant
-
资助金额:$126.62万
-
财政年份:2009
-
负责人:Awais Rashid
-
依托单位:
Industrial CASE Account - Lancaster 2009
-
批准号:EP/H501347/1
-
项目类别:Training Grant
-
资助金额:$41.6万
-
财政年份:2009
-
负责人:Awais Rashid
-
依托单位:
ISIS: Protecting children in online social networks
-
批准号:EP/F035438/1
-
项目类别:Research Grant
-
资助金额:$54.85万
-
财政年份:2008
-
负责人:Awais Rashid
-
依托单位:
IDS - Lancaster University
-
批准号:EP/P504627/1
-
项目类别:Training Grant
-
资助金额:$1.78万
-
财政年份:2008
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P504708/1
-
项目类别:Training Grant
-
资助金额:$109.87万
-
财政年份:2008
-
负责人:Awais Rashid
-
依托单位:
IDS - Lancaster University
-
批准号:EP/P50368X/1
-
项目类别:Training Grant
-
资助金额:$3.82万
-
财政年份:2007
-
负责人:Awais Rashid
-
依托单位:
DTA - Lancaster University
-
批准号:EP/P503825/1
-
项目类别:Training Grant
-
资助金额:$126.88万
-
财政年份:2007
-
负责人:Awais Rashid
-
依托单位:
VERA: Verifiable Aspect Models for Middleware Product Families (Visiting Fellowship)
-
批准号:EP/E005276/1
-
项目类别:Research Grant
-
资助金额:$2.48万
-
财政年份:2006
-
负责人:Awais Rashid
-
依托单位:
海外基金