课题基金 / 基金详情

Scaling Trust: An Anthropology of Cyber Security

Scaling Trust: An Anthropology of Cyber Security
扩大信任:网络安全人类学
批准号:
MR/S037373/1
负责人:
Matthew Spencer
金额:
$61.58万
依托单位:
依托单位国家:
英国
项目类别:
Fellowship
财政年份:
2019
资助国家:
英国
项目状态:
已结题
起止时间:
2019 至 --

项目摘要

项目成果

Matthew Spencer的其他基金

相似基金

相关文献

中文摘要
翻译
随着人们对数字基础设施的日益依赖,网络灾难的脆弱性成为社会生活的一个决定性背景。在过去的两年里,Wannacry导致了数千个NHS预约的取消,NotPetya使马士基的全球航运业务陷入停顿,Equifax的黑客攻击泄露了1.4亿人的详细信息,而TSB的中断使数千名客户受到欺骗。在这些失败的背后——修补系统、保护网络、实施良好的治理——是一个规模问题:最小的“薄弱环节”最终可能危及整个系统的安全。然而,由于完全的安全在实践中是不可能实现的,因此与基础设施相处得很好已经成为一个信任问题。信任不是“用户的问题”,这是该协会的前提。在我们日常生活中所依赖的服务和公用事业背后,我们可以找到一系列专业的网络安全实践,旨在赢得和维持信任,质疑信任并跨规模管理信任。他们如何做到这一点,他们的成功和失败,是这项研究的主题。这项雄心勃勃的网络安全人类学研究是该奖学金的核心,将与英国国家网络安全中心(NCSC)合作进行。一个广泛的人种学研究项目将侧重于对关键国家基础设施(CNI)组织内的治理过程和知识实践的长期参与观察。三个调查轨迹构成了该奖学金的核心:在1-2年,通过对2个CNI地点实施网络和信息系统指令的民族志研究,它提出:网络安全政策如何将最佳实践“扩展”到不同的现实世界环境中?在第3-4年,通过对3个CNI地点的公司治理“仪式”如何建立信任的民族志分析,它提出了一个问题:it从业者如何“扩大”当地形式的信任,以创建“高水平”的整体表征,从而获得批准,并承担责任?在5-7年级,该研究员将与一名博士后一起,对自动化和人工智能等新技术对网络安全实践的影响进行研究,问题是:新技术如何重新配置信任?传统上由工程师领导的网络安全,有一种将人或用户简单化的传统:将其视为问题或攻击载体。近年来,跨学科方法在开发更多细微差别的方法方面取得了稳定的成功。该奖学金通过对跨尺度建立和管理信任的专业实践进行实证基础的批判性概念分析的人类学风格,推动了跨学科网络安全研究的最新进展。在此过程中,它还将为社会科学的几个研究领域做出重要贡献:治理和问责的人类学、信任的社会学,以及作为当代社会基础的数字基础设施的跨学科研究。一项全面的影响计划将确保该研究与政策制定者的优先事项保持一致,并为整个行业和政府的网络安全政策和实践做出贡献。学术观众将通过在主要会议上的演讲和针对高影响力期刊的雄心勃勃的出版战略,以及旨在成为网络安全的权威人类学账户的学术专著来达到。该研究员管理数字和IT项目的专业背景,以及他在计算科学人种学方面的研究经验,对于这项研究是不可或缺的。广泛的培训和学科跳跃计划将使研究员成为研究领域的领导者,站在学术领域,行业和政策之间,准备开展应对英国工业战略重大挑战所需的跨学科研究
英文摘要
With growing dependency on digital infrastructure, vulnerability to cyber disaster becomes a defining context for social life. Within the last two years Wannacry led to the cancellation of thousands of NHS appointments, NotPetya brought Maersk's global shipping operations to a halt, the Equifax hack compromised the details of 140 million people, and TSB's outage left thousands of customers defrauded. Behind these failures-to patch systems, to secure networks, to implement good governance-is a problem of scales: the smallest "weak link" can end up compromising the security of the whole system. Yet because complete security is unattainable in practice, living well with infrastructures has become a question of trust.It is the premise of this fellowship that trust is not a "user's problem". Behind the services and utilities that we rely on in daily life, we can find an array of professional cyber security practices aiming to win and maintain trust, to question it and manage it across scales. How they go about doing that, their successes and failures, is the subject of this study.The ambitious anthropological study of cyber security at the heart of this fellowship will be undertaken in collaboration with the UK's National Cyber Security Centre (NCSC). A broad programme of ethnographic research will focus on long term participant observation of governance processes and knowledge practices within Critical National Infrastructure (CNI) organisations. Three trajectories of investigation comprise the core of the fellowship:In years 1-2, with an ethnographic study of the implementation of the Network and Information Systems directive in 2 CNI locations, it asks: how does cyber security policy "scale" best practice into diverse real-world contexts? In years 3-4, with an ethnographic analysis of how trust is built through the "rituals" of corporate governance in 3 CNI locations, it asks: how do IT practitioners "scale up" local forms of trust to create "high level" holistic representations with which approval can be given, and responsibility taken?In years 5-7, together with a postdoc, the fellow will conduct an examination of the impact of new technologies of automation and AI on cyber security practice, it asks: how do new technologies reconfigure trust? Traditionally led by engineers, cyber security has a legacy of treating people or users simplistically: as problems, or attack vectors. Interdisciplinary approaches have had steady success over recent years in developing more nuances approaches. This fellowship advances the state of the art in interdisciplinary cyber security research with an anthropological style of empirically grounded critical conceptual analysis of professional practices involved in making and managing trust across scales. In doing so it will also make important contributions to several fields of research in the social sciences: the anthropology of governance and accountability, the sociology of trust, and interdisciplinary studies of the digital infrastructures that underlie contemporary social societies. A comprehensive impact programme will ensure that the study stays aligned with policymakers' priorities, and contributes to cyber security policy and practice across industry and government. Academic audiences will be reached through presentation at leading conferences and an ambitious publication strategy targeting high impact journals, and an academic monograph, aiming to be a definitive anthropological account of cyber security.The fellow's professional background managing digital and IT projects are indispensable to this research, as is his research experience in the ethnography of computational science. An extensive training and discipline hopping programme will make the fellow a research leader, standing between academic fields, industry, and policy, poised to produce the engaged interdisciplinary research needed to tackle the Grand Challenges of the UK's Industrial Strateg
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
Figure - Concept and Method
图-概念和方法
DOI: 10.1007/978-981-19-2476-7_6
发表时间: 2022
期刊:
影响因子: --
作者: [Spencer M]
通讯作者: Spencer M
Characterising assurance: scepticism and mistrust in cyber security
保证的特征:对网络安全的怀疑和不信任
DOI: 10.1080/17530350.2022.2098515
发表时间: 2022
期刊: Journal of Cultural Economy
影响因子: 1.9
作者: [Spencer M]
通讯作者: Spencer M
Creative Malfunction: Finding Fault with Rowhammer
创意故障:用 Rowhammer 找茬
DOI: --
发表时间: 2021
期刊: A Journal of Software Studies
影响因子: --
作者: [Spencer M J]
通讯作者: Spencer M J
The de-perimeterisation of information security: The Jericho Forum, zero trust, and narrativity
信息安全的去边界化:杰里科论坛、零信任和叙事
DOI: 10.1177/03063127231221107
发表时间: 2023
期刊: Social Studies of Science
影响因子: 3
作者: [Spencer M]
通讯作者: Spencer M
Scaling Trust: An Anthropology of Cyber Security (Renewal)
  • 批准号:
    MR/X023338/1
  • 项目类别:
    Fellowship
  • 资助金额:
    $75.85万
  • 财政年份:
    2024
  • 负责人:
    Matthew Spencer
  • 依托单位:
Dynamics of community composition
  • 批准号:
    NE/K00297X/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $48.81万
  • 财政年份:
    2013
  • 负责人:
    Matthew Spencer
  • 依托单位:
Collaborative Research: Continued Study of Physical Properties of the WAIS Divide Deep Core
  • 批准号:
    1043313
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $12.02万
  • 财政年份:
    2011
  • 负责人:
    Matthew Spencer
  • 依托单位:
Collaborative Research: Combined Physical Property Measurements at Siple Dome
  • 批准号:
    0917509
  • 项目类别:
    Standard Grant
  • 资助金额:
    $3.55万
  • 财政年份:
    2008
  • 负责人:
    Matthew Spencer
  • 依托单位:
海外基金