课题基金 / 基金详情

Scaling Trust: An Anthropology of Cyber Security (Renewal)

Scaling Trust: An Anthropology of Cyber Security (Renewal)
扩展信任:网络安全人类学(续订)
批准号:
MR/X023338/1
负责人:
Matthew Spencer
金额:
$75.85万
依托单位:
依托单位国家:
英国
项目类别:
Fellowship
财政年份:
2024
资助国家:
英国
项目状态:
未结题
起止时间:
2024 至 --

项目摘要

项目成果

Matthew Spencer的其他基金

相似基金

相关文献

中文摘要
翻译
Scaling Trust是一个跨学科的研究项目,借鉴了人类学、社会学、传播学、文学理论、科学哲学和计算学的资源。通过访谈、文本分析、研讨会和民族志,Scaling Trust研究了网络安全在四个不同领域的最新变化,并提出了以下问题:新的模型和方法如何重塑当代社会的信任和安全?新形式的叙述性威胁、技术和规模问题以及安全解决方案如何定义安全的未来?A)在研究金的初期,我们调查了技术保证的当前转变。在这个领域中,安全性被视为技术产品的质量,可以在评估实验室中进行测试和测量。近年来,我们可以观察到对依赖可信产品的意外副作用的日益认识,以及专注于风险和通信质量的新方法的兴起。B)在最初的研究期间,我们还研究了“去边界化”安全模型的出现,今天最突出的是与“零信任”IT架构相关。我们研究的安全模型的性质一般,以及如何这一个特别是挑战了直觉的信息安全作为保护的“内部”的一个私人网络,并集中注意力,而不是资产价值。这种安全目标的表述对什么是安全技术以及如何定位和对待用户/人员具有深远的影响。C)在更新期间,我们将对“DevSecOps”运动进行实证研究,该运动旨在重新配置组织,以便安全,在这里被理解为一种组织功能,不再处于“孤岛”中,而是整合到协作的多功能交付团队中。这里对社会架构的关注借鉴了软件开发中的经典组织思想,例如康威定律(即技术倾向于从团队的结构中继承组织模式),以及“设计安全”概念,并受到持续交付方法的需求的驱动。在这里,安全被理解为组织的一部分所做的事情,以及开发,维护和运营。D)在更新期间,我们还建立了对最近出现的基于硬件的漏洞的研究,例如Rowhammer,SPECTRE和Meltdown,这些漏洞从根本上挑战了一些安全推理的基础。这些漏洞引起了人们对硬件水平作为不确定性来源的关注,挑战了可以通过分析软件中实现的逻辑来理解安全性的概念。除了防止攻击之外,安全保护因此成为一个在新漏洞出现时对其做出响应的问题。在《扩展信任》一书中,我们研究了安全的叙述,以及安全如何以不同但交叉的方式构成一种有意义的活动,因为这些专家领域经历了转变:安全如何以不同的方式构成A)评估,B)架构,C)组织和D)功能的问题。如果网络安全的本质不是固定的,而是通过一些专家实践折射出来的,那么重要的是要检查和理解它是如何变化的,以及对社会、组织和政策制定者的影响。Scaling Trust包括与政策制定者和组织的参与活动组合。它涉及使用定性研究方法的调色板,而且还为组织和研究人员开发了一种新的参与式研讨会形式,称为“信任映射”。这是一个奖学金项目,因此也涉及对PI的投资,Matt Spencer博士,支持他的职业轨迹和网络安全研究领导地位的发展。
英文摘要
Scaling Trust is an interdisciplinary research project drawing on resources from anthropology, sociology, communication studies, literary theory, philosophy of science and computing. Using interviews, textual analysis, workshops and ethnography, Scaling Trust examines recent transformations in Cyber Security across four distinct domains, and asks: how are novel models and methods reshaping trust and securing in contemporary society? How do new forms of narrativizing threats, problems of technology and scale, and security solutions define what a secure future may be?A) In the initial period of the fellowship, we investigated current transformations in technology assurance. Security in this domain has been treated as a quality of technical products, a quality that can be tested and measured in an evaluation lab. In recent years, we can observe increasing awareness of unintended side effects of reliance on trusted products and the rise of new approaches focused on risk and the quality of communication.B) We also, in the initial fellowship period, examined the emergence of 'de-perimeterised' security models, today most prominently associated with 'Zero Trust' IT architectures. We examine the nature of security models in general, and how this one in particular has challenged intuitions of information security as the protection of an 'inside' of a private network, and focussed attention instead on asset value. This formulation of the object of securing has profound implications for what counts as a security technology, and for how users/people are positioned and treated. C) In the renewal period, we will conduct an empirical study of the 'DevSecOps' movement, a movement that aims to reconfigure organisations, so that security, here understood as an organisational function, is no longer in a 'silo', but becomes integrated in collaborative multi-function delivery teams. The focus on social architecture here draws on classic organisational thinking in software development, such as Conway's law (that technology tends to inherit a pattern of organisation from the structure of teams who made it), on 'Secure by Design' concepts, and is driven by the demands of continuous delivery methodologies. Securing is here understood as what a part of an organisation does, alongside developing, maintaining and operating.D) During the renewal period, we also build out a study of the recent emergence of hardware-based vulnerabilities, such as Rowhammer, SPECTRE and Meltdown, which have fundamentally challenged some of the certainties upon which security reasoning was built. These vulnerabilities drew attention to the level of hardware as a source of uncertainty, challenging the notion that security can be understood via analysis of logics implemented in software. In addition to preventing attacks, securing thus becomes a matter of being responsive to novel vulnerabilities as they emerge. In Scaling Trust, we examine the narrativization of security, how securing is constituted as a meaningful activity in distinct, but intersecting ways, as these expert domains undergo transformation: how security is variously posed as a problem of A) evaluation, B) architecture, C) organisation and D) function. If, as we argue, the nature of cyber security is not fixed, but rather refracts through a number of expert practices, it is important to examine and make sense of how it is changing and the implications for society, for organisations and for policymakers.Scaling Trust includes a portfolio of engagement activities with policymakers and with organisations. It involves the use of a palette of qualitative research methodologies, but also the development of a new participatory workshop format, called 'Trust Mapping' for organisations and researchers. It is a fellowship project, and thus also involves investment in the PI, Dr Matt Spencer, supporting his career trajectory and development of a position of research leadership in cyber security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Scaling Trust: An Anthropology of Cyber Security
  • 批准号:
    MR/S037373/1
  • 项目类别:
    Fellowship
  • 资助金额:
    $61.58万
  • 财政年份:
    2019
  • 负责人:
    Matthew Spencer
  • 依托单位:
Dynamics of community composition
  • 批准号:
    NE/K00297X/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $48.81万
  • 财政年份:
    2013
  • 负责人:
    Matthew Spencer
  • 依托单位:
Collaborative Research: Continued Study of Physical Properties of the WAIS Divide Deep Core
  • 批准号:
    1043313
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $12.02万
  • 财政年份:
    2011
  • 负责人:
    Matthew Spencer
  • 依托单位:
Collaborative Research: Combined Physical Property Measurements at Siple Dome
  • 批准号:
    0917509
  • 项目类别:
    Standard Grant
  • 资助金额:
    $3.55万
  • 财政年份:
    2008
  • 负责人:
    Matthew Spencer
  • 依托单位:
海外基金