TC: Medium: Collaborative Research: User-Controllable Policy Learning

TC:媒介:协作研究:用户可控的策略学习

基本信息

  • 批准号:
    0905403
  • 负责人:
  • 金额:
    $ 45万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2009
  • 资助国家:
    美国
  • 起止时间:
    2009-10-01 至 2013-09-30
  • 项目状态:
    已结题

项目摘要

As both corporate and consumer-oriented applications introduce new functionality and increased levels of customization and delegation, they inevitably give rise to more complex security and privacy policies. Yet, studies have repeatedly shown that both lay and expert users are not good at configuring policies, rendering the human element an important, yet often overlooked source of vulnerability. This project aims to develop and evaluate a new family of user-controllable policy learning techniques capable of leveraging user feedback and presenting them with incremental, user-understandable suggestions on how to improve their security or privacy policies. In contrast to traditional machine learning techniques, which are generally configured as ?black boxes? that take over from the user, user-controllable policy learning aims to ensure that users continue to understand their policies and remain in control of policy changes. As a result, this family of policy learning techniques offers the prospect of empowering lay and expert users to more effectively configure a broad range of security and privacy policies. The techniques to be developed in this project will be evaluated and refined in the context of two strategically important domains, namely privacy policies in social networks and firewall policies. In the process, work to be conducted in this project is also expected to lead to a significantly deeper understanding of (1) the difficulties experienced by users as they try to specify and refine security and privacy policies, and (2) what it takes to overcome these difficulties. The latter includes developing models of the types of policy modifications users can relate to and exploit as well as an understanding of the tradeoffs between usability and the number of policy modifications users are presented with. It also includes understanding how the effectiveness of user-controllable policy learning is impacted by the expressiveness of underlying policy languages, modes of interaction with the user (e.g. graphical versus text-based), and the topologies across which policies are deployed,
随着公司和面向消费者的应用程序都引入了新的功能,并提高了自定义和授权水平,它们不可避免地会产生更复杂的安全性和隐私政策。然而,研究反复表明,外行和专家用户都不擅长配置政策,从而使人类因素成为重要但经常被忽视的脆弱性来源。该项目旨在开发和评估一个可利用用户反馈并向他们提出有关如何改善其安全性或隐私政策的逐步,用户可靠的建议,并向他们介绍新的可控制策略学习技术的新家族。与传统的机器学习技术相反,通常将它们配置为“黑匣子”?从用户接管的情况下,可控制用户的策略学习旨在确保用户继续了解其政策并保持控制策略更改。结果,这种政策学习家族提供了授权外行和专家用户更有效地配置广泛的安全性和隐私政策的前景。该项目中要开发的技术将在两个具有战略上重要的领域的背景下进行评估和完善,即社交网络和防火墙政策中的隐私政策。在此过程中,预计在该项目中要进行的工作还会使(1)用户试图指定和完善安全性和隐私政策时遇到的困难,以及(2)克服这些困难所需的事情。后者包括开发用户可以与和利用的策略修改类型的模型,以及对可用性与用户所呈现的策略修改数量之间的权衡的理解。它还包括了解用户控制策略学习的有效性如何受到潜在策略语言的表现力,与用户的互动方式(例如,基于图形的文本)的互动方式以及部署,部署,策略的拓扑。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

暂无数据

数据更新时间:2024-06-01

Steven Bellovin的其他基金

Collaborative Research: Conference: Workshop on Advanced Automated Systems, Contestability, and the Law
合作研究:会议:先进自动化系统、可竞争性和法律研讨会
  • 批准号:
    2349804
    2349804
  • 财政年份:
    2023
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant
SaTC: TTP: Small: Easy Email Encryption
SaTC:TTP:小型:轻松电子邮件加密
  • 批准号:
    1717801
    1717801
  • 财政年份:
    2017
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant
TWC: Small: Virtual Private Social Networks
TWC:小型:虚拟私人社交网络
  • 批准号:
    1318415
    1318415
  • 财政年份:
    2013
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant
Collaborative Research: Planning Grant: A Clean-Slate Design for the Next-Generation Secure Internet
合作研究:规划拨款:下一代安全互联网的全新设计
  • 批准号:
    0540274
    0540274
  • 财政年份:
    2005
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant

相似国自然基金

复合低维拓扑材料中等离激元增强光学响应的研究
  • 批准号:
    12374288
  • 批准年份:
    2023
  • 资助金额:
    52 万元
  • 项目类别:
    面上项目
基于管理市场和干预分工视角的消失中等企业:特征事实、内在机制和优化路径
  • 批准号:
    72374217
  • 批准年份:
    2023
  • 资助金额:
    41.00 万元
  • 项目类别:
    面上项目
托卡马克偏滤器中等离子体的多尺度算法与数值模拟研究
  • 批准号:
    12371432
  • 批准年份:
    2023
  • 资助金额:
    43.5 万元
  • 项目类别:
    面上项目
中等质量黑洞附近的暗物质分布及其IMRI系统引力波回波探测
  • 批准号:
    12365008
  • 批准年份:
    2023
  • 资助金额:
    32 万元
  • 项目类别:
    地区科学基金项目
中等垂直风切变下非对称型热带气旋快速增强的物理机制研究
  • 批准号:
    42305004
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1630037
    1630037
  • 财政年份:
    2015
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1064646
    1064646
  • 财政年份:
    2011
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064944
    1064944
  • 财政年份:
    2011
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065216
    1065216
  • 财政年份:
    2011
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
  • 批准号:
    1065130
    1065130
  • 财政年份:
    2011
  • 资助金额:
    $ 45万
    $ 45万
  • 项目类别:
    Standard Grant
    Standard Grant