Risk Management

group_project

Visible to the public TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale

The ability to generate random numbers -- to flip coins -- is crucial for many computing tasks, from Monte Carlo simulation to secure communications. The theory of building such subsystems to generate random numbers is well understood, but the gap between theory and practice is surprisingly wide. As built today, these subsystems are opaque and fragile. Flaws in these subsystems can compromise the security of millions of Internet hosts.

group_project

Visible to the public TWC: Medium: Secure and Resilient Vehicular Platooning

The goal of the project is to provide a secure foundation for a transportation system that increasingly relies on the cooperation, connectedness, and automation of vehicles to achieve increases in safety, efficiency, and capacity. The financial losses attributable to congestion in America's transportation infrastructure are more than $1 trillion annually and the parallel loss of life in vehicle collisions is 40,000 deaths per year.

group_project

Visible to the public EAGER: Neurobiological Basis of Decision Making in Online Environments

Considerable research in the field has been focused on developing new technologies to enhance privacy; encryption of personal data is often presented as a potential solution. Many of the technologies resulting from this research are not being effectively utilized because of issues rooted in human judgment under risk and uncertainty. The majority of existing models and products related to human judgement are based on a limited number of documented incidents and on questionable assumptions about user intent and behavior.

group_project

Visible to the public EAGER: Toward Automated Integration of Moving Target Defense Techniques

Moving Target defense (MTD) is a new Cybersecurity paradigm for deterring and disturbing attacks proactively in order to counter the ?asymmetry? phenomena in cyber warfare. A number of moving target techniques have been recently proposed to inverse this asymmetry by randomizing systems? attributes (e.g., configuration) and exhibiting non-determinism to attackers. However, due to potential inter-dependency between various MTD mechanisms, an ad hoc combination of MTD techniques can cause profoundly detrimental effect on security, performance and the operational integrity of the system.

group_project

Visible to the public  EAGER: The Role of Emotion in Risk Communication and Warning: Application to Risks of Failures to Update Software

End-users' online behavior can significantly affect the reliability and security of next-generation software systems. For instance, skipping repeated requests to update software or ignoring security warnings while visiting unknown websites, while extremely dangerous, are not uncommon. Although end-users' actions (or inactions) often open up the opportunity for cyber-attacks, the lack of emotional appeals and poor design of the current software update/warning messages are to blame to a large extent for such risky behavior, which is addressed as follows.

group_project

Visible to the public TWC: Option: Small: FRADE: Model Human Behavior for Flash cRowd Attack DEfense

Application-level, aka ``flash-DDoS'' attacks are the most challenging form of distributed denial of service (DDoS). They flood the victim with legitimate-like service requests generated from numerous bots. There is no defense today that is even remotely effective against flash-DDoS attacks, thus such attacks are today a serious and unmitigated threat to any server.

group_project

Visible to the public TWC SBE: Option: Small: Building Public Cyber Health - Designing and Testing the Efficacy of a School-Focused, Gamification Approach to Create a Secure Computing Environment

As the frequency and complexity of cyber attacks increase, approaches to create secure computing environments must look beyond technical barriers that protect from the outside to building a collaborative culture of cyber health from the inside. Use of online incentives have been shown to be an effective tool for enhancing an individual's engagement with a task.

group_project

Visible to the public TWC: Small: Discovering and Restricting Undesirable Information Flows Between Multiple Spheres of Activities

Loss of personal data or leakage of corporate data via apps on mobile devices poses a significant risk to users. It can have both a huge personal and financial cost. This work is designing new novel techniques to help reduce the risks for end-users who use a single device for multiple spheres of activity. Getting security right when a single device is used for multiple spheres of activity is a major research challenge, with unforeseen information flows between various subsystems that are currently difficult to control.

group_project

Visible to the public CAREER: Secure and Trustworthy Provenance for Accountable Clouds

Cloud computing has emerged as one of the most successful computing models in recent years. However, lack of accountability and non-compliance with data protection regulations have prevented major users such as business, healthcare, and defense organizations from utilizing clouds for sensitive data and applications. Due to the lack of information about cloud internals and the inability to perform trustworthy audits, today's clouds are often not used in regulated industries, preventing their widespread adoption.