SoS Quarterly Lablet Meeting, Oct '14 at UMD

file

Visible to the public SoK: Policy and Governance for Sociotechnical Systems (Discussion Points)

ABSTRACT

I introduce some ideas about policy and governance in sociotechnical systems, approaching these topics from a normative standpoint. I propose that the normative concepts can provide the elements of a new potential foundations for security. I describe how we can characterize a variety of security-relevant behaviors in normative terms touching upon the challenges of accountability and how accountability differs from, yet relates to, mechanisms for monitoring and sanctioning

file

Visible to the public System Science of SecUrity and REsilience for Cyber-Physical Systems (SURE)

ABSTRACT

The project on the System Science of SecUrity and REsilience for cyber-physical systems (SURE) will develop foundations and tools for designing, building, and assuring cyber-physical systems (CPS) that can maintain essential system properties in the presence of adversaries. The technology base of SURE will provide CPS designers and operators with models, methods, and tools that can be integrated with an end-to-end model-based design flow and tool chain.

file

Visible to the public SoS-VO Developments

Overview of some recently released and upcoming new features on the VO.

file

Visible to the public Insights into Composability from Lablet Research

Abstract

This presentation describes a framework for understanding the hard problem of Composability in the setting of security, along with highlights of lablet research results illustrating recent progress in this area and remaining research challenges.

file

Visible to the public Deploying the Security Behavior Observatory: An Infrastructure for Long-term Monitoring of Client Machines

Abstract: Much of the data researchers usually collect about users' privacy and security behavior comes from short-term studies and focuses on specific, narrow activities. We present a design architecture and deployment of the Security Behavior Observatory (SBO), a client-server infrastructure designed to collect a wide array of data on user and computer security- and privacy-related behavior from a panel of hundreds of participants over several years. The SBO infrastructure had to be carefully designed to fulfill several requirements.