Project Grant 2339679

Award Date 7/1/24
Completion Date 6/30/29
Dollars Obligated $229K
Federal Grant Program
47.070
Assistance Type
Project Grant
Place of Performance
Madison, WI 53715, USA
Similar Awards
This Project Grant award of $100,000 from the National Science Foundation (NSF) Social, Behavioral, and Economic Sciences (CFDA 47.075) program supports research by Cornell University to improve personal account security. The project aims to: Better understand the experiences of individuals targeted by abusive digital attacks, support professionals, and adversaries through qualitative stakeholder investigations. Catalog existing account management tools and emerging authentication mechanisms,...
This Project Grant award, totaling $200,000.00, is funded by the National Science Foundation (NSF) under the Computer and Information Science and Engineering (CFDA 47.070) program. The award will support a collaborative research project focused on designing secure account management tools and frameworks to improve personal account security and foster safer digital ecosystems for people facing targeted attacks. The key objectives of the research are to: 1) gain a better understanding of the...
This Project Grant award from the National Science Foundation (CFDA 47.070 - Computer and Information Science and Engineering) to Florida International University totaling $600,000 aims to advance the security and privacy of on-device machine learning (ML) models used in Internet of Things (IoT)-driven scientific cyberinfrastructure (CI). The project has two primary goals: Develop a novel runtime detection and prevention mechanism to protect ML models from extraction attacks that could lead to...
The National Science Foundation (NSF) awarded a $198,607 Project Grant under the Computer and Information Science and Engineering (CFDA 47.070) program to the Georgia Tech Research Corporation (Georgia Tech) to conduct collaborative research on understanding and combatting impersonation attacks and data leakage risks in online advertising networks. The project aims to: 1) define and enumerate a new class of privacy threats from ad networks' cross-device user tracking efforts, 2) develop...
This Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program (CFDA 47.070) supports the development of a learner-centered artificial intelligence (AI) co-pilot tool to crowd-source the curation of comprehensive cybersecurity attack artifacts. The $299,999 award to the Rochester Institute of Technology (RIT) aims to leverage large language models and techniques like prompt engineering to guide users in emulating end-to-end...
This National Science Foundation (NSF) Division of Information and Intelligent Systems Project Grant award of $1,132,002 to the Regents of the University of Michigan, Office of Research and Sponsored Projects (doing business as the University of Michigan), will examine the design of sociotechnical systems that offer user controls for combating non-consensual intimate media (NCIM) and deter perpetrators from sharing it. The research objectives include: 1) understanding victim needs through design...
This $102,471 Project Grant awarded by the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program (CFDA 47.070) will support the development of a general query framework to enhance cyber attack investigation using system audit logs. The key products and services to be delivered under this grant include: Building an infrastructure to compute discriminative weights for dependencies and identify attack-relevant events and entry points from system audit...
This three-year, $244,997 Project Grant from the National Science Foundation's Computer and Information Science and Engineering program aims to develop scalable methods for analyzing large-scale network traffic data to quantify internet-of-things (IoT) device insecurities and characterize malicious IoT campaigns. The awardee, San Diego State University Research Foundation, will work with collaborators to design algorithms and formal methods using supervised deep learning to fingerprint exploited...
This $100,000 Project Grant award from the National Science Foundation's (NSF) Social, Behavioral, and Economic Sciences (CFDA 47.075) program supports the development of an empathy-based framework to enhance privacy education and design. The project team at the University of Notre Dame is using generative AI to create synthetic personas with AI-generated personal data. These personas are then used to design interactive sandboxes and developer tools that allow individuals to empathize with the...
This Project Grant from the National Science Foundation's Technology, Innovation, and Partnerships program totaling $100,000.00 was awarded on June 15, 2022 to Texas Tech University to develop a technology platform to automatically measure user susceptibility to social engineering attacks. The platform will quantify individual users' personality traits, demographics, education, and experiences using publicly available information to estimate susceptibility to phishing attacks. This will help...

CAREER: ACCOUNT SECURITY AGAINST INTERPERSONAL ATTACKS -ACCOUNT SECURITY LOGS ARE DESIGNED BY ONLINE SERVICES TO HELP USERS DETECT IF THERE WAS AN UNAUTHORIZED LOGIN TO THEIR ACCOUNTS. HOWEVER, CURRENT ACCOUNT SECURITY LOGS OFFER UNRELIABLE AND COARSE-GRAINED INFORMATION FOR USERS TO DIFFERENTIATE THEIR LOGINS FROM ATTACKERS' LOGINS. LIMITED DATA, SUCH AS DEVICE MODEL AND APPROXIMATE CITY OR PROVINCE BASED ON IP ADDRESSES, CAN BE EASILY SPOOFED BY ATTACKERS, ESPECIALLY IN CASES OF INTERPERSONAL ATTACKS. INTERPERSONAL ATTACKERS KNOW THE VICTIMS PERSONALLY; THEY MAY BE AN INTIMATE PARTNER, FAMILY MEMBER, FRIEND, OR COLLEAGUE. AN INTERPERSONAL ATTACKER MAY LIVE IN THE SAME HOUSE OR TOWN AND POSSESS DEVICES WITH IDENTICAL MODELS AS THE VICTIM, MAKING IT CHALLENGING FOR VICTIMS TO CONCLUSIVELY DETECT UNAUTHORIZED LOGINS BY THEIR ATTACKERS. THE KEY PROBLEM HERE IS TWOFOLD: (A) THERE IS NO UNIQUE AND NON-SPOOFABLE DEVICE IDENTIFIER THAT PRESERVES USER PRIVACY, AND (B) HUMANS AND ONLINE SERVICES IDENTIFY PHYSICAL DEVICES DIFFERENTLY. IN THIS PROJECT, WE AIM TO TACKLE THESE ISSUES BY DEVELOPING A FRAMEWORK OF DEVICE IDENTIFIERS THAT CAN UNIQUELY IDENTIFY A DEVICE WHILE PRESERVING USERS' PRIVACY AND USERS ARE ABLE TO RECOGNIZE AND ASSOCIATE THOSE IDS WITH THEIR RESPECTIVE PHYSICAL DEVICE, BRIDGING THE DISCONNECT BETWEEN THE METHODS OF IDENTIFYING DEVICES BY HUMANS AND SOFTWARE. THIS PROJECT IS DESIGNING, IMPLEMENTING, AND EVALUATING NOVEL WAYS TO IMPROVE ACCOUNT SECURITY LOGS TO ENHANCE UNAUTHORIZED LOGIN DETECTION. THE OBJECTIVES OF THE PROJECT ARE TO (A) DESIGN AND IMPLEMENT A PROTOCOL FOR DERIVING UNIQUE YET PRIVACY PRESERVING IDENTIFIERS OF DEVICES; (B) EXPLORE METHODS TO FAMILIARIZE USERS WITH SUCH DEVICE IDENTIFIERS WITHOUT DISRUPTING THEIR USER EXPERIENCE, AND (C) REDESIGN ACCOUNT SECURITY LOGS TO INCORPORATE SUCH IDENTIFIERS AND MEASURE THEIR EFFICACY IN DETECTING UNAUTHORIZED LOGS. THE BROADER IMPACTS OF THE PROJECT INCLUDE: (1) PRODUCING GUIDELINES AND ENGAGING WITH DEVELOPERS OF ONLINE SERVICES TO ENHANCE ACCOUNT SECURITY MECHANISMS, (2) DEPLOYING UNAUTHORIZED LOGIN DETECTION WITH MADISON TECH CLINIC (MTC) AND CLINIC TO END TECH ABUSE (CETA) IN NEW YORK CITY TO SUPPORT SURVIVORS OF IA, (3) TEACHING STUDENTS ABOUT NUANCED THREAT MODELS, LIKE THOSE OF IA, AND (4) INCREASING THE PARTICIPATION OF STUDENTS FROM MINORITY BACKGROUNDS, SUCH AS WOMEN AND LGBTQ+ STUDENTS, BY PROVIDING A SPACE TO ENGAGE AND INFLUENCE TECHNOLOGIES WITH REAL-WORLD IMPACT ON THEIR LIVES. THIS AWARD REFLECTS NSF'S STATUTORY MISSION AND HAS BEEN DEEMED WORTHY OF SUPPORT THROUGH EVALUATION USING THE FOUNDATION'S INTELLECTUAL MERIT AND BROADER IMPACTS REVIEW CRITERIA.- SUBAWARDS ARE NOT PLANNED FOR THIS AWARD.

Posted 3/4/24, 12:00 AM