140 likes | 168 Views
Jaime G. Carbonell. Mehrbod Sharifi. Eugene Fink. Personalized Cybersecurity for Dummies. Application of machine learning and crowdsourcing to adapt cybersecurity tools to the needs of (naïve) individual users. Different users need different security tools. Individual user differences.
E N D
Jaime G.Carbonell MehrbodSharifi EugeneFink Personalized Cybersecurityfor Dummies Application of machine learning and crowdsourcing to adapt cybersecurity tools to the needs of (naïve) individual users.
Different users need different security tools. Individual user differences • Security needs- Data confidentiality- Data-loss tolerance- Recovery costs • Usage patterns • Computer knowledge
Problems • Inflexible engineered solutionswith “too much security”- Too high security at high costs- Insufficient customization REIGN OF CONFUSION • “Advanced user” assumption- Complicated customization- Unclear security warnings
Typical response of naïve users: • Always no (too much security) • Always yes (not enough security) • Ask a techie if available Examples
User naïveté correctanswers Population statistics Computer use byage and gender
Population statistics • Almost everyone uses a computer • Most users are naïve, with very limited technical knowledge • Many security problems aredue to the user naïveté When an average user deals with security issues, she needs basic advice and handholding.
Long-term goal We need an automated security assistant that learns the needs of the individual user and helps the user to apply security tools. MACHINE LEARNING TO THE RESCUE
DEMO Initial results A security assistant for web browsing, integrated with Internet Explorer.
Scams (welcome to Nigeria) • Rip-offs (overpricing, low quality) • Bad info (inaccurate, biased) • ... and so on More problems Automated tools cannot detect “advanced” threats that go beyond software attacks.
Filter Integrate Long-term goal Rely on the collective wisdom of the users. CROWDSOURCING TO THE RESCUE Gather USERS OF THE WORLD, UNITE!
AVAILABLE AT WWW.CYBERPSA.COM DEMO Initial results A browser plug-in for the gathering of opinions and warnings about web pages.
Future research • Summarization of comments • Analysis of sentiments and biases • Identification of reliable contributors • Synergy with other techniques for analysis of web pages • … and so on