Lifelong learning is essential in computing, given the dynamic nature of the field. Employers and curricular reviewers recognize the value of being self-directed in support of becoming a lifelong learner. The ACM/IEEE-CS Computing Curricula 2020 report identifies self-directed as having elements of self-motivation, determination, and independence. Little is known, however, about how to cultivate this disposition in computing courses. The motivation of this study is to better understand what behaviors computing students believe are self-directed. This study's research questions are: 1) What do students describe as their self-directed practices in computing? and 2) What do students report are factors that prevent them from being self-directed? Assignments in five undergraduate computing courses from four institutions included prompts to elicit student's reflections on how they were self-directed (or not). Thematic content analysis using the constant comparative method produced eight categories of self-directed behaviors (utilizing external resources, learning necessary material, working independently, assessing oneself, planning ahead, applying useful techniques, completing the assigned work, and reviewing against expectations). Thematic analysis also resulted in five categories of factors that impeded the self-directed behavior (assignment structure, unsuccessful effort, self-sufficiency, insufficient motivation, and insufficient time). Understanding how students describe self-directedness can help educators design pedagogical and assessment approaches that facilitate self-directed student behaviors in the classroom.
This tutorial will introduce the Entrepreneurial Mindset (EM), an approach from engineering education that aims to foster students' motivation and ability to identify innovative opportunities, address complex, societal problems, and create value in diverse ways. EM specifically centers around the ''3Cs'': Curiosity, Connections, and Creating Value, which are concepts that can benefit students not only in entrepreneurship, but also in their CS work generally. In the tutorial, we will define and operationalize each of these concepts, and facilitate discussions on how participants likely already cover some of these concepts in their courses. We will also discuss facets of CS that especially benefit from EM, as well as how the dispositions, competencies, and behaviors that comprise EM serve as helpful complements to the knowledge, skills, and dispositions described in the CS2023 guidelines. These activities will help participants build a basic understanding of EM-related concepts and its connections to CS. We will then ask participants to design an intervention to foster EM in one of their existing courses, including an activity and an assessment plan, and present this draft to others in the workshop for peer feedback. This activity will help participants apply their understanding to their own teaching, and create a potential plan for integrating EM into their classroom. The tutorial will also introduce the Kern Entrepreneurial Engineering Network (KEEN), which developed EM, and describe further resources to learn about and engage with KEEN.
This full research paper contributes to current work on fostering the collaborative disposition among computing and engineering students. Collaborative work is essential in computing and engineering, given the scope and complexity of the projects within these fields. However, little is known about how to cultivate this disposition in the undergraduate classroom. The motivation of this research is to identify the categories of behaviors that students associate with being collaborative. The research questions for this study are: 1) What do students describe as collaborative practices applied to their coursework? and 2) What do students report as factors that prevent them from being collaborative? In computing courses at three institutions, students were asked to complete programming assignments and complete a reflection prompt after each assignment that asked “Describe an example of you being collaborative when completing this assignment. Otherwise, describe the circumstances that prevented you from being collaborative”. Responses were qualitatively/thematically analyzed resulting in the identification of ten categories of collaborative behaviors and nine categories of factors that impeded collaborative behavior. The significance of the study is that it deepens understanding of the collaborative disposition and identifies conditions that promote or discourage it. The results of this work will help educators design classroom interventions that will facilitate the development of the collaborative disposition among computing and engineering students.
Computing is everywhere, and it's here to stay. Computing is crucial in many disciplines and influences every discipline. It's unlikely we'll willingly return to a society unmediated by computing. How do our institutions proceed? This BoF asks, "Should computing be a requirement for all college and university students?" Some say yes, citing potential for improving equity-of-access, for expanding students' capabilities, for diversifying the people who understand and critique computing, and for increasing the diversity of computing participation. Some say no, citing the lack of equity-of-outcomes, the infeasibility of teaching all students equitably, and students' need for freedom in choosing what they study. Some say, "Let's consider the spectrum of possibilities... ." This session will discuss these possibilities, expressed and constrained by 2024's forces. Is computing's value saturated - or soon to be? Or is computing a meta-skill, whose practice in learning-to-learn amplifies individual efficacy along all paths? Is Computing1 too gate-kept to be as equitable a GenEd as Composition1? Or does requiring computing, in fact, help dismantle those gates? Can students adequately learn about core computing concepts via non-CS courses that use computing? What might required computing entail? We invite and welcome all with an interest in computing-as-degree-requirement, program-requirement, or GenEd offering. The session's seed materials will highlight evidence against the idea, for the idea, and across its vast, uncertain middle. Our BoF proposers include researchers and educators, both non-CS-requiring and CS-requiring, as well as non-CS-required and CS-required "educatees." Join us!
Characterising code quality is a challenge that was addressed by a previous ITiCSE Working Group (Borstler et al., 2017). As emerged from that study, educators, developers, and students have different perceptions of the aspects involved. The perception of code quality by CS1 students develops from the feedback they receive when submitting practical work. As a consequence of increasingly large classes and the widespread use of autograders, student code is predominantly assessed based on functional correctness, emphasising a machine-oriented perspective with scarce or no feedback given about human-oriented aspects of code quality. Such limited perception of code quality may negatively impact how students understand, create, and interact with code artefacts. Although Borstler et al. concluded that "code quality should be discussed more thoroughly in educational programs", the lack of materials and time constraints have slowed down progress in that regard. The goal of this Working Group is to support CS1 instructors who want to introduce a broader perspective on code quality in their classroom, by providing a curated list of examples and activities suitable for novices. In order to achieve this goal, we have extracted from the CS education literature a range of examples and activities, which have then been analysed and organised in terms of code quality dimensions. We have also mapped the topics covered in those materials to existing taxonomies relevant to code quality in CS1. Based on this work, we provide: (1) a catalogue of examples that illustrates the range of quality defects that could be addressed at CS1 level; and (2) a sample set of activities devised to introduce code quality to CS1 students. These materials have the potential to help educators address the subject in more depth.
Characterising code quality is a challenge that was addressed by Borstler et al.'s working group in 2017. As emerged from their study, educators, developers and students have different perceptions of the manifold aspects involved, and a major conclusion of that WG was that "code quality should be discussed more thoroughly in educational programs" [2, p. 70]. However, the lack of materials and the time constraints have slowed down progress in that regard. The goal of this working group is to propose manageable ways to address code quality in the CS1 classroom, with a particular focus on activities that help students become aware of and improve the quality of their code. To achieve this goal, we will (a) extract from the literature a comprehensive set of quality issues which will then be classified according to the appropriate strategies to fix them; and (b) circulate a survey to explore the instructors' views on code quality issues and the way they deal with (or ignore) them. Based on this work we aim to produce: (1) a taxonomy of code quality issues with associated examples, as well as (2) a sample set of teaching materials to introduce those issues to CS1 students.
Many recent proposals to increase the resilience of the Web PKI against misbehaving CAs face significant obstacles to deployment. These hurdles include (1) the requirement of drastic changes to the existing PKI players and their interactions, (2) the lack of signaling mechanisms to protect against downgrade attacks, (3) the lack of an incremental deployment strategy, and (4) the use of inflexible mechanisms that hinder recovery from misconfiguration or from the loss or compromise of private keys. As a result, few of these proposals have seen widespread deployment, despite their promise of a more secure Web PKI. To address these roadblocks, we propose Certificates with Automated Policies and Signaling (CAPS), a system that leverages the infrastructure of the existing Web PKI to overcome the aforementioned hurdles. CAPS offers a seamless and secure transition away from today’s insecure Web PKI and towards present and future proposals to improve the Web PKI. Crucially, with CAPS, domains can take simple steps to protect themselves from MITM attacks in the presence of one or more misbehaving CAs, and yet the interaction between domains and CAs remains fundamentally the same. We implement CAPS and show that it adds at most 5% to connection establishment latency.
Despite a great deal of work to improve the TLS PKI, CA misbehavior continues to occur, resulting in unauthorized certificates that can be used to mount man-in-the-middle attacks against HTTPS sites. CAs lack the incentives to invest in higher security, and the manual effort required to report a rogue certificate deters many from contributing to the security of the TLS PKI. In this paper, we present IKP, a platform that automates responses to unauthorized certificates and provides incentives for CAs to behave correctly and for others to report potentially unauthorized certificates. Domains in IKP specify criteria for their certificates, and CAs specify reactions such as financial penalties that execute in case of unauthorized certificate issuance. By leveraging smart contracts and blockchain-based consensus, we can decentralize IKP while still providing automated incentives. We describe a theoretical model for payment flows and implement IKP in Ethereum to show that decentralizing and automating PKIs with financial incentives is both economically sound and technically viable.
In this article, we address the problem of scaling authentication for naming, routing, and end-entity (EE) certification to a global environment in which authentication policies and users’ sets of trust roots vary widely. The current mechanisms for authenticating names (DNSSEC), routes (BGPSEC), and EE certificates (TLS) do not support a coexistence of authentication policies, affect the entire Internet when compromised, cannot update trust root information efficiently, and do not provide users with the ability to make flexible trust decisions. We propose the Scalable Authentication Infrastructure for Next-generation Trust (SAINT), which partitions the Internet into groups with common, local trust roots and isolates the effects of a compromised trust root. SAINT requires groups with direct routing connections to cross-sign each other for authentication purposes, allowing diverse authentication policies while keeping all entities’ authentication information globally discoverable. SAINT makes trust root management a central part of the network architecture, enabling trust root updates within seconds and allowing users to make flexible trust decisions. SAINT operates without a significant performance penalty and can be deployed alongside existing infrastructures.
Man-in-the-middle attacks in TLS due to compromised CAs have been mitigated by log-based PKI enhancements such as Certificate Transparency. However, these log-based schemes do not offer sufficient incentives to logs and monitors, and do not offer any actions that domains can take in response to CA misbehavior. We propose IKP, a blockchain-based PKI enhancement that offers automatic responses to CA misbehavior and incentives for those who help detect misbehavior. IKP’s decentralized nature and smart contract system allows open participation, offers incentives for vigilance over CAs, and enables financial recourse against misbehavior. We demonstrate through a game theoretic model and through an Ethereum prototype implementation that the incentives and increased deterrence offered by IKP are technically and economically viable.
With the emergence of secure network protocols that rely on public-key certification, such as DNSSEC, BGPSEC, and future Internet architectures, ISPs and domain administrators not specialized in certification have been thrust into certificate-signing roles. These so-called conscripted CAs sign a low volume of certificates, but still face the same challenges that plague modern CAs: private signing key security, administrator authentication, and personnel and key management. We propose CA Signing in a Touch-Less Environment (CASTLE), an air-gapped and completely touchless system to enable low-volume, high-security certificate signing in conscripted CAs. We demonstrate that CASTLE's layered, defense-in-depth approach is technically and practically feasible, and that CASTLE empowers conscripted CAs to overcome challenges that even professional CAs struggle with.
With the emergence of secure network protocols that rely on public-key certification, such as DNSSEC, BGPSEC, and future Internet architectures, ISPs and domain administrators not specialized in certification have been thrust into certificate-signing roles. These so-called conscripted CAs sign a low volume of certificates, but still face the same challenges that plague modern CAs: private signing key security, administrator authentication, and personnel and key management. We propose CA Signing in a Touch-Less Environment (CASTLE), an air-gapped and completely touchless system to enable low-volume, high-security certificate signing in conscripted CAs. We demonstrate that CASTLE's layered, defense-in-depth approach is technically and practically feasible, and that CASTLE empowers conscripted CAs to overcome challenges that even professional CAs struggle with.
We address the problem of scaling authentication for naming, routing, and end-entity certification to a global environment in which authentication policies and users' sets of trust roots vary widely. The current mechanisms for authenticating names (DNSSEC), routes (BGPSEC), and end-entity certificates (TLS) do not support a coexistence of authentication policies, affect the entire Internet when compromised, cannot update trust root information efficiently, and do not provide users with the ability to make flexible trust decisions. We propose a Scalable Authentication Infrastructure for Next-generation Trust (SAINT), which partitions the Internet into groups with common, local trust roots, and isolates the effects of a compromised trust root. SAINT requires groups with direct routing connections to cross-sign each other for authentication purposes, allowing diverse authentication policies while keeping all entities globally verifiable. SAINT makes trust root management a central part of the network architecture, enabling trust root updates within seconds and allowing users to make flexible trust decisions. SAINT operates without a significant performance penalty and can be deployed alongside existing infrastructures.
We propose to leverage accountability mechanisms to deal with trust-related security incidents of certification authorities (CAs) in the SSL/TLS public-key infrastructure (PKI). We argue that, despite recent advances in securing certificate issuance and verification, the TLS PKI does not sufficiently incentivize careful identity verification by CAs during certificate issuance or provide CA accountability in the event of a certificate compromise. We propose a new paradigm, Certificates-as-anInsurance, to hold CAs accountable for misbehavior by using insurance policies and benefits negotiated between the CA and the domain. In this positional paper, we only sketch an instantiation of our insurance model as an extension of the existing certification model and identify challenges for future research.
Log-based PKI enhancements propose to improve the current TLS PKI by creating public logs to monitor CA operations, thus providing transparency and accountability. In this paper we take the first steps in studying the deployment process of log-based PKI enhancements in two ways. First, we model the influences that parties in the PKI have to incentivize one another to deploy a PKI enhancement, and determine that potential PKI enhancements should focus their initial efforts on convincing browser vendors to deploy. Second, as a promising vendor-based solution we propose deployment status filters, which use a Bloom filter to monitor deployment status and efficiently defend against downgrade attacks from the enhanced protocol to the current TLS PKI. Our results provide promising deployment strategies for log-based PKI enhancements and raise additional questions for further fruitful research.
The flexibility of the current Domain Name System (DNS) has been stretched to its limits to accommodate new applications such as content delivery networks and dynamic DNS. In particular, maintaining cache consistency has become a much larger problem, as emerging technologies require increasingly-frequent updates to DNS records. Though Time-To-Live (TTL) is the most widely used method of controlling cache consistency, it does not offer the fine-grained control necessary for handling these frequent changes. In addition, TTLs are too static to handle sudden changes in traffic caused by Internet failures or social media trends, demonstrating their inflexibility in the face of unforeseen events.To address these problems, we first propose a metric called Expected Aggregate Inconsistency (EAI), which allows us to consider important factors such as a record's update frequency and popularity when quantitatively measuring inconsistency. We then design ECO-DNS, a lightweight system that leverages the information provided by EAI to optimize a record's TTL. This value can be tuned to individual cache servers' preferences between better consistency and bandwidth overhead. Furthermore, our optimization model's flexibility allows us to easily adapt ECO-DNS to handle various caching hierarchies such as multi-level caching while considering the tradeoff among consistency, overhead, latency, and server load.
The recently proposed concept of publicly verifiable logs is a promising approach for mitigating security issues and threats of the current Public-Key Infrastructure (PKI). Although much progress has been made towards a more secure infrastructure, the currently proposed approaches still suffer from security vulnerabilities, inefficiency, or incremental deployment challenges. In this paper we propose PoliCert, a comprehensive log-based and domain-oriented architecture that enhances the security of PKI by offering: a) stronger authentication of a domain's public keys, b) comprehensive and clean mechanisms for certificate management, and c) an incentivised incremental deployment plan. Surprisingly, our approach has proved fruitful in addressing other seemingly unrelated problems such as TLS-related error handling and client/server misconfiguration.
We present the malicious administrator problem, in which one or more network administrators attempt to damage routing, forwarding, or network availability by misconfiguring controllers. While this threat vector has been acknowledged in previous work, most solutions have focused on enforcing specific policies for forwarding rules. We present a definition of this problem and a controller design called Fleet that makes a first step towards addressing this problem. We present two protocols that can be used with the Fleet controller, and argue that its lower layer deployed on top of switches eliminates many problems of using multiple controllers in SDNs. We then present a prototype simulation and show that as long as a majority of non-malicious administrators exists, we can usually recover from link failures within several seconds (a time dominated by failure detection speed and inter-administrator latency).