Dynamic techniques for finding errors and preventing security violations
Dynamic techniques for finding errors and preventing security violations
批准号:
0305387
负责人:
Susan Horwitz
金额:
$0.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-07-01 至 2008-06-30
中文摘要
苏珊·霍维茨威斯康星大学麦迪逊分校编写正确、安全的软件是非常困难的。像C这样具有弱类型系统的语言使程序员很容易在他们的代码中引入错误和潜在的安全漏洞,从而加剧了这个问题。这个项目的目标是设计、实现和评估C程序的动态错误检测和安全实施工具。现有的动态错误检测工具受到覆盖率较低的限制:它们只能检测在给定程序执行期间实际发生的错误行为。这一限制将通过使用创新的动态技术来解决,以增加“数据覆盖率”(查找在不同输入值的情况下可能发生的错误)和“路径”覆盖率(查找在整个程序中遵循不同路径可能发生的错误)。安全执行工具将以较低的开销提供针对广泛攻击的保护,不需要修改现有源代码,也不需要程序员放弃对数据表示或内存管理的控制。
英文摘要
0305387Susan HorwitzUniversity of Wisconsin-MadisonWriting correct, secure software is very difficult. Languages like C that have weak type systems exacerbate the problem by making it easy for programmers to introduce errors and potential security holes intheir code.The goal of this project is the design, implementation, and evaluation of dynamic error-detection and security-enforcement tools for C programs. Existing dynamic error-detection tools are limited by poorcoverage: they can only detect erroneous behaviors that actually occur during a given program execution. That limitation will be addressed by the use of innovative new dynamic techniques for increasing both"data coverage" (finding errors that could occur given different input values) and "path" coverage (finding errors that could occur if a different path were followed through the program). The security-enforcement tool will provide protection against a wide range of attacks, with low overhead, without requiring modifications to existing source code, and without requiring the programmer to give up control over data representations or memory management.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Static and Dynamic Techniques for Classifying, Locating, and Fixing Bugs
-
批准号:0701957
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2007
-
负责人:Susan Horwitz
-
依托单位:
ITWF: Collaborative Research: Increasing the Representation of Undergraduate Women and Minorities in Computer Science
-
批准号:0420436
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Susan Horwitz
-
依托单位:
Software Reengineering via Method Extraction
-
批准号:9987435
-
项目类别:Standard Grant
-
资助金额:$17.57万
-
财政年份:2000
-
负责人:Susan Horwitz
-
依托单位:
Debugging Via Run-Time Type Checking
-
批准号:9970907
-
项目类别:Standard Grant
-
资助金额:$15.7万
-
财政年份:1999
-
负责人:Susan Horwitz
-
依托单位:
Special Project: Group Travel Grant for Faculty at Minority Institutions and Women's Colleges to attend PLDI 96
-
批准号:9625408
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:1996
-
负责人:Susan Horwitz
-
依托单位:
Program Dependence Graphs and Dataflow Analysis
-
批准号:9625656
-
项目类别:Standard Grant
-
资助金额:$16.08万
-
财政年份:1996
-
负责人:Susan Horwitz
-
依托单位:
Minority Graduate Research Honorable Mention - Gregory Simpson
-
批准号:8915593
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:1989
-
负责人:Susan Horwitz
-
依托单位:
PYI: Language-Based Tools for Programming Environments
-
批准号:8958530
-
项目类别:Continuing Grant
-
资助金额:$31.2万
-
财政年份:1989
-
负责人:Susan Horwitz
-
依托单位:
Generating Language-Based Programming Environments
-
批准号:8603356
-
项目类别:Standard Grant
-
资助金额:$8.73万
-
财政年份:1986
-
负责人:Susan Horwitz
-
依托单位:
国内基金
海外基金
EstimatingLarge Demand Systems with MachineLearning Techniques
-
批准号:--
-
项目类别:外国学者研究基金
-
资助金额:--
-
批准年份:2024
-
负责人:IoshuaAlex
-
依托单位:
计算电磁学高稳定度辛算法研究
-
批准号:60931002
-
项目类别:重点项目
-
资助金额:200.0万元
-
批准年份:2009
-
负责人:吴先良
-
依托单位: