Dynamic techniques for finding errors and preventing security violations
Dynamic techniques for finding errors and preventing security violations
批准号:
0305387
负责人:
Susan Horwitz
金额:
$0.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-07-01 至 2008-06-30
中文摘要
0305387苏珊Horwitz威斯康星大学麦迪逊分校写作正确,安全的软件是非常困难的。 像C这样的语言有着弱类型系统,这使得程序员很容易在代码中引入错误和潜在的安全漏洞,从而加剧了这个问题。本项目的目标是为C程序设计、实现和评估动态错误检测和安全执行工具。 现有的动态错误检测工具受到覆盖率低的限制:它们只能检测在给定程序执行期间实际发生的错误行为。 将通过使用创新的新的动态技术来解决这一限制,以增加“数据覆盖面”(发现在不同输入值下可能发生的错误)和“路径”覆盖面(发现在程序中遵循不同路径时可能发生的错误)。 安全执行工具将提供针对各种攻击的保护,开销低,不需要修改现有的源代码,也不需要程序员放弃对数据表示或内存管理的控制。
英文摘要
0305387Susan HorwitzUniversity of Wisconsin-MadisonWriting correct, secure software is very difficult. Languages like C that have weak type systems exacerbate the problem by making it easy for programmers to introduce errors and potential security holes intheir code.The goal of this project is the design, implementation, and evaluation of dynamic error-detection and security-enforcement tools for C programs. Existing dynamic error-detection tools are limited by poorcoverage: they can only detect erroneous behaviors that actually occur during a given program execution. That limitation will be addressed by the use of innovative new dynamic techniques for increasing both"data coverage" (finding errors that could occur given different input values) and "path" coverage (finding errors that could occur if a different path were followed through the program). The security-enforcement tool will provide protection against a wide range of attacks, with low overhead, without requiring modifications to existing source code, and without requiring the programmer to give up control over data representations or memory management.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Static and Dynamic Techniques for Classifying, Locating, and Fixing Bugs
-
批准号:0701957
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2007
-
负责人:Susan Horwitz
-
依托单位:
ITWF: Collaborative Research: Increasing the Representation of Undergraduate Women and Minorities in Computer Science
-
批准号:0420436
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Susan Horwitz
-
依托单位:
Software Reengineering via Method Extraction
-
批准号:9987435
-
项目类别:Standard Grant
-
资助金额:$17.57万
-
财政年份:2000
-
负责人:Susan Horwitz
-
依托单位:
Debugging Via Run-Time Type Checking
-
批准号:9970907
-
项目类别:Standard Grant
-
资助金额:$15.7万
-
财政年份:1999
-
负责人:Susan Horwitz
-
依托单位:
Special Project: Group Travel Grant for Faculty at Minority Institutions and Women's Colleges to attend PLDI 96
-
批准号:9625408
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:1996
-
负责人:Susan Horwitz
-
依托单位:
Program Dependence Graphs and Dataflow Analysis
-
批准号:9625656
-
项目类别:Standard Grant
-
资助金额:$16.08万
-
财政年份:1996
-
负责人:Susan Horwitz
-
依托单位:
Minority Graduate Research Honorable Mention - Gregory Simpson
-
批准号:8915593
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:1989
-
负责人:Susan Horwitz
-
依托单位:
PYI: Language-Based Tools for Programming Environments
-
批准号:8958530
-
项目类别:Continuing Grant
-
资助金额:$31.2万
-
财政年份:1989
-
负责人:Susan Horwitz
-
依托单位:
Generating Language-Based Programming Environments
-
批准号:8603356
-
项目类别:Standard Grant
-
资助金额:$8.73万
-
财政年份:1986
-
负责人:Susan Horwitz
-
依托单位:
国内基金
海外基金
EstimatingLarge Demand Systems with MachineLearning Techniques
-
批准号:--
-
项目类别:外国学者研究基金
-
资助金额:--
-
批准年份:2024
-
负责人:IoshuaAlex
-
依托单位:
计算电磁学高稳定度辛算法研究
-
批准号:60931002
-
项目类别:重点项目
-
资助金额:200.0万元
-
批准年份:2009
-
负责人:吴先良
-
依托单位: