Collaborative Research: Type Qualifiers for Software Security
Collaborative Research: Type Qualifiers for Software Security
批准号:
0430585
负责人:
David Wagner
金额:
$0.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-09-15 至 2009-08-31
中文摘要
0430585瓦格纳,大卫 协作研究:用于软件安全的类型验证器0430378 Alex Aiken 0430118 Foster,Jeffrey 本研究旨在开发工具和技术来发现和消除软件中的安全漏洞。 该方法基于静态分析,通过分析源代码可以对程序的所有可能执行进行建模。 该项目的显着特点是表明,非常大的应用程序是免费的安全漏洞类。 因此,重点不仅仅是在软件中找到安全漏洞,而是验证它们的存在。 以往的经验表明,简单、近似的工具无法找到所有甚至几乎所有的安全漏洞;需要通过验证提供更高的保证。 实验的目标是将这些技术应用于Linux内核,这是一个具有数百万行代码的安全关键应用程序。正在研究的主要技术方法是基于用户定义的类型限定符,这些限定符细化了编程语言的标准类型。 以前的工作表明,类型限定符是显式指定所需安全属性的一种自然而有用的方法,这些属性通常只在程序中隐式存在。 就像一个正确类型的程序不会有运行时类型错误一样,在整个程序中具有一致的类型限定符意味着这些限定符所表达的属性必须在每次执行中都保持不变。 这项工作的意义在于,如果成功的话,它将提高对如何执行非常大型程序的复杂静态分析的理解。 更广泛的影响将是发现和修复广泛使用的软件基础设施中的新安全漏洞,并验证其中一些基础设施至少没有一些安全漏洞。
英文摘要
0430585 Wagner, David Collaborative Research: Type Qualifiers for Software Security0430378 Alex Aiken 0430118 Foster, Jeffrey This research aims to develop tools and techniques to find and eliminate security vulnerabilities in software. The approach is based on static analysis, which by analyzing source code can model all possible executions of a program. The distinguishing feature of the project is to show that very large applications are free from classes of security vulnerabilities. Thus, the focus is not just in finding security holes in software, but in verifying their absence. Previous experience has shown that simple, approximate tools do not find all or even nearly all security vulnerabilities; the higher assurance given by verification is needed. The experimental goal is to apply these techniques to the Linux kernel, a security-critical application with millions of lines of code.The main technical approach being investigated is based on user-defined type qualifiers that refine the standard types of the programming language. Previous work has shown that type qualifiers are a natural and useful way to explicitly specify desired security properties that are normally only implicit in a program. In much the same way that a correctly typed program cannot have run-time type errors, having consistent type qualifiers throughout a program implies that the property expressed by those qualifiers must hold in every execution. The significance of this work is that, if successful, it will improve the understanding of how to perform sophisticated static analysis of very large programs. The broader impact will be in discovering and repairing new security vulnerabilities in widely-used software infrastructure and in verifying that some of that infrastructure is free from at least some security flaws.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
RCN: An International Network to Assess the Status of Insects
-
批准号:2225092
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2022
-
负责人:David Wagner
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Machine Learning for Cybersecurity: Robustness Against Concept Drift
-
批准号:2154873
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2022
-
负责人:David Wagner
-
依托单位:
REU Site: Summer Undergraduate Program in Engineering Research at Berkeley-Responsible Artificial Intelligence (SUPERB-RAI)
-
批准号:1950668
-
项目类别:Standard Grant
-
资助金额:$32.98万
-
财政年份:2020
-
负责人:David Wagner
-
依托单位:
TWC: Medium: Collaborative: Security and Privacy for Wearable and Continuous Sensing Platforms
-
批准号:1514457
-
项目类别:Standard Grant
-
资助金额:$35.03万
-
财政年份:2015
-
负责人:David Wagner
-
依托单位:
TWC: Small: A Choice Architecture for Mobile Privacy and Security
-
批准号:1318680
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2013
-
负责人:David Wagner
-
依托单位:
TC: Small: Securing Web Software Systems
-
批准号:1018924
-
项目类别:Standard Grant
-
资助金额:$48.0万
-
财政年份:2010
-
负责人:David Wagner
-
依托单位:
CT-T: Collaborative Research: Complex, High-level, Integrated Properties for Security
-
批准号:0716715
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2007
-
负责人:David Wagner
-
依托单位:
Dissertation Research: Systematics and Morphology of Metalmark Moths (Lepidoptera: Choreutidae)
-
批准号:0608399
-
项目类别:Standard Grant
-
资助金额:$1.1万
-
财政年份:2006
-
负责人:David Wagner
-
依托单位:
Collaborative Research: CT-CS: A Center for Correct, Usable, Reliable, Auditable, and Transparent Elections (ACCURATE)
-
批准号:0524745
-
项目类别:Continuing Grant
-
资助金额:$129.56万
-
财政年份:2005
-
负责人:David Wagner
-
依托单位:
CAREER: Security in the Large: Gaining Assurance in Real-World Systems
-
批准号:0093337
-
项目类别:Continuing Grant
-
资助金额:$26.77万
-
财政年份:2001
-
负责人:David Wagner
-
依托单位:
ITR/SY(CISE): Cryptography: Examining the Assumptions
-
批准号:0113941
-
项目类别:Continuing Grant
-
资助金额:$37.49万
-
财政年份:2001
-
负责人:David Wagner
-
依托单位:
Dissertation Research: Phylogeny and the Evolution of Host Use and Host Specialization in the Endophagous Moth Genus Papaipema (Lepidoptera: Noctuidae)
-
批准号:9423516
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:1995
-
负责人:David Wagner
-
依托单位:
Mean Value Analysis Models of Deflection-Routed Interconnection Networks
-
批准号:9301964
-
项目类别:Standard Grant
-
资助金额:$5.85万
-
财政年份:1993
-
负责人:David Wagner
-
依托单位:
A Simulation/Interactive Video Physics Laboratory
-
批准号:9252332
-
项目类别:Standard Grant
-
资助金额:$1.91万
-
财政年份:1992
-
负责人:David Wagner
-
依托单位:
Hybrid Approaches to Loosely-Synchronized Parallel Discrete-Event Simulation
-
批准号:9010672
-
项目类别:Standard Grant
-
资助金额:$6.0万
-
财政年份:1990
-
负责人:David Wagner
-
依托单位:
Morphology and Cladistic Relationships of North American Gracillariid Genera (Lepidoptera)
-
批准号:9007671
-
项目类别:Standard Grant
-
资助金额:$6.57万
-
财政年份:1990
-
负责人:David Wagner
-
依托单位:
Mathematical Sciences: Research in Nonlinear Partial Differential Equations and Bifurcation Theory
-
批准号:8601917
-
项目类别:Standard Grant
-
资助金额:$1.7万
-
财政年份:1986
-
负责人:David Wagner
-
依托单位:
Summer Pre-College Teacher Development Project in History Of Science
-
批准号:7713759
-
项目类别:Standard Grant
-
资助金额:$1.59万
-
财政年份:1977
-
负责人:David Wagner
-
依托单位:
Student Science Training For High Ability Secondary School Students
-
批准号:7505951
-
项目类别:Standard Grant
-
资助金额:$1.94万
-
财政年份:1975
-
负责人:David Wagner
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: