课题基金 / 基金详情

CT-T: Enabling Collaborative Self-Healing Software Systems

CT-T: Enabling Collaborative Self-Healing Software Systems
CT-T:实现协作式自我修复软件系统
批准号:
0627473
负责人:
Angelos Keromytis
金额:
$0.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-09-01 至 2011-08-31

项目摘要

项目成果

Angelos Keromytis的其他基金

相似基金

相关文献

中文摘要
翻译
Angelos Keroma哥伦比亚大学启用协作自愈软件系统P0627473专家小组P060975摘要协作自愈系统(COSS)是一种保护软件系统的新范式。软件单一培养是广泛使用的应用程序,它们具有共同的漏洞。因此,任何利用易受攻击的应用程序的一个实例的攻击都提供了广泛破坏的手段。协作安全这一新兴概念提供了利用软件单一文化的同质性进行集体和相互保护的机会。在协作安全的概念中,独立但合作的实体组成一个组来提高各自的安全性。可以利用单一培养来提高应用程序的整体安全性和可靠性。运行同一应用程序的独立实例的COSS成员将不断交换信息,使他们能够集体识别新的应用程序故障和攻击(协作监控),识别该应用程序的所有实例共享的核心漏洞(漏洞识别),并自动开发、测试和应用修复程序(修复应用程序)。识别应用程序漏洞可能需要在每个应用程序实例中插入和监控大量成本。我们利用COSS的大小,通过将监控任务分布在大量人群中,在每个实例的基础上分摊监控应用程序行为的成本;每个实例只监控通用应用程序的一部分,但总体上覆盖整个应用程序。COSS可以被视为一种大规模、多样化的软件测试工具,它允许其成员识别潜在的大型和复杂的主机应用程序在非常精细的粒度级别上的行为方式。该项目开发、原型和评估用于自动构建协作的、自我保护的软件系统的技术,从而实现可靠和安全的商用软件。
英文摘要
Angelos KeromytisColumbia UniversityEnabling Collaborative Self-healing Software Systems0627473Panel P060975AbstractCollaborative Self-healing Systems (COSS) is a new paradigm for protecting software systems. Software monocultures are widely used applications that share common vulnerabilities. Hence, any attack that exploits one instance of a vulnerable application provides the means for wide-spread damage. The emerging concept of collaborative security, wherein independent but cooperative entities form a group to improve their individual security, provides the opportunity to exploit the homogeneity of a software monoculture for collective and mutual protection. Monocultures can be leveraged to improve an application's overall security and reliability. COSS members running independent instances of the same application will continuously exchange information that allows them to collectively identify new application faults and attacks (collaborative monitoring), identify the core vulnerability shared by all instances of the application (vulnerability identification), and to automatically develop, test and apply fixes (heal the application). Identifying the application vulnerability requires potentially substantial costs in instrumentation and monitoring in each application instance. We leverage the size of a COSS to amortize the cost of monitoring the application's behavior on a per-instance basis by distributing the monitoring task across a large population; each instance only monitors a portion of the common application but collectively the entire application is covered. COSS may be viewed as a large-scale, diverse software-testing facility that allows its members to identify how a potentially large and complex host application behaves at a very fine level of granularity. This project develops, prototypes and evaluates technologies for automatically building collaborative, self-securing software systems, enabling reliable and secure commodity software.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: An Anti-tracking and Robocall-free Architecture for Next-G Mobile Networks
  • 批准号:
    2247562
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.97万
  • 财政年份:
    2023
  • 负责人:
    Angelos Keromytis
  • 依托单位:
U.S. Open-Source Software Security Initiative Workshop
  • 批准号:
    2232616
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.34万
  • 财政年份:
    2022
  • 负责人:
    Angelos Keromytis
  • 依托单位:
TWC: Small: Auditing PII in the Cloud with CloudFence
  • 批准号:
    1222748
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2012
  • 负责人:
    Angelos Keromytis
  • 依托单位:
NSF Support for the 2010 New Security Paradigms Workshop Financial Aid; September 2010; Concord, MA
  • 批准号:
    1019309
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.0万
  • 财政年份:
    2010
  • 负责人:
    Angelos Keromytis
  • 依托单位:
海外基金