CT: New Techniques for Attack Detection, Prevention and Immunization
CT: New Techniques for Attack Detection, Prevention and Immunization
批准号:
0627687
负责人:
Ramasubramanian Sekar
金额:
$35.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-09-01 至 2010-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Software vulnerabilities have been the biggest culprit behind cyberattacks in the past several years. A handful of vulnerabilities, such asbuffer overflows, format string, SQL injection, command injection,cross-site scripting, and directory traversals, have come to dominate,accounting for about 70% of the CVE vulnerabilities reported in the lasttwo years. Although that these vulnerabilities are well understood anddocumented, their number continues to escalate from one year to the next.New vulnerabilities continue to be discovered in recently releasedsoftware, as well as established software.This will develop novel techniques for defending applications from knownas well as unknown attacks, and for immunizing applications from futureattack instances. The proposed approach can thus protect the integrity aswell as the availability of vulnerable applications. A central componentof the proposed approach is an efficient fine-grained dynamic taintanalysis that tracks the flow of untrusted information through avulnerable program. Both specification-based and anomaly-based attackdetection techniques can be made highly versatile and accurate by usingfine-grained taint, and can stop the wide range of attacks mentionedabove. Taint analysis will also form the basis of an immunizationtechnique that is based on learning input filters that characterizeattack-bearing inputs, and selectively discarding such inputs.The proposed work can address multi-billion dollar losses experienced dueto cyber attacks, since it can stop most types of exploits before theycause damage. To maximize impact, the techniques developed in the projectwill be implemented into open-source software prototypes.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: WebSheets: A New Privacy-Centric Framework for Web Applications
-
批准号:2153056
-
项目类别:Standard Grant
-
资助金额:$101.93万
-
财政年份:2022
-
负责人:Ramasubramanian Sekar
-
依托单位:
SaTC: CORE: Medium: Collaborative: RADAR: Real-time Advanced Detection and Attack Reconstruction
-
批准号:1918667
-
项目类别:Standard Grant
-
资助金额:$59.99万
-
财政年份:2019
-
负责人:Ramasubramanian Sekar
-
依托单位:
TWC: Small: A platform for enhancing security of binary code
-
批准号:1319137
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2013
-
负责人:Ramasubramanian Sekar
-
依托单位:
CT-T: Proactive Techniques for Preserving System Integrity: A Basis for Robust Defense Against Malware
-
批准号:0831298
-
项目类别:Continuing Grant
-
资助金额:$100.0万
-
财政年份:2008
-
负责人:Ramasubramanian Sekar
-
依托单位:
Collaborative Project: An Extensible Software Platform for a Virtual Cyber Security Laboratory
-
批准号:0817188
-
项目类别:Standard Grant
-
资助金额:$19.1万
-
财政年份:2008
-
负责人:Ramasubramanian Sekar
-
依托单位:
Center for Information Protection: A Multi-University Industry/University Collaborative Research Center
-
批准号:0733935
-
项目类别:Continuing Grant
-
资助金额:$25.0万
-
财政年份:2007
-
负责人:Ramasubramanian Sekar
-
依托单位:
A Plan for Developing a Multi-University Industry/University Collaborative Research Center on Cyber Security
-
批准号:0532030
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2005
-
负责人:Ramasubramanian Sekar
-
依托单位:
Scholarship for Service in Information Assurance
-
批准号:0417103
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Ramasubramanian Sekar
-
依托单位:
Collaborative Research: Capacity Expansion in Information Assurance
-
批准号:0313858
-
项目类别:Standard Grant
-
资助金额:$19.99万
-
财政年份:2003
-
负责人:Ramasubramanian Sekar
-
依托单位:
A New Approach for Securing Systems Using Automated Adaptive Intrusion Response
-
批准号:0208877
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2002
-
负责人:Ramasubramanian Sekar
-
依托单位:
A Model-Based Approach for Securing Software Systems
-
批准号:0098154
-
项目类别:Continuing Grant
-
资助金额:$19.98万
-
财政年份:2001
-
负责人:Ramasubramanian Sekar
-
依托单位:
海外基金