课题基金 / 基金详情

CT-ER: On the Use of Security Metrics to Identify and Rank the Risk of Vulnerability- and Exploit-Prone Components

CT-ER: On the Use of Security Metrics to Identify and Rank the Risk of Vulnerability- and Exploit-Prone Components
CT-ER:关于使用安全指标来识别和排名易受攻击组件的风险
批准号:
0716176
负责人:
Laurie Williams
金额:
$0.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2007
资助国家:
美国
项目状态:
已结题
起止时间:
2007-08-01 至 2011-01-31
关键词:

项目摘要

项目成果

Laurie Williams的其他基金

相似基金

相关文献

中文摘要
翻译
CT-ER:关于使用安全度量来识别易受攻击和易被利用的组件的风险并对其进行排序几十年的软件工程研究已经表明,使用软件度量来识别易出错和易失败的组件,并在软件开发生命周期的早期预测系统的整体质量是有效的。软件开发组织使用这些知识来确定重新设计、确认和验证工作的优先级。在这项研究中,我们扩展了这项工作,以检查软件安全度量的相应能力,从而在软件开发生命周期的早期有效地识别易受攻击和易被利用的组件。这项研究的技术目标是创建并验证一个预测模型,该模型使用安全度量来识别软件产品中容易出现漏洞和容易被利用的组件的风险,并对其进行排序。该模型的结果可用于通知风险管理,并在生命周期的后期阶段优先考虑重新设计、确认和验证工作。通过预测模型指导软件开发工作的预期结果是生产出更安全的软件。教育目标是将这些研究结果纳入教育学生设计安全软件产品的资源中。
英文摘要
CT-ER: On the Use of Security Metrics to Identify and Rank the Risk of Vulnerability- and Exploit-Prone ComponentsDecades of software engineering research has shown the effectiveness of the use software metrics to identify fault- and failure-prone components and to predict the overall quality of a system early in the software development lifecycle. Software development organizations use this knowledge to prioritize their redesign and validation and verification efforts. In this research, we extend this work to examine the corresponding power of software security metrics to effectively identify vulnerability-prone and exploit-prone components early in the software development lifecycle. The technical objective of this research is to create and validate a predictive model that uses security metrics to identify and rank the risk of vulnerability-prone and exploit-prone components in a software product. The results of this model can be used to inform risk management and to prioritize re-design and validation and verification efforts in the later phases of the life cycle. The expected result from guiding software development efforts via the predictive model is the production of more secure software. The educational objective is to incorporate these research results into resources for educating students to engineer secure software products.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain
  • 批准号:
    2207008
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $634.45万
  • 财政年份:
    2022
  • 负责人:
    Laurie Williams
  • 依托单位:
SaTC: CORE: Small: Risk-based Secure Checked-in Credential Reduction for Software Development
  • 批准号:
    2055554
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.97万
  • 财政年份:
    2021
  • 负责人:
    Laurie Williams
  • 依托单位:
SHF: Small: Detecting the 1%: Growing the Science of Vulnerability Detection
  • 批准号:
    1909516
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2019
  • 负责人:
    Laurie Williams
  • 依托单位:
Collaborative Research: DarkSide-20k: A Global Program for the Direct Detection of Dark Matter Using Low-Radioactivity Argon
  • 批准号:
    1812480
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2018
  • 负责人:
    Laurie Williams
  • 依托单位:
国内基金
海外基金
CENPI/NRF2/ALDH3A1 信号轴介导的脂质代谢重编程诱导ER阳性乳腺癌免疫抑制的作用机制研究
  • 批准号:
    JCZRLH202600982
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
  • 依托单位:
基于“郁痰”理论探讨海藻消瘤胶囊调控ERα-PPARγ轴抑制PTC细胞代谢失衡的作用机制
基于MAMs途径调控ER-phagy探讨肾安汤治疗糖尿病肾病的作用机制
SWI/SNF介导的表观遗传重塑与ER-α36依赖的信号编程协同调控非小细胞肺癌治疗抵抗的机制研究
  • 批准号:
    2026JJ82016
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
    龚灿
  • 依托单位: