CAREER: Foundational Theories and Enforcement Tools for Secure Software Systems

职业:安全软件系统的基础理论和实施工具

基本信息

  • 批准号:
    0742736
  • 负责人:
  • 金额:
    $ 33.11万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2008
  • 资助国家:
    美国
  • 起止时间:
    2008-02-01 至 2014-01-31
  • 项目状态:
    已结题

项目摘要

This project addresses the problem that, to be trustworthy yet practical, mechanisms for enforcing software security must (1) undergo rigorous analysis that provides formal security guarantees and (2) be developed quickly. The project addresses this problem by creating (1) formal, foundational theories of software security and (2) convenient tools for quickly generating provably sound enforcement mechanisms. The foundational theories consist of formal definitions and rules for precisely specifying and reasoning about general security principles: threats, policies, mechanisms, and the means by which mechanisms enforce policies to prevent attacks. These theories aim to enable researchers and developers to analyze real mechanisms precisely and to prove which attacks those mechanisms can and cannot prevent in practice. The enforcement tools consist of technologies for converting expressive specifications of policies to be enforced into concrete mechanisms guaranteed to enforce those policies. These tools aim to enable researchers and developers to quickly and conveniently define, concretize, and deploy new security mechanisms. The enforcement tools and foundational theories are connected in that the theories provide models in which to establish the trustworthiness of tool-generated mechanisms. Taken together, these research tasks for creating and connecting theories and tools enable rapid development and deployment of trustworthy enforcement mechanisms for secure software systems.
这个项目解决了这样一个问题,即,为了可靠而实用,执行软件安全性的机制必须(1)经过严格的分析,以提供正式的安全性保证,并且(2)快速开发。该项目通过创建(1)正式的、基础的软件安全理论和(2)方便的工具来解决这个问题,这些工具可以快速生成可靠的执行机制。基础理论由形式定义和规则组成,用于精确指定和推理一般安全原则:威胁、策略、机制以及机制执行策略以防止攻击的方法。这些理论的目的是使研究人员和开发人员能够精确地分析真实的机制,并证明这些机制在实践中能够和不能防止哪些攻击。执行工具包括将要执行的策略的表达性规范转换为保证执行这些策略的具体机制的技术。这些工具旨在使研究人员和开发人员能够快速方便地定义、具体化和部署新的安全机制。执行工具和基础理论是联系在一起的,因为理论提供了建立工具生成机制可信度的模型。总的来说,这些创建和连接理论和工具的研究任务使安全软件系统的可靠执行机制的快速开发和部署成为可能。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Jay Ligatti其他文献

A theory of aspects
方面理论
  • DOI:
    10.1145/944705.944718
  • 发表时间:
    2003
  • 期刊:
  • 影响因子:
    0
  • 作者:
    David Walker;Steve Zdancewic;Jay Ligatti
  • 通讯作者:
    Jay Ligatti
On Subtyping-Relation Completeness, with an Application to Iso-Recursive Types
关于子类型关系完整性及其在等递归类型上的应用
Edit automata: enforcement mechanisms for run-time security policies
Far Proximity Identification in Wireless Systems
无线系统中的远近识别
SQL-Identifier Injection Attacks
SQL 标识符注入攻击

Jay Ligatti的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Jay Ligatti', 18)}}的其他基金

CT-ISG: Collaborative Research: Trustworthy Enforcement of Domain-independent Run-time Policies
CT-ISG:协作研究:域独立运行时策略的可信执行
  • 批准号:
    0716343
  • 财政年份:
    2007
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Continuing Grant

相似海外基金

Research Infrastructure: CC* Data Storage: Foundational Campus Research Storage for Digital Transformation
研究基础设施:CC* 数据存储:数字化转型的基础校园研究存储
  • 批准号:
    2346636
  • 财政年份:
    2024
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Standard Grant
CAREER: Foundational Principles for Harnessing Provenance Analytics for Advanced Enterprise Security
职业:利用来源分析实现高级企业安全的基本原则
  • 批准号:
    2339483
  • 财政年份:
    2024
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Continuing Grant
CAREER: Continual Learning with Evolving Memory, Soft Supervision, and Cross-Domain Knowledge - Foundational Theory and Advanced Algorithms
职业:利用进化记忆、软监督和跨领域知识进行持续学习——基础理论和高级算法
  • 批准号:
    2338506
  • 财政年份:
    2024
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Continuing Grant
CAREER: Efficient and Scalable Large Foundational Model Training on Supercomputers for Science
职业:科学超级计算机上高效且可扩展的大型基础模型训练
  • 批准号:
    2340011
  • 财政年份:
    2024
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Standard Grant
TRTech-PGR: Unlocking Bread Wheat Genome Diversity: Foundational Genome Sequences and Resources to Advance Breeding and Biotechnological Improvement of a Global Food Security Crop
TRTech-PGR:解锁面包小麦基因组多样性:促进全球粮食安全作物育种和生物技术改进的基础基因组序列和资源
  • 批准号:
    2322957
  • 财政年份:
    2024
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Standard Grant
Sonar Foundational Model for Representation Learning and Automatic Target Recognition Systems in Underwater Maritime Environment
水下海洋环境中表示学习和自动目标识别系统的声纳基础模型
  • 批准号:
    2903803
  • 财政年份:
    2024
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Studentship
Establishing foundational tools and datasets for investigation of NSD1 gene function in neural development
建立用于研究神经发育中 NSD1 基因功能的基础工具和数据集
  • 批准号:
    10711291
  • 财政年份:
    2023
  • 资助金额:
    $ 33.11万
  • 项目类别:
Conference: NSF-NIH Joint Workshop on Foundational AI in Biology
会议:NSF-NIH 生物学基础人工智能联合研讨会
  • 批准号:
    2325301
  • 财政年份:
    2023
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Standard Grant
Remote and Autonomous Integrated Service Robot System Based on Intuitive Human Sensation and Foundational Model
基于人类直觉和基础模型的远程自主综合服务机器人系统
  • 批准号:
    23K20003
  • 财政年份:
    2023
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Grant-in-Aid for Research Activity Start-up
Collaborative Research: IIS: III: MEDIUM: Learning Protein-ish: Foundational Insight on Protein Language Models for Better Understanding, Democratized Access, and Discovery
协作研究:IIS:III:中等:学习蛋白质:对蛋白质语言模型的基础洞察,以更好地理解、民主化访问和发现
  • 批准号:
    2310113
  • 财政年份:
    2023
  • 资助金额:
    $ 33.11万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了