CAREER: A Framework for Preventing Web-based Attacks
职业:防止基于 Web 的攻击的框架
基本信息
- 批准号:0845894
- 负责人:
- 金额:$ 40.5万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2009
- 资助国家:美国
- 起止时间:2009-09-01 至 2014-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).The World Wide Web is a critical infrastructure that serves our societyby facilitating information exchange, business andeducation. As it continues to evolve, the number of web-basedattacks that target innocent web users keeps increasing. Examples of such attacks include Cross-site Scripting, SQL Injectionand Cross-site Request Forgery. Recent attacks on end-users andonline enterprises through these virulent attacks have resulted inwidespread damage. Defending these attacks is therefore of very important concern to Internet economy and to society-at-large. This project develops a comprehensive plan for defending web applications from these attacks. The technical contributions of this project are in the development of thetechnologies that elicit the intended behavior of a web applicationand prevent attacks by enforcing these intended behaviors. We builda framework in which the intentions of a web application are represented using models, which are then enforced to ensure robust prevention of attacks. This framework uses novel techniques based on static and dynamicanalysis, symbolic evaluation, runtime checking and isolated execution as foundations. This project also developstechniques that enable a web application and a browser tocollaborate in order to prevent attacks, and apply fine-grainedrestrictions on Web content. The tools being developed in this project will have immediate impact on defending legacy web applications that are vulnerable to these attacks. The CAREER research project is closely tied with educationalefforts by integrating topics on web security in the undergraduate and graduate computer security classrooms. Finally, a collaborative effort with a Chicago inner-city elementary school is also part of this project's educational mission.
该奖项是根据2009年美国复苏和再投资法案(公法111-5)资助的。万维网是一个重要的基础设施,通过促进信息交换,商业和教育为我们的社会服务。随着它的不断发展,针对无辜网络用户的网络攻击数量不断增加。这类攻击的例子包括跨站脚本、SQL注入和跨站请求伪造。最近通过这些恶意攻击对最终用户和在线企业的攻击造成了广泛的损害。因此,防御这些攻击是互联网经济和整个社会非常重要的问题。该项目开发了一个全面的计划,以保护Web应用程序免受这些攻击。 该项目的技术贡献在于开发了能够引发Web应用程序预期行为的技术,并通过强制执行这些预期行为来防止攻击。我们构建了一个框架,其中Web应用程序的意图使用模型表示,然后强制执行,以确保强大的攻击预防。该框架使用了基于静态和动态分析、符号计算、运行时检查和隔离执行的新技术作为基础。该项目还开发了使Web应用程序和浏览器能够协作以防止攻击的技术,并对Web内容应用细粒度限制。 该项目中开发的工具将对保护易受这些攻击的传统Web应用程序产生直接影响。 职业研究项目与教育工作密切相关,将网络安全主题整合到本科生和研究生计算机安全教室中。最后,与芝加哥市中心小学的合作也是该项目教育使命的一部分。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Venkat Venkatakrishnan其他文献
Venkat Venkatakrishnan的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Venkat Venkatakrishnan', 18)}}的其他基金
SaTC: CORE: Medium: Collaborative: RADAR: Real-time Advanced Detection and Attack Reconstruction
SaTC:核心:中等:协作:雷达:实时高级检测和攻击重建
- 批准号:
1918542 - 财政年份:2019
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1514472 - 财政年份:2015
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
I-Corps: Automated Web Application Analysis
I-Corps:自动化 Web 应用程序分析
- 批准号:
1248717 - 财政年份:2012
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
SFS Scholarships in Cybersecurity and Information Assurance
SFS 网络安全和信息保障奖学金
- 批准号:
1241685 - 财政年份:2012
- 资助金额:
$ 40.5万 - 项目类别:
Continuing Grant
IGERT: Electronic Security and Privacy: Technological, Human, Enterprise and Legal Considerations
IGERT:电子安全和隐私:技术、人力、企业和法律考虑因素
- 批准号:
1069311 - 财政年份:2011
- 资助金额:
$ 40.5万 - 项目类别:
Continuing Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065537 - 财政年份:2011
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
A Series of Workshops on Security in Emerging Areas
新兴地区安全系列研讨会
- 批准号:
1139947 - 财政年份:2011
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
TC: A U.S.-France Collaborative Symposium of Young Engineering Scientists (YESS 2009)
TC:美国-法国青年工程科学家合作研讨会(YESS 2009)
- 批准号:
0946768 - 财政年份:2009
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
TC: Small: Keeping Jack in the Box: Confining the Role of Untrusted Inputs in Web Scenarios
TC:小:将 Jack 留在盒子里:限制不可信输入在 Web 场景中的作用
- 批准号:
0917229 - 财政年份:2009
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
CT-ER : Runtime Techniques for protecting confidential data in large scale software
CT-ER:保护大型软件中机密数据的运行时技术
- 批准号:
0716584 - 财政年份:2007
- 资助金额:
$ 40.5万 - 项目类别:
Continuing Grant
相似海外基金
Integrating Self-Regulated Learning Into STEM Courses: Maximizing Learning Outcomes With The Success Through Self-Regulated Learning Framework
将自我调节学习融入 STEM 课程:通过自我调节学习框架取得成功,最大化学习成果
- 批准号:
2337176 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
CAREER: Many-Body Green's Function Framework for Materials Spectroscopy
职业:材料光谱的多体格林函数框架
- 批准号:
2337991 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
CAREER: Resilient and Efficient Automatic Control in Energy Infrastructure: An Expert-Guided Policy Optimization Framework
职业:能源基础设施中的弹性和高效自动控制:专家指导的政策优化框架
- 批准号:
2338559 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
Planning Grant: Developing capacity to attract diverse students to the geosciences: A public relations framework
规划补助金:培养吸引多元化学生学习地球科学的能力:公共关系框架
- 批准号:
2326816 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
RII Track-4:NSF: An Integrated Urban Meteorological and Building Stock Modeling Framework to Enhance City-level Building Energy Use Predictions
RII Track-4:NSF:综合城市气象和建筑群建模框架,以增强城市级建筑能源使用预测
- 批准号:
2327435 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
EAGER/Collaborative Research: An LLM-Powered Framework for G-Code Comprehension and Retrieval
EAGER/协作研究:LLM 支持的 G 代码理解和检索框架
- 批准号:
2347624 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
CRII: OAC: A Compressor-Assisted Collective Communication Framework for GPU-Based Large-Scale Deep Learning
CRII:OAC:基于 GPU 的大规模深度学习的压缩器辅助集体通信框架
- 批准号:
2348465 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
Collaborative Research: An Integrated Framework for Learning-Enabled and Communication-Aware Hierarchical Distributed Optimization
协作研究:支持学习和通信感知的分层分布式优化的集成框架
- 批准号:
2331710 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
Collaborative Research: An Integrated Framework for Learning-Enabled and Communication-Aware Hierarchical Distributed Optimization
协作研究:支持学习和通信感知的分层分布式优化的集成框架
- 批准号:
2331711 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant
CAREER: A Universal Framework for Safety-Aware Data-Driven Control and Estimation
职业:安全意识数据驱动控制和估计的通用框架
- 批准号:
2340089 - 财政年份:2024
- 资助金额:
$ 40.5万 - 项目类别:
Standard Grant














{{item.name}}会员




