TC:Medium:Collaborative Research:Techniques to Retrofit Legacy Code with Security

TC:中:协作研究:安全改造遗留代码的技术

基本信息

  • 批准号:
    0904831
  • 负责人:
  • 金额:
    $ 30万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2009
  • 资助国家:
    美国
  • 起止时间:
    2009-09-01 至 2013-08-31
  • 项目状态:
    已结题

项目摘要

This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).Though perhaps unfortunate, as a practical matter software is oftenbuilt with functionality as a primary goal, and security features areonly added later, often after vulnerabilities have been identified.To reduce the cost and increase assurance in the process of securityretrofitting, the aim to develop a methodology involving automated andsemi-automated tools and techniques to add authorization policyenforcement functionality to legacy software systems.The main insight is that major portions of the tasks involved inretrofitting code can be or already have been automated, so the designprocess focuses on enabling further automation and aggregating thesetasks into a single, coherent approach.More specifically, techniques and tools are being developed to: (1)identify and label security-relevant objects and I/O channels byanalyzing and instrumenting annotated application source code; (2)insert code to mediate access to labeled entities; (3) abstract theinserted checks into policy-relevant, security-sensitive operationsthat are authorized (or denied) by the application's security policy;(4) integrate the retrofitted legacy code with the site's specificpolicy at deployment time to ensure, through advanced policy analysis,that the application enforces that site's policy correctly, and (5)verify correct enforcement of OS policy delegation by the retrofittedapplication.The techniques and tools being developed are useful not onlyfor retrofitting, but also for augmenting and verifying existing codealready outfitted with security functionality; hence improving thestate-of-the-art in creating more secure software.
该奖项是根据 2009 年《美国复苏和再投资法案》(公法 111-5)提供资金的。尽管可能不幸的是,作为一个实际问题,软件通常以功能为主要目标构建,而安全功能通常是在发现漏洞之后才添加的。为了降低安全改造过程中的成本并增加保证,目标是开发一种涉及自动化和半自动化工具和技术的方法,以 向遗留软件系统添加授权策略执行功能。主要的见解是,改造代码所涉及的主要任务可以是或已经是自动化的,因此设计过程的重点是实现进一步的自动化,并将这些任务聚合成一个单一的、连贯的方法。更具体地说,正在开发技术和工具来:(1)通过分析来识别和标记与安全相关的对象和 I/O 通道 以及检测带注释的应用程序源代码; (2)插入代码来调解对标记实体的访问; (3) 将插入的检查抽象为由应用程序的安全策略授权(或拒绝)的与策略相关的安全敏感操作;(4) 在部署时将改进的遗留代码与站点的特定策略集成,以通过高级策略分析确保应用程序正确执行该站点的策略,以及 (5) 验证改进的应用程序对操作系统策略委派的正确执行。 开发的代码不仅可用于改造,还可用于增强和验证已配备安全功能的现有代码;因此提高了创建更安全软件的最先进水平。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Somesh Jha其他文献

2018 CAV award
  • DOI:
    10.1007/s10703-021-00375-3
  • 发表时间:
    2021-06-28
  • 期刊:
  • 影响因子:
    0.800
  • 作者:
    Kim G. Larsen;Natarajan Shankar;Pierre Wolper;Somesh Jha
  • 通讯作者:
    Somesh Jha
Adaptation with Self-Evaluation to Improve Selective Prediction in LLMs
适应自我评估以提高法学硕士的选择性预测
  • DOI:
    10.48550/arxiv.2310.11689
  • 发表时间:
    2023
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jiefeng Chen;Jinsung Yoon;Sayna Ebrahimi;Sercan Ö. Arik;Tomas Pfister;Somesh Jha
  • 通讯作者:
    Somesh Jha
Bilevel Relations and Their Applications to Data Insights
双层关系及其在数据洞察中的应用
  • DOI:
    10.48550/arxiv.2311.04824
  • 发表时间:
    2023
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Xi Wu;Xiangyao Yu;Shaleen Deep;Ahmed Mahmood;Uyeong Jang;Stratis Viglas;Somesh Jha;J. Cieslewicz;Jeffrey F. Naughton
  • 通讯作者:
    Jeffrey F. Naughton
Securing the Future of GenAI: Policy and Technology
确保 GenAI 的未来:政策和技术
  • DOI:
  • 发表时间:
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Mihai Christodorescu;Google Ryan;Craven;S. Feizi;Neil Gong;Mia Hoffmann;Somesh Jha;Zhengyuan Jiang;Mehrdad Saberi Kamarposhti;John Mitchell;Jessica Newman;Emelia Probasco;Yanjun Qi;Khawaja Shams;Google Matthew;Turek
  • 通讯作者:
    Turek
rideApp RideSharing Application smsApp SMS Application mapApp Map Application SearchActivity MsgActivity action : VIEW dataScheme : geo action
rideApp 共乘应用程序 smsApp 短信应用程序 mapApp 地图应用程序 SearchActivity MsgActivity 操作:查看数据方案:地理操作
  • DOI:
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jinman Zhao;Vaibhav Rastogi;Somesh Jha;Damien Octeau
  • 通讯作者:
    Damien Octeau

Somesh Jha的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Somesh Jha', 18)}}的其他基金

SaTC: CORE: Medium: Collaborative: User-Centered Deployment of Differential Privacy
SaTC:核心:媒介:协作:以用户为中心的差异隐私部署
  • 批准号:
    1931364
  • 财政年份:
    2020
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
SaTC: CORE: Frontier: Collaborative: End-to-End Trustworthiness of Machine-Learning Systems
SaTC:核心:前沿:协作:机器学习系统的端到端可信度
  • 批准号:
    1804648
  • 财政年份:
    2018
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
FMitF: Collaborative Research: Formal Methods for Machine Learning System Design
FMITF:协作研究:机器学习系统设计的形式化方法
  • 批准号:
    1836978
  • 财政年份:
    2018
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Scaling and Prioritizing Market-Sized Application Analysis
TWC:媒介:协作:扩展和优先考虑市场规模的应用程序分析
  • 批准号:
    1563831
  • 财政年份:
    2016
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
TWC: Phase: Medium: Collaborative Proposal: Understanding and Exploiting Parallelism in Deep Packet Inspection on Concurrent Architectures
TWC:阶段:中:协作提案:理解和利用并发架构深度数据包检查中的并行性
  • 批准号:
    1228782
  • 财政年份:
    2012
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Extending Smart-Phone Application Analysis
TWC:媒介:协作:扩展智能手机应用程序分析
  • 批准号:
    1228620
  • 财政年份:
    2012
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064944
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
Collaborative Research: CT-T: Towards Behavior-Based Malware Detection
合作研究:CT-T:迈向基于行为的恶意软件检测
  • 批准号:
    0627501
  • 财政年份:
    2007
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
CT-ISG: Alternate representation of NIDS/NIPS signatures for fast matching
CT-ISG:NIDS/NIPS 签名的替代表示形式,用于快速匹配
  • 批准号:
    0716538
  • 财政年份:
    2007
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
CAREER: Combating Malicious Behavior in Commodity Software
职业:打击商品软件中的恶意行为
  • 批准号:
    0448476
  • 财政年份:
    2005
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant

相似海外基金

TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1630037
  • 财政年份:
    2015
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1064646
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064944
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065216
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
  • 批准号:
    1065130
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
  • 批准号:
    1065537
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
  • 批准号:
    1064844
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
  • 批准号:
    1064986
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
  • 批准号:
    1064900
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
  • 批准号:
    1065288
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了