TC: Medium: Collaborative Research: Techniques to Retrofit Legacy Code with Security
TC:媒介:协作研究:安全改造遗留代码的技术
基本信息
- 批准号:0905343
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2009
- 资助国家:美国
- 起止时间:2009-09-01 至 2013-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).Though perhaps unfortunate, as a practical matter software is oftenbuilt with functionality as a primary goal, and security features areonly added later, often after vulnerabilities have been identified.To reduce the cost and increase assurance in the process of securityretrofitting, the aim to develop a methodology involving automated andsemi-automated tools and techniques to add authorization policyenforcement functionality to legacy software systems.The main insight is that major portions of the tasks involved inretrofitting code can be or already have been automated, so the designprocess focuses on enabling further automation and aggregating thesetasks into a single, coherent approach.More specifically, techniques and tools are being developed to: (1)identify and label security-relevant objects and I/O channels byanalyzing and instrumenting annotated application source code; (2)insert code to mediate access to labeled entities; (3) abstract theinserted checks into policy-relevant, security-sensitive operationsthat are authorized (or denied) by the application's security policy;(4) integrate the retrofitted legacy code with the site's specificpolicy at deployment time to ensure, through advanced policy analysis,that the application enforces that site's policy correctly, and (5)verify correct enforcement of OS policy delegation by the retrofittedapplication.The techniques and tools being developed are useful not onlyfor retrofitting, but also for augmenting and verifying existing codealready outfitted with security functionality; hence improving thestate-of-the-art in creating more secure software.
该奖项是根据2009年的《美国恢复和再投资法》(公法111-5)资助的。尽管很不幸,因为经常将功能作为主要目标构建的实际物质软件,并且在以后会添加安全功能,并且通常在脆弱性之后添加了脆弱性,从而降低了成本和提高安全性的工具,以自动的方式促进了一种方法,该方法既可以自动地进行,又有一种方法,使您有启发性地进行了研究。将授权政策执行功能添加到遗留软件系统中。主要的见解是,涉及的任务的主要部分可以或已经是已经是自动化的,因此DesignProcess着重于实现进一步的自动化,并将这些方法汇总为单一的,连贯的方法,更具体地识别和实验性的工具和实验性,并识别:1(1)启用:(1)启用:(1)启用:(1)启用:(1)启用:(1)启用:(1)启用:(1)启用:(1)启用:(1)启用。和仪器注释的应用程序代码; (2)插入代码以调解对标记实体的访问; (3)抽象插入的检查与策略相关的,对安全敏感的操作的授权(或拒绝)由申请的安全策略授权(或拒绝);(4)将改进的遗产代码与站点的特定政策集成到部署时间,以确保通过先进的策略分析来确保该申请通过该站点的策略来确保正确的策略和(5)验证OS的策略,并(5)执行OSS的策略,并(5)依据,并(5)验证OS的策略,并确保OS的策略依据,并且(5)开发的不仅用于改造,而且还用于增强和验证带有安全功能的现有CodealReady;因此,改善了创建更安全的软件的最新情况。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Trent Jaeger其他文献
Practical Integrity Validation in the Smart Home with HomeEndorser
使用 HomeEndorser 在智能家居中进行实用的完整性验证
- DOI:
10.1145/3643833.3656116 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Kaushal Kafle;Kirti Jagtap;Mansoor Ahmed;Trent Jaeger;Adwait Nadkarni - 通讯作者:
Adwait Nadkarni
Don’t Waste My Efforts: Pruning Redundant Sanitizer Checks of Developer-Implemented Type Checks
不要浪费我的努力:修剪开发人员实现的类型检查的冗余消毒剂检查
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
Yizhuo Zhai;Zhiyun Qian;Chengyu Song;Manu Sridharan;Trent Jaeger;Paul L. Yu;S. Krishnamurthy - 通讯作者:
S. Krishnamurthy
Countering unauthorized code execution on commodity kernels: A survey of common interfaces allowing kernel code modification
- DOI:
10.1016/j.cose.2011.09.003 - 发表时间:
2011-11-01 - 期刊:
- 影响因子:
- 作者:
Trent Jaeger;Paul C. van Oorschot;Glenn Wurster - 通讯作者:
Glenn Wurster
Trent Jaeger的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Trent Jaeger', 18)}}的其他基金
SaTC: CORE: Small: Information Flow Control Infrastructure for Single-Use Service Platforms
SaTC:核心:小型:一次性服务平台的信息流控制基础设施
- 批准号:
1816282 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
SaTC:核心:中:协作:威胁感知防御:评估威胁以持续改进
- 批准号:
1801534 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
TWC:中:协作:改进纵深防御软件
- 批准号:
1408880 - 财政年份:2014
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Trusted Infrastructure Workshop 2013
2013 年可信基础设施研讨会
- 批准号:
1313027 - 财政年份:2013
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TC: Small: Towards Customer-Centric Utility Computing
TC:小型:迈向以客户为中心的效用计算
- 批准号:
1117692 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CPS:Small:Collaborative Research:Establishing Integrity in Dynamic Networks of Cyber Physical Devices
CPS:小型:协作研究:在信息物理设备动态网络中建立完整性
- 批准号:
0931914 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CT-IS: Shamon: Systems Approaches for Constructing Distributed Trust
CT-IS:Shamon:构建分布式信任的系统方法
- 批准号:
0627551 - 财政年份:2006
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
相似国自然基金
复合低维拓扑材料中等离激元增强光学响应的研究
- 批准号:12374288
- 批准年份:2023
- 资助金额:52 万元
- 项目类别:面上项目
基于管理市场和干预分工视角的消失中等企业:特征事实、内在机制和优化路径
- 批准号:72374217
- 批准年份:2023
- 资助金额:41.00 万元
- 项目类别:面上项目
托卡马克偏滤器中等离子体的多尺度算法与数值模拟研究
- 批准号:12371432
- 批准年份:2023
- 资助金额:43.5 万元
- 项目类别:面上项目
中等质量黑洞附近的暗物质分布及其IMRI系统引力波回波探测
- 批准号:12365008
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
中等垂直风切变下非对称型热带气旋快速增强的物理机制研究
- 批准号:42305004
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1630037 - 财政年份:2015
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064646 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064944 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065216 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
- 批准号:
1065130 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Standard Grant