课题基金 / 基金详情

TC: Medium: Collaborative Research: Techniques to Retrofit Legacy Code with Security

TC: Medium: Collaborative Research: Techniques to Retrofit Legacy Code with Security
TC:媒介:协作研究:安全改造遗留代码的技术
批准号:
0905343
负责人:
Trent Jaeger
金额:
$30.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2013-08-31

项目摘要

项目成果

Trent Jaeger的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).Though perhaps unfortunate, as a practical matter software is oftenbuilt with functionality as a primary goal, and security features areonly added later, often after vulnerabilities have been identified.To reduce the cost and increase assurance in the process of securityretrofitting, the aim to develop a methodology involving automated andsemi-automated tools and techniques to add authorization policyenforcement functionality to legacy software systems.The main insight is that major portions of the tasks involved inretrofitting code can be or already have been automated, so the designprocess focuses on enabling further automation and aggregating thesetasks into a single, coherent approach.More specifically, techniques and tools are being developed to: (1)identify and label security-relevant objects and I/O channels byanalyzing and instrumenting annotated application source code; (2)insert code to mediate access to labeled entities; (3) abstract theinserted checks into policy-relevant, security-sensitive operationsthat are authorized (or denied) by the application's security policy;(4) integrate the retrofitted legacy code with the site's specificpolicy at deployment time to ensure, through advanced policy analysis,that the application enforces that site's policy correctly, and (5)verify correct enforcement of OS policy delegation by the retrofittedapplication.The techniques and tools being developed are useful not onlyfor retrofitting, but also for augmenting and verifying existing codealready outfitted with security functionality; hence improving thestate-of-the-art in creating more secure software.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Information Flow Control Infrastructure for Single-Use Service Platforms
SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
Trusted Infrastructure Workshop 2013
海外基金