课题基金 / 基金详情

TC: Small:Automata Based String Analysis for Detecting Vulnerabilities in Web Applications

TC: Small:Automata Based String Analysis for Detecting Vulnerabilities in Web Applications
TC:Small:基于自动机的字符串分析,用于检测 Web 应用程序中的漏洞
批准号:
0916112
负责人:
Tevfik Bultan
金额:
$35.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2013-08-31

项目摘要

项目成果

Tevfik Bultan的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Web applications contain numerous vulnerabilities that can be exploitedby attackers to gain unauthorized access to confidential information andto manipulate sensitive data. Many of these vulnerabilities are due toinadequate manipulation of string variables. String analysis, a techniquethat captures the string values that a certain variable might hold at aparticular program point, can be used to identify such flaws. In thisproject, novel and precise string analysis techniques will be developedusing an automata-based approach that represents possible values of astring variable at a program point as an automaton. Techniques thatsupport path-sensitivity and that enable precise analysis of loops usingautomata-based widening operations will be developed. Basic string analysistechniques will be extended to a composite analysis where relationships amongstring variables and other types of variables can be automatically discoveredand analyzed. The precision of string analysis plays a central role forobtaining good results with static vulnerability detection tools. Theprecise string analysis techniques developed in this project will enableanalysis of programs that cannot be analyzed with existing techniques. Theresults of these improved string analysis techniques will lead to novelsoftware security solutions and detection of novel types of vulnerabilities.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
FMitF: Track I: Scalable and Quantitative Verification for Neural Network Analysis and Design
Collaborative Research: SHF: Small: Automated Quantitative Assessment of Testing Difficulty
SHF: Medium: Collaborative Research: HUGS: Human-Guided Software Testing and Analysis for Scalable Bug Detection and Repair
SHF: Small: Differential Policy Verification and Repair for Access Control in the Cloud
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: