CAREER: Towards Identifying and Eliminating Exploitable Software Bugs
职业:识别和消除可利用的软件错误
基本信息
- 批准号:0953751
- 负责人:
- 金额:$ 52.15万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2010
- 资助国家:美国
- 起止时间:2010-03-01 至 2016-02-29
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Attackers only need to find a single exploitable bug in order toinstall malware, bots, and viruses on a vulnerable user's computer.Unfortunately, bugs are plentiful. For example, the Ubuntu Linuxdistribution bug management database currently lists over 58,000 openbugs. Thus, the question is not whether an attacker can find a bug,but which bugs an attacker can exploit.This research investigates novel techniques, approaches, andalgorithms for finding exploitable bugs. The ability to deteriminewhether a bug is exploitable or not will allow developers toprioritize bug reports so that the most security-critical bugs arefixed first. The techniques investigated will also help developersdistribute patches safely.
攻击者只需要找到一个可利用的漏洞,就可以在易受攻击的用户计算机上安装恶意软件、僵尸程序和病毒。 例如,Ubuntu Linux发行版错误管理数据库目前列出了超过58,000个openbug。 因此,问题不在于攻击者是否能找到漏洞,而在于攻击者能利用哪些漏洞。 确认bug是否可被利用的能力将允许开发人员优先考虑bug报告,以便首先修复最安全的bug。 所研究的技术也将帮助开发人员安全地分发补丁。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
David Brumley其他文献
The Mayhem Cyber Reasoning System
混乱网络推理系统
- DOI:
10.1109/msp.2018.1870873 - 发表时间:
2018 - 期刊:
- 影响因子:1.9
- 作者:
Thanassis Avgerinos;David Brumley;John Davis;R. Goulden;Tyler Nighswander;Alexandre Rebert;Ned Williamson - 通讯作者:
Ned Williamson
How Shall We Play a Game?: A Game-theoretical Model for Cyber-warfare Games
我们该如何玩游戏?:网络战游戏的博弈论模型
- DOI:
10.1109/csf.2017.34 - 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Tiffany Bao;Yan Shoshitaishvili;Ruoyu Wang;Christopher Krügel;Giovanni Vigna;David Brumley - 通讯作者:
David Brumley
Tachyon: Tandem Execution for Efficient Live Patch Testing
Tachyon:用于高效实时补丁测试的串联执行
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
Matthew Maurer;David Brumley - 通讯作者:
David Brumley
A Binary-Centric Approach to Vulnerability Analysis and Defense
- DOI:
- 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
David Brumley - 通讯作者:
David Brumley
1227 . 6 MHZ ) Military Signal L 2 L 1 Civilian and Military
1227.
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
Tyler Nighswander;Brent Ledvina;Jonathan Diamond;Robert Brumley;David Brumley - 通讯作者:
David Brumley
David Brumley的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('David Brumley', 18)}}的其他基金
EDU: Collaborative: PicoCTF: Teaching Cybersecurity To High School Students through Scalable Challenges
EDU:协作:PicoCTF:通过可扩展的挑战向高中生教授网络安全
- 批准号:
1419362 - 财政年份:2014
- 资助金额:
$ 52.15万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Breaking the Satisfiability Modulo Theories (SMT) Bottleneck in Symbolic Security Analysis
TWC:媒介:协作:打破符号安全分析中的可满足性模理论 (SMT) 瓶颈
- 批准号:
1228827 - 财政年份:2012
- 资助金额:
$ 52.15万 - 项目类别:
Standard Grant
TC: Medium: Exploiting Multicore and Hardware Acceleration to Perform Efficient Behavior-Based Attack Detection and Repair
TC:中:利用多核和硬件加速执行高效的基于行为的攻击检测和修复
- 批准号:
1065112 - 财政年份:2011
- 资助金额:
$ 52.15万 - 项目类别:
Standard Grant
相似海外基金
Spain: Towards identifying common patterns of microbe-induced plant resistance against insect pests
西班牙:旨在确定微生物诱导的植物对害虫的抗性的常见模式
- 批准号:
BB/W018578/1 - 财政年份:2022
- 资助金额:
$ 52.15万 - 项目类别:
Research Grant
Towards Identifying Optimal NICU Admission Criteria for Late Preterm Infants
确定晚期早产儿最佳 NICU 入院标准
- 批准号:
10678642 - 财政年份:2022
- 资助金额:
$ 52.15万 - 项目类别:
Towards Identifying Optimal NICU Admission Criteria for Late Preterm Infants
确定晚期早产儿最佳 NICU 入院标准
- 批准号:
10536584 - 财政年份:2022
- 资助金额:
$ 52.15万 - 项目类别:
Identifying pathways to support British victims of modern slavery towards safety and recovery: A scoping study
确定支持英国现代奴隶制受害者实现安全和康复的途径:一项范围界定研究
- 批准号:
AH/V012967/1 - 财政年份:2021
- 资助金额:
$ 52.15万 - 项目类别:
Research Grant
CAS: Towards sustainable sunscreens: identifying chemical structures in sunscreens linked to phototoxicity in corals
CAS:迈向可持续防晒霜:确定防晒霜中与珊瑚光毒性相关的化学结构
- 批准号:
2114790 - 财政年份:2021
- 资助金额:
$ 52.15万 - 项目类别:
Standard Grant
Identifying nutrition and lifestyle mediators of genetic susceptibility to obesity: towards a precision lifestyle medicine approach to obesity prevention.
确定肥胖遗传易感性的营养和生活方式调节因素:采用精准的生活方式医学方法来预防肥胖。
- 批准号:
444019 - 财政年份:2021
- 资助金额:
$ 52.15万 - 项目类别:
Operating Grants
Identifying potential synergy between pleurotin and bacteriophages towards tackling multi- resistant infections.
确定侧耳素和噬菌体之间在应对多重耐药感染方面的潜在协同作用。
- 批准号:
2391871 - 财政年份:2020
- 资助金额:
$ 52.15万 - 项目类别:
Studentship
Determining the role of endothelial activation on microRNA communication in atherosclerotic plaque: towards identifying of a novel therapeutic target in carotid disease
确定内皮激活对动脉粥样硬化斑块中 microRNA 通讯的作用:确定颈动脉疾病的新治疗靶点
- 批准号:
416180 - 财政年份:2019
- 资助金额:
$ 52.15万 - 项目类别:
Studentship Programs
Association of systemic inflammation with specific types of depressive symptoms: A new approach towards identifying the inflammatory subtypes of depr
全身炎症与特定类型抑郁症状的关联:识别抑郁症炎症亚型的新方法
- 批准号:
2083645 - 财政年份:2018
- 资助金额:
$ 52.15万 - 项目类别:
Studentship
Towards Modeling & Simulation-Enabled Design of Intelligent Robots A Meeting Dedicated to Identifying Opportunities, Summarizing Challenges, and Brainstorming for Impactful Di
迈向建模
- 批准号:
1830129 - 财政年份:2018
- 资助金额:
$ 52.15万 - 项目类别:
Standard Grant














{{item.name}}会员




