课题基金 / 基金详情

SDCI Sec New: In-Depth Vulnerability Assessment of Middleware

SDCI Sec New: In-Depth Vulnerability Assessment of Middleware
SDCI Sec 新内容:中间件的深入漏洞评估
批准号:
1032341
负责人:
Barton Miller
金额:
$77.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-01-01 至 2015-12-31

项目摘要

项目成果

Barton Miller的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
This research establishes MIST, the MIddleware Security and Testing facility,to identify security vulnerabilities in middleware, which include e-commercesystems, supercomputers, and scientific and commercial networks. Theresearchers are identifying limitations in current abilities to identify andremediate vulnerabilities in the middleware. The limitations include assessmenttechniques that provide insufficient focus on critical vulnerabilities and aresubject to high false-positives, tools that provide limited abilities to find serious vulnerabilities, little or no formal characterization ofvulnerabilities, lack of trained security analysts to perform vulnerabilityassessment, scarcity of curricula, both in academia and professional training,for training security analysts, scarcity of training in software engineeringand design techniques for secure systems, and lack of independent vulnerabilityassessment activities in middleware software development.The researchers are developing first principles based vulnerability assessment(FPVA) that starts with architectural and resource analysis of the software,identifying high-value assets, and then derives threats based on how theassets are used. This research includes new and extended algorithms andtechniques for tools to help improve the automation of this task, and newsoftware engineering and coding techniques for developing secure systems.Results from their FPVA assessment activities are used to develop formalcharacterizations of these hard-to-discover vulnerabilities and, from thesecharacterizations, develop algorithms for detecting these vulnerabilities.From algorithms, they are developing new automated tools for detection. Thetools take the form of plug-ins to existing tools (to reduce unnecessaryeffort and time-to-deployment). This project expands the skills software developers by developing trainingmaterials in the form of tutorials, short courses, and a new undergraduatecourse in vulnerability assessment and secure coding practices.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: TTP: Medium: Collaborative: Deployment-quality and Accessible Solutions for Cryptography Code Development
  • 批准号:
    1929739
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2019
  • 负责人:
    Barton Miller
  • 依托单位:
SI2-SSI: Collaborative Research: A Sustainable Infrastructure for Performance, Security, and Correctness Tools
  • 批准号:
    1449918
  • 项目类别:
    Standard Grant
  • 资助金额:
    $150.0万
  • 财政年份:
    2015
  • 负责人:
    Barton Miller
  • 依托单位:
Vulnerability Assessment of Grid Software Infrastructure
  • 批准号:
    0844219
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2008
  • 负责人:
    Barton Miller
  • 依托单位:
Joint U.S.-Venezuelan Workshop on High Performance Computing; January 3-7, 2000, Puerto La Cruz, Anzoategui, Venezuela
  • 批准号:
    9979307
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.72万
  • 财政年份:
    2000
  • 负责人:
    Barton Miller
  • 依托单位:
国内基金
海外基金
工业大麻内生菌SEC-024A高效抑菌VOCs的合成调控、诱变选育及其增效分子机制研究
蟾毒灵通过SEC13/HMGB1/TLR4/NF-κB轴调控转移生态位抑制乳腺癌骨转移的机制研究
SEC61A2调控EMT影响肺腺癌细胞侵袭和转移的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    徐磊
  • 依托单位:
膀胱癌细胞中TEAD4激活SEC61G通过糖酵解促进M2巨噬细胞极化的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李朋
  • 依托单位: