SBIR Phase I: Automatic Security Audit of Third-Party Software
SBIR第一阶段:第三方软件自动安全审计
基本信息
- 批准号:1249029
- 负责人:
- 金额:$ 15万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2013
- 资助国家:美国
- 起止时间:2013-01-01 至 2013-06-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The innovation of this Small Business Innovation Research Phase I project is the automatic security audit of third-party software. To demonstrate the capabilities of the technology, this project will build a security audit Cloud service, BitTurner, to automatically discover vulnerabilities and conduct security audits of third-party software. This cloud service will be fully automated; it will apply to programs for which source code is not available such as commercial binaries; and because every vulnerability report it generates will be accompanied by a test case demonstrating the vulnerability, it will have no false positives. This combination of attributes should revolutionize the process of software auditing and make it much faster and more cost effective. This is made possible by a novel combination of state-of-the-art program analysis techniques. The BitTurner Cloud service will incorporate white-box fuzzing using two different symbolic execution engines, black-box fuzzing enhanced with taint-directed fuzzing, and static vulnerability analysis to direct white-box fuzzing. The proposed highly parallel architecture will let us achieve high throughput and low latency while minimizing cost. The team also plans to extend the technology and infrastructure for security audit of mobile apps.The broader/commercial impact of automatic security audit of third-party software addresses an enormous market that has a dire and immediate need for innovative solutions. Security breaches cost businesses billions of dollars every year, and a majority of attacks are due to vulnerabilities in software. However, many barriers stand in the way of taking the steps needed to ensure software security. Manual auditing is prohibitively expensive because of the time and specialized skills required. Techniques based on source code are inapplicable to third-party software in binary form. Existing techniques based on static analysis can report so many false positive warnings that their results overwhelm developers and analysts and waste huge resources to weed out false positives. BitTurner's disruptive Cloud-based security audit technology should change this landscape by allowing fully automatic auditing of third-party software with no false positives, based on low-cost distributed computing. Security auditing as a service is already a large market, but existing commercial offerings are often an inadequate match for customer needs. BitTurner's technology may provide more comprehensive results at a competitive price point, and so both capture existing customers and make auditing available for software where it is currently infeasible.
本次小企业创新研究一期项目的创新点是第三方软件的自动安全审计。 为了展示该技术的能力,该项目将构建安全审计云服务BitTurner,自动发现漏洞并对第三方软件进行安全审计。该云服务将完全自动化;它将适用于无法获得源代码的程序,例如商业二进制文件;而且由于它生成的每个漏洞报告都会附有一个演示该漏洞的测试用例,因此不会出现误报。这种属性的组合应该会彻底改变软件审计的过程,并使其更快、更具成本效益。这是通过最先进的程序分析技术的新颖组合实现的。 BitTurner 云服务将结合使用两种不同符号执行引擎的白盒模糊测试、通过污点定向模糊测试增强的黑盒模糊测试以及指导白盒模糊测试的静态漏洞分析。所提出的高度并行架构将使我们能够实现高吞吐量和低延迟,同时最大限度地降低成本。该团队还计划扩展移动应用程序安全审核的技术和基础设施。第三方软件自动安全审核的更广泛/商业影响满足了一个对创新解决方案迫切需要的巨大市场。安全漏洞每年给企业造成数十亿美元的损失,大多数攻击都是由于软件漏洞造成的。然而,采取必要措施确保软件安全存在许多障碍。由于需要时间和专业技能,手动审核成本高昂。基于源代码的技术不适用于二进制形式的第三方软件。基于静态分析的现有技术可以报告如此多的误报警告,其结果使开发人员和分析师不知所措,并浪费大量资源来消除误报。 BitTurner 颠覆性的基于云的安全审核技术应该会改变这一现状,它允许基于低成本分布式计算对第三方软件进行全自动审核,不会出现误报。安全审计即服务已经是一个很大的市场,但现有的商业产品往往不足以满足客户的需求。 BitTurner 的技术可以以具有竞争力的价格提供更全面的结果,因此既可以吸引现有客户,又可以对目前不可行的软件进行审计。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Jimmy Su其他文献
A CORRELATIVE STUDY OF NIRS LIPID CORE BURDEN INDEX VERSUS HISTOLOGICAL PLAQUE DISEASE ARC IN HUMAN CORONARY AUTOPSY SPECIMENS
- DOI:
10.1016/s0735-1097(18)31841-2 - 发表时间:
2018-03-10 - 期刊:
- 影响因子:
- 作者:
Stephanie Grainger;Jimmy Su;Cherry Greiner;Matthew Saybolt;William Pickering;Robert Wilensky;Sean Madden - 通讯作者:
Sean Madden
243 - <em>In Vitro</em> Formation of Three-Dimensional Biliary Trees Within Decellularized Liver Extracellular Matrix Hydrogels
- DOI:
10.1016/s0016-5085(18)33594-7 - 发表时间:
2018-05-01 - 期刊:
- 影响因子:
- 作者:
Phillip L. Lewis;Jimmy Su;Julie Venter;Fanyin Meng;Shannon Glaser;Richard M. Green;Gianfranco Alpini;Beatriz Sosa-Pineda;Ramille N. Shah - 通讯作者:
Ramille N. Shah
TCT-575 Combined near-infrared spectroscopy and intravascular ultrasound (NIRS-IVUS) coronary imaging as a means to improve prediction of events by IVUS plaque burden alone
- DOI:
10.1016/j.jacc.2016.09.713 - 发表时间:
2016-11-01 - 期刊:
- 影响因子:
- 作者:
Jimmy Su;Cherry Greiner;Stephanie Grainger;Matthew Saybolt;William Pickering;Robert Wilensky;Joel Raichlen;Veronica He;Stephen Sum;James Muller;Sean Madden - 通讯作者:
Sean Madden
TCT-349 Ability of NIRS-IVUS to Image Lipid Core Plaque through Organized Thrombus
- DOI:
10.1016/j.jacc.2015.08.967 - 发表时间:
2015-10-13 - 期刊:
- 影响因子:
- 作者:
Stephanie J. Grainger;Cherry Greiner;Jimmy Su;Matthew D. Saybolt;Robert Wilensky;Sean Madden;James E. Muller - 通讯作者:
James E. Muller
DEPLETED COLLAGEN AS A POSSIBLE MEASURE OF CAP WEAKNESS IN HUMAN CORONARY AUTOPSY SPECIMENS
- DOI:
10.1016/s0735-1097(16)30591-5 - 发表时间:
2016-04-05 - 期刊:
- 影响因子:
- 作者:
Jimmy Su;Stephanie Grainger;Cherry A. Greiner;Matthew Saybolt;William Pickering;Robert Wilensky;Joel Raichlen;Sean Madden;James Muller - 通讯作者:
James Muller
Jimmy Su的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
相似国自然基金
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark
Supercooled Phase Transition
- 批准号:24ZR1429700
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
ATLAS实验探测器Phase 2升级
- 批准号:11961141014
- 批准年份:2019
- 资助金额:3350 万元
- 项目类别:国际(地区)合作与交流项目
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
- 批准号:41802035
- 批准年份:2018
- 资助金额:12.0 万元
- 项目类别:青年科学基金项目
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究
- 批准号:61675216
- 批准年份:2016
- 资助金额:60.0 万元
- 项目类别:面上项目
基于Phase-type分布的多状态系统可靠性模型研究
- 批准号:71501183
- 批准年份:2015
- 资助金额:17.4 万元
- 项目类别:青年科学基金项目
纳米(I-Phase+α-Mg)准共晶的临界半固态形成条件及生长机制
- 批准号:51201142
- 批准年份:2012
- 资助金额:25.0 万元
- 项目类别:青年科学基金项目
连续Phase-Type分布数据拟合方法及其应用研究
- 批准号:11101428
- 批准年份:2011
- 资助金额:23.0 万元
- 项目类别:青年科学基金项目
D-Phase准晶体的电子行为各向异性的研究
- 批准号:19374069
- 批准年份:1993
- 资助金额:6.4 万元
- 项目类别:面上项目
相似海外基金
SBIR Phase I: Automatic, Digital Classification and Counting of Mosquitos to Allow More Effective Vector Control
SBIR 第一阶段:对蚊子进行自动数字分类和计数,以实现更有效的病媒控制
- 批准号:
2233676 - 财政年份:2023
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase I: Automatic debridement device
SBIR第一期:自动清创装置
- 批准号:
2126854 - 财政年份:2021
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase I: Automatic Data Series Extraction from a Text Corpus
SBIR 第一阶段:从文本语料库中自动提取数据序列
- 批准号:
2110123 - 财政年份:2021
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase I: Automatic Generation of Physics-Informed AI Models
SBIR 第一阶段:自动生成基于物理的 AI 模型
- 批准号:
2037517 - 财政年份:2021
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase II: Inexpensive Automatic Classification And Counting Of Insects To Enable Precision Agriculture
SBIR 第二阶段:廉价的昆虫自动分类和计数,以实现精准农业
- 批准号:
1951256 - 财政年份:2020
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase I: Automatic Reconstruction of As-is Building Information Model from Indoor Point Cloud Data for Planning Purposes
SBIR 第一阶段:出于规划目的从室内点云数据自动重建原样建筑信息模型
- 批准号:
1942348 - 财政年份:2020
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase I: 6crickets Automatic Schedule Recommendation
SBIR 第一阶段:6crickets 自动赛程推荐
- 批准号:
1842790 - 财政年份:2019
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase I: Inexpensive Automatic Classification And Counting Of Insects To Enable Precision Agriculture
SBIR 第一阶段:廉价的昆虫自动分类和计数以实现精准农业
- 批准号:
1843998 - 财政年份:2019
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase I: Programmer-Friendly Automatic Code Fixes
SBIR 第一阶段:程序员友好的自动代码修复
- 批准号:
1747219 - 财政年份:2018
- 资助金额:
$ 15万 - 项目类别:
Standard Grant
SBIR Phase II: Providing Automatic System Anomaly Management Software as a Service for Dynamic Complex Computing Infrastructures
SBIR 第二阶段:为动态复杂计算基础设施提供自动系统异常管理软件即服务
- 批准号:
1660219 - 财政年份:2017
- 资助金额:
$ 15万 - 项目类别:
Standard Grant