课题基金 / 基金详情

TWC: Small: Collaborative: Discovering Software Vulnerabilities through Interactive Static Analysis

TWC: Small: Collaborative: Discovering Software Vulnerabilities through Interactive Static Analysis
TWC:小型:协作:通过交互式静态分析发现软件漏洞
批准号:
1318323
负责人:
Emerson Murphy-Hill
金额:
$24.99万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-10-01 至 2018-09-30

项目摘要

项目成果

Emerson Murphy-Hill的其他基金

相似基金

相关文献

中文摘要
翻译
软件开发是一个复杂的手动过程,部分原因是典型的软件程序包含数十万行以上的计算机代码。如果软件程序员未能在代码中执行关键检查,例如确保用户被授权更新帐户,则会接踵而至的是严重的安全威胁。事实上,易受攻击的软件是网络安全问题的主要原因之一。检查安全问题是非常昂贵的,因为它需要检查计算机代码的安全错误,而这样的过程需要大量的人工工作。该研究项目旨在开发一种交互式帮助系统,警告软件程序员潜在的安全错误,类似于现代文字处理器警告作者拼写和语法错误的方式。这可能会导致软件开发工具的新功能,从而显著减少软件中的安全漏洞。这项研究基于交互式静态分析的概念,这是一种新的混合主动范式,用于与程序员交互,以帮助检测和预防安全漏洞。静态分析被无缝地集成到开发环境中,这样程序员就不需要学习开发环境之外的其他编程语言和分析概念。静态分析是在开发环境中执行的,允许程序员在他们的程序构造过程中利用和影响这种分析。本研究的目标是将程序员带入安全循环,提高他们检测、理解和预防漏洞的能力;并利用程序员的上下文知识来驱动定制的静态分析,检测使用当前静态分析技术难以检测的软件漏洞。
英文摘要
Software development is a complex and manual process, in part because typical software programs contain more than hundreds of thousands lines of computer code. If software programmers fail to perform critical checks in that code, such as making sure a user is authorized to update an account, serious security compromises ensue. Indeed, vulnerable software is one of the leading causes of cyber security problems. Checking for security problems is very expensive because it requires examining computer code for security mistakes, and such a process requires significant manual effort. This research project aims at developing an interactive help system to warn software programmers about potential security mistakes, similar to the way modern word processors warn writers of spelling and grammar errors. This is likely lead to new functions for software development tools that will significantly reduce security vulnerabilities in software. The research is based on the concept of interactive static analysis, a novel mixed-initiative paradigm for interacting with programmers to aid in the detection and prevention of security vulnerabilities. Static analysis is seamlessly integrated into the development environment in such a way that programmers are not required to learn additional programming language and analysis concepts beyond the use of the development environment. Static analysis is performed in the context of development, allowing programmers to utilize and influence such analysis during their program construction. The goals of this research are to bring programmers into the security loop, improving their ability to detect, understand, and prevent vulnerabilities; and utilize the programmer's contextual knowledge to drive customized static analysis, detecting software vulnerabilities that are difficult to detect using current static analysis techniques.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SHF: Small: Retrospective and Prospective Studies of the Effects of Gender Bias in Software Engineering
  • 批准号:
    1813041
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.85万
  • 财政年份:
    2018
  • 负责人:
    Emerson Murphy-Hill
  • 依托单位:
FSE 2016 Doctoral Consortium and Mentorship Sessions Program
  • 批准号:
    1642247
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.5万
  • 财政年份:
    2016
  • 负责人:
    Emerson Murphy-Hill
  • 依托单位:
CAREER: Expanding Developers' Usage of Software Tools by Enabling Social Learning
  • 批准号:
    1252995
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $49.57万
  • 财政年份:
    2013
  • 负责人:
    Emerson Murphy-Hill
  • 依托单位:
WORKSHOP: VL/HCC 2012 Doctoral Consortium
  • 批准号:
    1216138
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.71万
  • 财政年份:
    2012
  • 负责人:
    Emerson Murphy-Hill
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: