课题基金 / 基金详情

TWC: Small: Collaborative: Similary-Based Program Analyses for Eliminating Vulnerabilities

TWC: Small: Collaborative: Similary-Based Program Analyses for Eliminating Vulnerabilities
TWC:小型:协作:基于相似性的程序分析以消除漏洞
批准号:
1318419
负责人:
Tao Xie
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-08-01 至 2014-03-31

项目摘要

项目成果

Tao Xie的其他基金

相似基金

相关文献

中文摘要
翻译
关键信息基础设施的安全性取决于有效的技术来检测通常被恶意攻击利用的漏洞。由于糟糕的编码实践或人为错误,在一个代码位置发现并修补的已知漏洞通常可能存在于许多其他未修补的代码位置,无论是在相同的代码库中还是在其他代码库中。此外,补丁通常容易出错,从而导致新的漏洞。该项目开发了用于检测代码级相似性以防止此类漏洞的实用技术。它有可能帮助建立一个更可靠和安全的信息系统基础设施,这将对社会产生巨大的经济影响,因为我们越来越依赖信息技术。特别是,该项目旨在开发基于相似性的测试和分析的实用技术,以检测未修补的易受攻击代码,并在源代码和二进制级别验证对检测到的易受攻击代码的补丁。为此,它主要关注三个主要的技术方向:(1)通过调整和改进工业强度的工具来开发检测源代码级漏洞的技术;(2)通过扩展检测二进制文件中的代码克隆的初步工作来开发检测二进制级别漏洞的能力;(3)通过开发验证软件补丁并帮助生成正确、安全补丁的方法和技术来支持补丁验证和修复。该项目有助于发现源代码和二进制级别漏洞分析的新技术,并更好地理解构建高度安全和可靠的软件的基本和实际挑战。
英文摘要
The security of critical information infrastructures depends upon effective techniques to detect vulnerabilities commonly exploited by malicious attacks. Due to poor coding practices or human error, a known vulnerability discovered and patched in one code location may often exist in many other unpatched code locations, either in the same code base or other code bases. Furthermore, patches are often error-prone, resulting in new vulnerabilities. This project develops practical techniques for detecting code-level similarity to prevent such vulnerabilities. It has the potential to help build a more reliable and secure information system infrastructure, which will have tremendous economical impact on society because of our growing reliance on information technologies.In particular, the project aims to develop practical techniques for similarity-based testing and analysis to detect unpatched vulnerable code and validate patches to the detected vulnerable code at both the source code and binary levels. To this end, it focuses on three main technical directions: (1) developing techniques for detecting source-level vulnerabilities by adapting and refining an industrial-strength tool, (2) developing capabilities of detecting binary-level vulnerabilities by extending preliminary work on detecting code clones in binaries, and (3) supporting patch validation and repair by developing methodologies and techniques to validate software patches and help produce correct, secure patches. This project helps discover new techniques for source- and binary-level vulnerability analysis and gain better understandings of the fundamental and practical challenges for building highly secure and reliable software.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CSR: Small: Decoupling File System from Volatile Main Memory: A First Step towards a Single-Level Persistent Store
TWC: Medium: Collaborative: Improving Mobile-Application Security via Text Analytics
CAREER: Cooperative Developer Testing with Test Intentions
CSR: Small: A Device-Array Based Flash Storage System for Emerging Data-Intensive and Mission-Critical Mobile Applications: from Architecture Redesign to New File System
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: