TWC: Option: Small: Automatic Software Model Repair for Security Policies

TWC:选项:小:安全策略的自动软件模型修复

基本信息

  • 批准号:
    1318678
  • 负责人:
  • 金额:
    $ 44.88万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2013
  • 资助国家:
    美国
  • 起止时间:
    2013-09-01 至 2017-08-31
  • 项目状态:
    已结题

项目摘要

Increasing cyber security depends on our ability to guarantee that the system will provide the expected functionality under normal circumstances as well as if the system is perturbed by some random events or security threats. Providing such guarantee is often complicated due to several factors such as changes in system requirements caused by user demands, exposure to a new threat model that was not considered (or not relevant) in the original design, or identifying bugs or vulnerabilities during a system life cycle. The purpose of the project is to develop automated techniques --that provide justifiable confidence about correctness-- to transform an existing software model into a new model that satisfies both the existing functionality and the desired security requirements. Developing algorithms that generate models that satisfy existing functionality and new security requirements poses new challenges due to the fact that existing trace-based properties do not suffice for several security properties. A characteristic of trace-based properties is that if a model satisfies a trace-based property and it is restricted by removing some undesired behaviors then the revised model still satisfies that trace-based property. Hence, adding a trace-based property can be achieved by removing behaviors that violate it. Since trace-based properties cannot express several security properties, this project will utilize a new formalism, hyperproperties, that generalizes trace-based properties and can be used for modeling security requirements. In particular, a hyperproperty consists of a set of trace-based properties and to satisfy that hyperproperty it is required that the repaired program exhibit `all? behaviors in one of these properties. To develop algorithms that justifiably provide assurance about models developed by them, this project will first focus on formalizing commonly used security requirements using hyperproperties. It will perform complexity analysis to evaluate the complexity of adding different security properties to an existing model. To mitigate cases where the complexity is high, it will develop heuristics and algorithms that (1) identify whether adding the given hyperproperty can be achieved via adding a related stronger trace-based property, and (2) identify a subset of hyperproperties where adding the given property is more efficient. This work will also result in the development of efficient algorithms and tools that utilize the complexity bottlenecks. Thus, the results of the proposed project will enhance assurance of software systems by repairing security flaws and vulnerabilities in an automated fashion.
提高网络安全性取决于我们是否有能力保证系统在正常情况下以及系统受到某些随机事件或安全威胁干扰时提供预期功能。提供这种保证通常是复杂的,因为有几个因素,如用户需求引起的系统要求的变化,暴露于原始设计中未考虑(或不相关)的新威胁模型,或在系统生命周期中识别错误或漏洞。该项目的目的是开发自动化技术--提供对正确性的合理信心--将现有的软件模型转换为既满足现有功能又满足所需安全要求的新模型。 由于现有的基于跟踪的属性不足以满足若干安全属性的事实,开发生成满足现有功能和新安全需求的模型的算法带来了新的挑战。基于迹的属性的一个特征是,如果模型满足基于迹的属性,并且通过移除一些不期望的行为来限制它,则修改后的模型仍然满足该基于迹的属性。因此,添加一个基于跟踪的属性可以通过删除违反它的行为来实现。由于基于跟踪的属性不能表示几个安全属性,这个项目将利用一个新的形式主义,hyperproperties,概括了基于跟踪的属性,并可用于建模的安全需求。特别是,一个hyperproperty由一组基于跟踪的属性,并满足hyperproperty,它需要修复的程序表现出`所有?这些属性之一的行为。为了开发算法,可验证地提供关于他们开发的模型的保证,该项目将首先专注于使用超属性来形式化常用的安全需求。它将执行复杂性分析,以评估向现有模型添加不同安全属性的复杂性。为了减轻复杂性高的情况,它将开发以下方法和算法:(1)确定是否可以通过添加相关的更强的基于跟踪的属性来实现添加给定的超属性,以及(2)确定添加给定属性更有效的超属性子集。这项工作还将导致开发利用复杂性瓶颈的有效算法和工具。 因此,拟议项目的成果将通过自动修复安全缺陷和漏洞,加强对软件系统的保证。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Sandeep Kulkarni其他文献

A multicenter prospective study of infections related morbidity and mortality in cirrhosis of liver
  • DOI:
    10.1007/s12664-014-0461-3
  • 发表时间:
    2014-06-01
  • 期刊:
  • 影响因子:
    2.100
  • 作者:
    Rajiv Baijal;Deepak Amarapurkar;H. R. Praveen Kumar;Sandeep Kulkarni;Nimish Shah;Soham Doshi;Deepak Gupta;Mayank Jain;Nikhil Patel;Praful Kamani;S. K. Issar;Mrudul Dharod;Apoorva Shah;Madhuri Chandnani;Sonali Gautam
  • 通讯作者:
    Sonali Gautam
Hazards of labour pain and the role of non-neuraxial labour analgesia
  • DOI:
    10.1016/j.tacc.2014.04.009
  • 发表时间:
    2014-08-01
  • 期刊:
  • 影响因子:
  • 作者:
    Sandeep Kulkarni;Sean Tjunan Sia
  • 通讯作者:
    Sean Tjunan Sia
Study of osteodystrophy in patients with cirrhosis of liver at tertiary care centre
  • DOI:
    10.1016/j.jceh.2013.02.220
  • 发表时间:
    2013-03-01
  • 期刊:
  • 影响因子:
  • 作者:
    Rajiv Kumar Baijal;Praveen Kumar;Deepak Gupta;Nimish Shah;Sandeep Kulkarni;Parijat Gupte;Deepak Amarapurkar
  • 通讯作者:
    Deepak Amarapurkar
Achieving starvation-freedom in multi-version transactional memory systems
  • DOI:
    10.1007/s00607-021-00994-y
  • 发表时间:
    2022-01-10
  • 期刊:
  • 影响因子:
    2.800
  • 作者:
    Ved Prakash Chaudhary;Chirag Juyal;Sandeep Kulkarni;Sweta Kumari;Sathya Peri
  • 通讯作者:
    Sathya Peri
Evaluation of sevafilachek immunoassays and rapid ICT-filariasis test for detection of bancroftian filariasis
塞瓦菲拉切克免疫分析和快速 ICT 丝虫病检测检测班克罗夫特丝虫病的评价

Sandeep Kulkarni的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Sandeep Kulkarni', 18)}}的其他基金

XPS: FULL: FP: Collaborative Research: Synchrony-aware Primitives for Building Highly Auditable, Highly Scalable, Highly Available Distributed Systems
XPS:完整:FP:协作研究:用于构建高度可审计、高度可扩展、高度可用的分布式系统的同步感知原语
  • 批准号:
    1533802
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Scalable Component-Based Model Revision of Cyber-Physical Systems with Separation of Concerns
CPS:突破:可扩展的基于组件的网络物理系统模型修订,具有关注点分离
  • 批准号:
    1329807
  • 财政年份:
    2013
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
CSR: Small: Collaborative Research: Tool Support for Producing High Assurance and Reliable Software for Wireless Sensor Actor Networks
CSR:小型:协作研究:为无线传感器参与者网络生产高保证和可靠软件的工具支持
  • 批准号:
    0914913
  • 财政年份:
    2009
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Continuing Grant
CAREER: Unified Component-Based Framework for Fault-Tolerance
职业:基于组件的统一容错框架
  • 批准号:
    0092724
  • 财政年份:
    2001
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Continuing Grant

相似国自然基金

Vessel co-option介导贝伐单抗治疗结直肠癌肝转移耐药的机制及克服策略研究
  • 批准号:
  • 批准年份:
    2022
  • 资助金额:
    52 万元
  • 项目类别:
    面上项目

相似海外基金

TWC: TTP Option: Small: Understanding the State of TLS Using Large-scale Passive Measurements
TWC:TTP 选项:小:使用大规模被动测量了解 TLS 的状态
  • 批准号:
    1528156
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Differential Introspective Side Channels --- Discovery, Analysis, and Defense
TWC:TTP 选项:小:差异内省侧通道 --- 发现、分析和防御
  • 批准号:
    1526455
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Collaborative: Enhancing Anonymity Network Resilience against Pervasive Internet Attacks
TWC:TTP 选项:小:协作:增强匿名网络抵御普遍互联网攻击的弹性
  • 批准号:
    1526306
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Collaborative: Enhancing Anonymity Network Resilience against Pervasive Internet Attacks
TWC:TTP 选项:小:协作:增强匿名网络抵御普遍互联网攻击的弹性
  • 批准号:
    1527401
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Collaborative: SRN: On Establishing Secure and Resilient Networking Services
TWC:TTP 选项:小型:协作:SRN:关于建立安全和弹性的网络服务
  • 批准号:
    1523994
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Collaborative: SRN: On Establishing Secure and Resilient Networking Services
TWC:TTP 选项:小型:协作:SRN:关于建立安全和弹性的网络服务
  • 批准号:
    1528099
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Collaborative: SRN: On Establishing Secure and Resilient Networking Services
TWC:TTP 选项:小型:协作:SRN:关于建立安全和弹性的网络服务
  • 批准号:
    1526299
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Automating Attack Strategy Recognition to Enhance Cyber Threat Prediction
TWC:TTP 选项:小:自动化攻击策略识别以增强网络威胁预测
  • 批准号:
    1526383
  • 财政年份:
    2015
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Collaborative: Detecting and Characterizing Internet Traffic Interception Based on BGP Hijacking
TWC:TTP 选项:小:协作:基于 BGP 劫持检测和表征互联网流量拦截
  • 批准号:
    1423659
  • 财政年份:
    2014
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Small: Collaborative: Integrated Smart Grid Analytics for Anomaly Detection
TWC:TTP 选项:小型:协作:用于异常检测的集成智能电网分析
  • 批准号:
    1421879
  • 财政年份:
    2014
  • 资助金额:
    $ 44.88万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了