TWC: Small: Collaborative: Discovering Software Vulnerabilities through Interactive Static Analysis
TWC: Small: Collaborative: Discovering Software Vulnerabilities through Interactive Static Analysis
批准号:
1318854
负责人:
Heather Lipford
金额:
$24.91万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-10-01 至 2017-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Software development is a complex and manual process, in part because typical software programs contain more than hundreds of thousands lines of computer code. If software programmers fail to perform critical checks in that code, such as making sure a user is authorized to update an account, serious security compromises ensue. Indeed, vulnerable software is one of the leading causes of cyber security problems. Checking for security problems is very expensive because it requires examining computer code for security mistakes, and such a process requires significant manual effort. This research project aims at developing an interactive help system to warn software programmers about potential security mistakes, similar to the way modern word processors warn writers of spelling and grammar errors. This is likely lead to new functions for software development tools that will significantly reduce security vulnerabilities in software. The research is based on the concept of interactive static analysis, a novel mixed-initiative paradigm for interacting with programmers to aid in the detection and prevention of security vulnerabilities. Static analysis is seamlessly integrated into the development environment in such a way that programmers are not required to learn additional programming language and analysis concepts beyond the use of the development environment. Static analysis is performed in the context of development, allowing programmers to utilize and influence such analysis during their program construction. The goals of this research are to bring programmers into the security loop, improving their ability to detect, understand, and prevent vulnerabilities; and utilize the programmer's contextual knowledge to drive customized static analysis, detecting software vulnerabilities that are difficult to detect using current static analysis techniques.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
REU Site: Smart and Secure Future Computing
-
批准号:2244424
-
项目类别:Standard Grant
-
资助金额:$35.07万
-
财政年份:2023
-
负责人:Heather Lipford
-
依托单位:
Collaborative Research: Conference: 2022 Secure and Trustworthy Cyberspace PI Meeting
-
批准号:2205941
-
项目类别:Standard Grant
-
资助金额:$3.52万
-
财政年份:2022
-
负责人:Heather Lipford
-
依托单位:
CyberCorps® Scholarship for Service (Renewal): Carolina Cyber Defender Scholarship Program
-
批准号:2043210
-
项目类别:Continuing Grant
-
资助金额:$287.41万
-
财政年份:2022
-
负责人:Heather Lipford
-
依托单位:
SaTC: CORE: Small: Collaborative: Leveraging community oversight to enhance collective efficacy for privacy and security
-
批准号:1814068
-
项目类别:Standard Grant
-
资助金额:$18.69万
-
财政年份:2018
-
负责人:Heather Lipford
-
依托单位:
Phase II IUCRC University of North Carolina Charlotte: Center for Cybersecurity Analytics and Automation CCAA
-
批准号:1822150
-
项目类别:Continuing Grant
-
资助金额:$64.22万
-
财政年份:2018
-
负责人:Heather Lipford
-
依托单位:
NSF Student Travel Grant for the 2018 Symposium On Usable Privacy and Security (SOUPS)
-
批准号:1832746
-
项目类别:Standard Grant
-
资助金额:$1.8万
-
财政年份:2018
-
负责人:Heather Lipford
-
依托单位:
NSF Student Travel Grant for the 2017 Symposium on Usable Privacy and Security (SOUPS)
-
批准号:1734106
-
项目类别:Standard Grant
-
资助金额:$1.8万
-
财政年份:2017
-
负责人:Heather Lipford
-
依托单位:
REU Site: Socially Relevant Computing in Pervasive Computing, Computer Vision, and Human-Computer Interaction
-
批准号:1461166
-
项目类别:Standard Grant
-
资助金额:$32.38万
-
财政年份:2015
-
负责人:Heather Lipford
-
依托单位:
EDU: Deploying and Evaluating Secure Programming Education in the IDE
-
批准号:1523041
-
项目类别:Standard Grant
-
资助金额:$29.98万
-
财政年份:2015
-
负责人:Heather Lipford
-
依托单位:
SaTC-EDU: EAGER: Transforming Usable Security and Privacy Education
-
批准号:1500052
-
项目类别:Standard Grant
-
资助金额:$19.44万
-
财政年份:2015
-
负责人:Heather Lipford
-
依托单位:
Collaborative Research: Supporting Secure Programming Education in the IDE
-
批准号:1044745
-
项目类别:Standard Grant
-
资助金额:$18.36万
-
财政年份:2011
-
负责人:Heather Lipford
-
依托单位:
SGER - Studying Map Interaction Behavior
-
批准号:0748983
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Heather Lipford
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: