EDU: Competing to Build Secure Systems

EDU:竞争构建安全系统

基本信息

  • 批准号:
    1319147
  • 负责人:
  • 金额:
    $ 30万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2013
  • 资助国家:
    美国
  • 起止时间:
    2013-09-15 至 2016-08-31
  • 项目状态:
    已结题

项目摘要

Even as security has long been a tenet of good programming practice, developers continue to produce insecure software resulting in a litany of data breaches and other compromises. This project aims to improve education on secure software development and add evidence to understanding methods, tools, techniques, and other factors that best contribute to writing secure code. The project centers on a novel multiphase programming competition that combines ideas from two traditionally disparate kinds of contests: those for building code and those for finding bugs in others' code. In phase one, contestants are tasked with building secure code. In phase two, contestants perform vulnerability analyses to attempt to break the code submitted by the other contestants in the first phase. The original builders finally aim to fix exploits discovered in phase two to recover lost points. Educators, practitioners, and policymakers broadly view secure code as important, and yet there is little consensus as to how best to teach and encourage secure-programming practices. By developing a competition, this project creates a setting that is more engaging to students, improving learning outcomes, and moreover enables greater insight into both practice and pedagogy through the analysis of data on how the participants approach secure programming, what techniques they use, and what methodologies succeed or fail for different programming tasks. The educational impact is significant, as the competition scales to hundreds of participants over two years, improving the design of the contest based on each offering. The artifacts and data produced by this project are made freely available to assist secure-programming endeavors across educational institutions. Finally, the students involved in the design, implementation, and execution of the contest are trained in advanced research and pedagogical methods.
尽管安全性长期以来一直是良好编程实践的原则,但开发人员继续生产不安全的软件,导致一连串的数据泄露和其他妥协。该项目旨在改善安全软件开发的教育,并为理解最有助于编写安全代码的方法,工具,技术和其他因素提供证据。该项目以一种新颖的多阶段编程竞赛为中心,它结合了两种传统上完全不同的竞赛的想法:构建代码的竞赛和在他人代码中发现错误的竞赛。在第一阶段,参赛者的任务是构建安全代码。在第二阶段,参赛者执行漏洞分析,试图破解其他参赛者在第一阶段提交的代码。最初的构建者最终的目标是修复在第二阶段发现的漏洞,以恢复丢失的积分。教育工作者、实践者和政策制定者普遍认为安全代码非常重要,但对于如何最好地教授和鼓励安全编程实践,几乎没有达成共识。通过开发竞赛,该项目创建了一个更吸引学生的环境,提高学习成果,并通过分析参与者如何处理安全编程,他们使用什么技术以及不同编程任务的成功或失败方法的数据,更深入地了解实践和教学法。教育影响是显着的,因为比赛规模超过两年数百名参与者,改进了基于每个产品的比赛设计。该项目产生的工件和数据可以免费提供,以帮助教育机构的安全编程工作。最后,参与竞赛设计、实施和执行的学生将接受先进的研究和教学方法的培训。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Michael Hicks其他文献

A Revised Basis for Iceberg Areal Density Values for Risk Analysis
用于风险分析的冰山面密度值的修订基础
Serializing C intermediate representations for efficient and portable parsing
序列化 C 中间表示以实现高效且可移植的解析
  • DOI:
    10.1002/spe.954
  • 发表时间:
    2010
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jeffrey A. Meister;Jeffrey S. Foster;Michael Hicks
  • 通讯作者:
    Michael Hicks
The roughness of the dark side of Iapetus from the 2004 to 2005 flyby
  • DOI:
    10.1016/j.icarus.2009.11.008
  • 发表时间:
    2010-04-01
  • 期刊:
  • 影响因子:
  • 作者:
    Janice S. Lee;Bonnie J. Buratti;Michael Hicks;Joel Mosher
  • 通讯作者:
    Joel Mosher
Nodal positivity in breast cancer correlated with the number of lesions detected by magnetic resonance imaging versus mammogram.
乳腺癌的淋巴结阳性与磁共振成像与乳房X光检查检测到的病变数量相关。
  • DOI:
    10.1016/j.amjsurg.2010.11.006
  • 发表时间:
    2011
  • 期刊:
  • 影响因子:
    3
  • 作者:
    S. Saha;S. Sirop;A. Korant;M. Kanaan;Rohil Shekher;D. Strahle;Michael Hicks;R. Hicks;L. Lawrence;D. Wiese
  • 通讯作者:
    D. Wiese
Assessing the sequence specificity in the binding of Co(III) to DNA via a thermodynamic approach
通过热力学方法评估 Co(III) 与 DNA 结合的序列特异性
  • DOI:
  • 发表时间:
    1997
  • 期刊:
  • 影响因子:
    2.9
  • 作者:
    Michael Hicks;George Wharton;D. Huchital;W. R. Murphy;R. Sheardy
  • 通讯作者:
    R. Sheardy

Michael Hicks的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Michael Hicks', 18)}}的其他基金

Mapping the Medieval Countryside: The Fifteenth-Century Inquisitions Post Mortem
绘制中世纪乡村地图:十五世纪的死后宗教裁判所
  • 批准号:
    AH/I027223/1
  • 财政年份:
    2011
  • 资助金额:
    $ 30万
  • 项目类别:
    Research Grant
TC:Medium:Collaborative Research:Techniques to Retrofit Legacy Code with Security
TC:中:协作研究:安全改造遗留代码的技术
  • 批准号:
    0905419
  • 财政年份:
    2009
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
SHF: Large: Collaborative Research: PASS: Perpetually Available Software Systems
SHF:大型:协作研究:PASS:永久可用的软件系统
  • 批准号:
    0910530
  • 财政年份:
    2009
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
SoD-HCER: Evaluation of Complex Designs--A Comparative Study
SoD-HCER:复杂设计的评估——比较研究
  • 批准号:
    0613601
  • 财政年份:
    2006
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
Scalable, Precise, and Effective Analyses for Detecting Race Conditions
用于检测竞争条件的可扩展、精确且有效的分析
  • 批准号:
    0541036
  • 财政年份:
    2006
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
PARALLEL STOCHASTIC ANALYSIS FOR GEO-ENGINEERING
地球工程并行随机分析
  • 批准号:
    EP/D037247/1
  • 财政年份:
    2006
  • 资助金额:
    $ 30万
  • 项目类别:
    Research Grant
Collaborative Research: CT-T: Flexible, Decentralized Information-flow Control for Dynamic Environments
合作研究:CT-T:动态环境下灵活、分散的信息流控制
  • 批准号:
    0524036
  • 财政年份:
    2005
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
CAREER: Programming Languages for Reliable and Secure Low-level Systems
职业:可靠且安全的低级系统的编程语言
  • 批准号:
    0346989
  • 财政年份:
    2004
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant

相似海外基金

Deciphering the Competing Mechanisms of Li Microstructure Formation in Solid Electrolytes with Nuclear Magnetic Resonance Spectroscopy (NMR) and Imaging (MRI)
利用核磁共振波谱 (NMR) 和成像 (MRI) 解读固体电解质中锂微结构形成的竞争机制
  • 批准号:
    2319151
  • 财政年份:
    2024
  • 资助金额:
    $ 30万
  • 项目类别:
    Continuing Grant
SERVICES TO EXTEND METHODS FOR RISK PREDICTION WITH A CONTINUOUS TIME MODEL FOR SURVIVAL UNDER COMPETING RISKS
通过连续时间模型扩展风险预测方法的服务,以实现竞争风险下的生存
  • 批准号:
    10974264
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
Contact Networks, Immunity, and Evolution in Competing Cancer Epidemics
癌症流行中的接触网络、免疫和进化
  • 批准号:
    DP230100162
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
    Discovery Projects
Private Disclosures in Competing Mechanisms: Theory and Applications
竞争机制中的私人披露:理论与应用
  • 批准号:
    2315652
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
Competing charge, spin, and molecular lattice interactions lead to quantum glass phases in strongly correlated pi-electron systems
竞争性电荷、自旋和分子晶格相互作用导致强相关π电子系统中的量子玻璃相
  • 批准号:
    23H01114
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
Testing competing models of the computational role of dopamine in hallucinations
测试多巴胺在幻觉中的计算作用的竞争模型
  • 批准号:
    10752192
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
Optimizing treatment decision by accounting for longitudinal biomarker trajectories and competing risks of each individual
通过考虑每个个体的纵向生物标志物轨迹和竞争风险来优化治疗决策
  • 批准号:
    10658050
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
Dynamic Modeling and Risk Prediction with Complex Observational Semi-Competing Risks Data
利用复杂的观察性半竞争风险数据进行动态建模和风险预测
  • 批准号:
    2406910
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
    Standard Grant
Competing effects of AgRP and POMC neurons on cAMP signaling in downstream neurons in vivo
AgRP 和 POMC 神经元对体内下游神经元 cAMP 信号传导的竞争作用
  • 批准号:
    10572109
  • 财政年份:
    2023
  • 资助金额:
    $ 30万
  • 项目类别:
Competing Commitments: Self-sufficiency and Mutual Obligation among Disabled Communities in Western Uganda
相互竞争的承诺:乌干达西部残疾人社区的自给自足和相互义务
  • 批准号:
    ES/X006468/1
  • 财政年份:
    2022
  • 资助金额:
    $ 30万
  • 项目类别:
    Fellowship
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了