CPS: Breakthrough: Cyber-Physical System Securitization by Responsibility Analysis

CPS:突破:通过责任分析实现信息物理系统安全化

基本信息

  • 批准号:
    1446511
  • 负责人:
  • 金额:
    $ 50万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2015
  • 资助国家:
    美国
  • 起止时间:
    2015-01-01 至 2019-12-31
  • 项目状态:
    已结题

项目摘要

Programs describe successions of actions to be performed by computers. Unfortunately programmers make errors which are exploited by attackers to divert program actions from their goals. Accordingly, program actions must be checked to be always safe and secure. Program security starts with the definition of which actions might be insecure and when they are bad. Insecure actions cannot be always forbidden as for safety. This project formalizes the concept of responsibility analysis. Responsibility analysis aims at determining automatically which program entities cause bad insecure actions to happen. This is possible by examining the program text only, because this text precisely describes all possible actions that can happen when later running a program. Based on an operational semantics of programs, the project formally defines semantic responsibility as the most precise way of locating the possible origin of bad actions. A sound static responsibility analysis will be designed by abstract interpretation of this operational semantics, on top of traditional safety analyses of C programs. A prototype static responsibility analyzer will be built to check for the security of cyber-physical systems (given bad actions and a security policy). The result of the analysis will be used to check that all entities responsible for bad actions are duly authorized (or the security policy is wrong). This tool will help programmers to soundly cure potential vulnerabilities at program design time as opposed to present-day post-mortem remedies after those attacks on programs that get detected. This would be a breakthrough at the confluence of cyber security, privacy, and cyber-physical systems.
程序描述计算机执行的一系列动作。不幸的是,程序员会犯错误,攻击者会利用这些错误来转移程序操作。因此,必须检查程序操作以确保始终安全可靠。 程序安全性从定义哪些操作可能是不安全的以及它们何时是坏的开始。不安全的行为不能总是为了安全而被禁止。 该项目正式确定了责任分析的概念。 责任分析旨在自动确定哪些程序实体导致了不良的不安全行为的发生。 这可以通过仅检查程序文本来实现,因为该文本精确地描述了在以后运行程序时可能发生的所有可能的操作。基于程序的操作语义,该项目正式定义了语义责任,作为定位不良行为可能起源的最精确方法。 一个健全的静态责任分析将设计抽象解释这种操作语义,在传统的C程序的安全分析。 将建立一个原型静态责任分析器,以检查网络物理系统的安全性(给定不良行为和安全策略)。 分析结果将用于检查所有应对不良行为负责的实体是否得到了适当授权(或安全策略是否错误)。 这个工具将帮助程序员在程序设计时就彻底修复潜在的漏洞,而不是在检测到对程序的攻击后进行事后补救。 这将是网络安全、隐私和网络物理系统融合的一个突破。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Patrick Cousot其他文献

Abstract Interpretation: From 0, 1, To ∞
抽象解读:从0、1、到无穷大
  • DOI:
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Patrick Cousot
  • 通讯作者:
    Patrick Cousot
Sometime = always + recursion ≡ always on the equivalence of the intermittent and invariant assertions methods for proving inevitability properties of programs
  • DOI:
    10.1007/bf00290704
  • 发表时间:
    1987-02-01
  • 期刊:
  • 影响因子:
    0.500
  • 作者:
    Patrick Cousot;Radhia Cousot
  • 通讯作者:
    Radhia Cousot

Patrick Cousot的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Patrick Cousot', 18)}}的其他基金

SHF: Small: Semantics, Static Analysis, and Refencing of Concurrent Programs with Weak Memory Models
SHF:小型:具有弱内存模型的并发程序的语义、静态分析和引用
  • 批准号:
    1617717
  • 财政年份:
    2016
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CSR - EHCS(EHS), TM: Abstract Interpretation-Based Analysis and Verification for Critical Systems
CSR - EHCS(EHS), TM:关键系统基于抽象解释的分析和验证
  • 批准号:
    0834535
  • 财政年份:
    2008
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant

相似海外基金

CPS: Breakthrough: Analysis, Identification and Mitigation of Delay Performance Bottlenecks of Network Infrastructure in Cyber-Physical Systems
CPS:突破:网络物理系统中网络基础设施延迟性能瓶颈的分析、识别和缓解
  • 批准号:
    2146968
  • 财政年份:
    2021
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Analysis, Identification and Mitigation of Delay Performance Bottlenecks of Network Infrastructure in Cyber-Physical Systems
CPS:突破:网络物理系统中网络基础设施延迟性能瓶颈的分析、识别和缓解
  • 批准号:
    1646458
  • 财政年份:
    2018
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Collaborative Research: A Framework for Extensibility-Driven Design of Cyber-Physical Systems
CPS:突破:协作研究:网络物理系统可扩展性驱动设计的框架
  • 批准号:
    1834324
  • 财政年份:
    2018
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Control Improvisation for Cyber-Physical Systems
CPS:突破:网络物理系统的即兴控制
  • 批准号:
    1646208
  • 财政年份:
    2017
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Collaborative Research: A Framework for Extensibility-Driven Design of Cyber-Physical Systems
CPS:突破:协作研究:网络物理系统可扩展性驱动设计的框架
  • 批准号:
    1646497
  • 财政年份:
    2016
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Understanding Sub-Second Instabilities in a Global Cyber-Physical System
CPS:突破:了解全球网络物理系统中的亚秒级不稳定性
  • 批准号:
    1522693
  • 财政年份:
    2016
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Collaborative Research: A Framework for Extensibility-Driven Design of Cyber-Physical Systems
CPS:突破:协作研究:网络物理系统可扩展性驱动设计的框架
  • 批准号:
    1646381
  • 财政年份:
    2016
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Toward Revolutionary Algorithms for Cyber-Physical Systems Architecture Optimization
CPS:突破:迈向信息物理系统架构优化的革命性算法
  • 批准号:
    1446622
  • 财政年份:
    2015
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: Knowledge-Aware Cyber-Physical Systems
CPS:突破:知识感知网络物理系统
  • 批准号:
    1446712
  • 财政年份:
    2015
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CPS: Breakthrough: A Meta-Game Theoretic Approach to Cyber-Physical Co-Design of Secure and Resilient Control Systems
CPS:突破:安全和弹性控制系统的网络物理协同设计的元博弈论方法
  • 批准号:
    1544782
  • 财政年份:
    2015
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了