CRII: SaTC: Empirical and Analytical Models for the Deployment of Software Updates in Large Vulnerable Populations
CRII:SaTC:在大量弱势群体中部署软件更新的经验和分析模型
基本信息
- 批准号:1464163
- 负责人:
- 金额:$ 17.03万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2015
- 资助国家:美国
- 起止时间:2015-05-15 至 2018-04-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Software vulnerabilities are an important vector for malware delivery. The software updating mechanisms, responsible for deploying the vulnerability patches, are in a race with the cyber attackers seeking to exploit the vulnerabilities. Moreover, these updating mechanisms have multiple, potentially conflicting, design goals, as they must quickly deploy patches on millions of hosts worldwide, must not overburden the users, and must avoid breaking dependencies in the deployment environment. This project aims to model the dynamics of vulnerable host populations, in order to assess the practical barriers for current software updating mechanisms and the conflicts among their security and reliability goals. Using real-world data sets of update deployment events, the research studies the decay of vulnerable host populations empirically to identify deployment-specific factors that delay updates. Building on these insights, the project develops parameterized analytical models for update deployment, and uses these models to quantify the trade-offs between reliability and security when updating software. The models provide principled methods for reasoning about the properties of software updates in the presence of multiple design goals and enable improvements in software updating mechanisms by exploring a large design space. The researchers are disseminating the results from this project by organizing workshops on data-driven security, by releasing data sets with augmented information about software vulnerabilities, and by collaborating with industry partners to evaluate the proposed techniques in real-world settings.
软件漏洞是恶意软件传播的重要媒介。负责部署漏洞补丁的软件更新机制正在与试图利用这些漏洞的网络攻击者展开竞争。此外,这些更新机制有多个潜在冲突的设计目标,因为它们必须在全球数以百万计的主机上快速部署补丁,不能使用户负担过重,并且必须避免破坏部署环境中的依赖关系。该项目旨在对易受攻击的主机群体的动态进行建模,以便评估当前软件更新机制的实际障碍及其安全和可靠性目标之间的冲突。使用更新部署事件的真实世界数据集,该研究对易受攻击的主机种群的衰退进行了经验研究,以确定延迟更新的部署特定因素。在这些见解的基础上,该项目开发了用于更新部署的参数化分析模型,并使用这些模型来进一步量化更新软件时可靠性和安全性之间的权衡。这些模型提供了在存在多个设计目标的情况下推理软件更新属性的原则性方法,并通过探索大的设计空间来改进软件更新机制。研究人员正在通过组织关于数据驱动的安全的研讨会,通过发布含有关于软件漏洞的补充信息的数据集,以及通过与行业合作伙伴合作,在现实世界环境中评估拟议的技术,来传播这一全球项目的成果。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Tudor Dumitras其他文献
The Broken Shield: Measuring Revocation Effectiveness in the Windows Code-Signing PKI
破碎的盾牌:测量 Windows 代码签名 PKI 中的撤销有效性
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Doowon Kim;Bum Jun Kwon;Kristián Kozák;Christopher S. Gates;Tudor Dumitras - 通讯作者:
Tudor Dumitras
Middleware , Fault-Tolerance and the Magical 1 % A Study of Unpredictability
中间件%20、%20容错%20和%20%20神奇%201%20%%20A%20研究%20的%20不可预测性
- DOI:
- 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
Tudor Dumitras;P. Narasimhan - 通讯作者:
P. Narasimhan
Too Big to FAIL: What You Need to Know Before Attacking a Machine Learning System
太大而不能失败:攻击机器学习系统之前您需要了解什么
- DOI:
10.1007/978-3-030-03251-7_17 - 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Tudor Dumitras;Yigitcan Kaya;R. Marginean;Octavian Suciu - 通讯作者:
Octavian Suciu
Understanding the Vulnerability Lifecycle for Risk Assessment and Defense Against Sophisticated Cyber Attacks
- DOI:
10.1007/978-3-319-14039-1_13 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Tudor Dumitras - 通讯作者:
Tudor Dumitras
Peek-a-boo: Inferring program behaviors in a virtualized infrastructure without introspection
Peek-a-boo:在不自省的情况下推断虚拟化基础设施中的程序行为
- DOI:
10.1016/j.cose.2018.08.010 - 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Sanghyun Hong;Alina Nicolae;Abhinav Srivastava;Tudor Dumitras - 通讯作者:
Tudor Dumitras
Tudor Dumitras的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Tudor Dumitras', 18)}}的其他基金
I-Corps: Data-Driven Risk Assessments for Software Vulnerabilities
I-Corps:数据驱动的软件漏洞风险评估
- 批准号:
2244900 - 财政年份:2023
- 资助金额:
$ 17.03万 - 项目类别:
Standard Grant
相似海外基金
CRII: SaTC: Automated Knowledge Representation for IoT Cybersecurity Regulations
CRII:SaTC:物联网网络安全法规的自动化知识表示
- 批准号:
2348147 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Standard Grant
CRII: SaTC: Reliable Hardware Architectures Against Side-Channel Attacks for Post-Quantum Cryptographic Algorithms
CRII:SaTC:针对后量子密码算法的侧通道攻击的可靠硬件架构
- 批准号:
2348261 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Standard Grant
CRII: SaTC: Privacy vs. Accountability--Usable Deniability and Non-Repudiation for Encrypted Messaging Systems
CRII:SaTC:隐私与责任——加密消息系统的可用否认性和不可否认性
- 批准号:
2348181 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Standard Grant
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
- 批准号:
2327427 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Continuing Grant
CRII: SaTC: Evolving I/O Protocols for Confidential Computing
CRII:SaTC:用于机密计算的不断发展的 I/O 协议
- 批准号:
2348130 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Standard Grant
CRII: SaTC: Enforcing Expressive Security Policies using Trusted Execution Environments
CRII:SaTC:使用可信执行环境执行表达性安全策略
- 批准号:
2348304 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Standard Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Continuing Grant
CRII: SaTC: The Right to be Forgotten in Follow-ups of Machine Learning: When Privacy Meets Explanation and Efficiency
CRII:SaTC:机器学习后续中被遗忘的权利:当隐私遇到解释和效率时
- 批准号:
2348177 - 财政年份:2024
- 资助金额:
$ 17.03万 - 项目类别:
Standard Grant