TWC: Medium: Toward Trustworthy Mutable Replay for Security Patches
TWC: Medium: Toward Trustworthy Mutable Replay for Security Patches
批准号:
1563555
负责人:
Gail Kaiser
金额:
$120.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2021-08-31
中文摘要
社会越来越依赖软件,但部署的软件包含安全漏洞和其他可能威胁隐私、财产甚至人类生命的漏洞。当发现安全漏洞或严重错误时,会发布软件补丁程序来尝试修复问题,但补丁程序本身可能是不正确、不充分的,并且必然会破坏功能。该项目研究了完整的工作流程,以便开发人员快速诊断漏洞或错误的根本原因,测试预期的补丁是否确实完全消除了缺陷,并允许用户在采用补丁之前检查已发布的补丁的配置和工作负载。这个项目探索了可变重放的使用,以帮助复制、诊断和修复软件错误。低开销记录器在发生故障或利用漏洞时记录软件的执行,允许开发人员重播记录的日志以重现问题。可变重播允许在关键补丁程序典型的适度代码更改后重播使用错误版本记录的日志,以显示补丁程序正确工作以解决检测到的问题。该项目利用开发人员随时可用的语义信息来执行易于理解的静态和动态分析,以正确转换记录的日志,从而实现可变回放。这项研究的结果将简化和加速补丁的生成和验证,最终使软件更可靠和更安全,从而使社会和个人受益。
英文摘要
Society is increasingly reliant on software, but deployed software contains security vulnerabilities and other bugs that can threaten privacy, property and even human lives. When a security vulnerability or critical error is discovered, a software patch is issued to attempt to fix the problem, but patches themselves can be incorrect, inadequate, and break necessarily functionality. This project investigates the full workflow for the developer to rapidly diagnose the root cause of the vulnerability or error, for the developer to test that a prospective patch indeed completely removes the defect, and for users to check the issued patch on their own configurations and workloads before adopting the patch. This project explores the use of mutable replay to help reproduce, diagnose, and fix software bugs. A low-overhead recorder records the execution of software in case a failure or exploit occurs, allowing the developer to replay the recorded log to reproduce the problem. Mutable replay allows logs recorded with the buggy version to be replayed after the modest code changes typical of critical patches to show that patches work correctly to resolve detected problems. This project leverages semantic information readily available to the developer to conduct well-understood static and dynamic analyses to correctly transform the recorded log to enable mutable replay. The results of this research will benefit society and individuals by simplifying and hastening both generation and validation of patches, ultimately making software more reliable and secure.
期刊论文(21)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DIRECT : A Transformer-based Model for Decompiled Identifier Renaming
DIRECT:基于 Transformer 的反编译标识符重命名模型
DOI:
--
发表时间:
2021
期刊:
1st Workshop on Natural Language Processing for Programming (NLP4Prog
影响因子:
--
作者:
[Nitin, Vikram, Saieva, Anthony, Ray, Baishakhi, Kaiser, Gail]
通讯作者:
Kaiser, Gail
Testing DNN Image Classifier for Confusion & Bias Errors
测试 DNN 图像分类器的混淆情况
DOI:
--
发表时间:
2020
期刊:
42nd International Conference on Software Engineering
影响因子:
--
作者:
[Tian, Yuchi, Zhong, Ziyuan, Ordonez, Vicente, Kaiser, Gail, Ray, Baishakhi]
通讯作者:
Ray, Baishakhi
Side Channel Attack on Smartphone Sensors to Infer Gender of the User
对智能手机传感器进行侧信道攻击以推断用户性别
DOI:
--
发表时间:
2019
期刊:
17th ACM Conference on Embedded Networked Sensor Systems (SenSys
影响因子:
--
作者:
[Singh, Shirish, Shila, Devu Manikantan, Kaiser, Gail]
通讯作者:
Kaiser, Gail
Obfuscation resilient search through executable classification
通过可执行分类进行混淆弹性搜索
DOI:
10.1145/3211346.3211352
发表时间:
2018
期刊:
Proceedings of the 2nd ACM SIGPLAN International Workshop on Machine Learning and Programming Languages
影响因子:
--
作者:
[Su, Fang-Hsiang, Bell, Jonathan, Kaiser, Gail, Ray, Baishakhi]
通讯作者:
Ray, Baishakhi
Learning Computational Thinking Efficiently with Block-based Parsons Puzzles
通过基于块的帕森斯谜题有效学习计算思维
DOI:
--
发表时间:
2022
期刊:
30th International Conference on Computers in Education (ICCE
影响因子:
--
作者:
[Bender, Jeff, Dziena, Alex, Kaiser, Gail]
通讯作者:
Kaiser, Gail
共 19 条
SaTC: CORE: Medium: Cannot Trust Anything: A Tiny TCB Architecture for Secure Containers
-
批准号:2247370
-
项目类别:Continuing Grant
-
资助金额:$120.0万
-
财政年份:2023
-
负责人:Gail Kaiser
-
依托单位:
SHF: Small: Preponderance of the Evidence for Behavioral Code Similarities
-
批准号:1815494
-
项目类别:Standard Grant
-
资助金额:$49.66万
-
财政年份:2018
-
负责人:Gail Kaiser
-
依托单位:
SHF: MEDIUM: Achieving Software Reliability without True Test Oracles
-
批准号:1161079
-
项目类别:Continuing Grant
-
资助金额:$89.46万
-
财政年份:2012
-
负责人:Gail Kaiser
-
依托单位:
CSR---VCM: Autonomic Mechanisms for Reducing System Downtime due to Maintenance and Upgrades
-
批准号:0717544
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Gail Kaiser
-
依托单位:
Smart Event Models and Architectures
-
批准号:0203876
-
项目类别:Continuing Grant
-
资助金额:$27.0万
-
财政年份:2002
-
负责人:Gail Kaiser
-
依托单位:
Component Technologies for Next-Generation Software Development Environments
-
批准号:9970790
-
项目类别:Continuing Grant
-
资助金额:$22.5万
-
财政年份:1999
-
负责人:Gail Kaiser
-
依托单位:
CISE Research Instrumentation: Semantics-based Prefetching for Mobile Computing
-
批准号:9529304
-
项目类别:Standard Grant
-
资助金额:$4.67万
-
财政年份:1996
-
负责人:Gail Kaiser
-
依托单位:
Components for Decentralized Process-Centered Environments
-
批准号:9301092
-
项目类别:Continuing Grant
-
资助金额:$21.7万
-
财政年份:1993
-
负责人:Gail Kaiser
-
依托单位:
Multi-Agent Rule-Based Development Environments
-
批准号:9106368
-
项目类别:Continuing Grant
-
资助金额:$23.63万
-
财政年份:1991
-
负责人:Gail Kaiser
-
依托单位:
Distributed Language-based Environments
-
批准号:9000930
-
项目类别:Continuing Grant
-
资助金额:$10.0万
-
财政年份:1990
-
负责人:Gail Kaiser
-
依托单位:
CISE Research Instrumentation
-
批准号:8920080
-
项目类别:Standard Grant
-
资助金额:$4.41万
-
财政年份:1990
-
负责人:Gail Kaiser
-
依托单位:
Presidential Young Investigator Award: Computer Science (Software)
-
批准号:8858029
-
项目类别:Continuing Grant
-
资助金额:$31.2万
-
财政年份:1988
-
负责人:Gail Kaiser
-
依托单位:
Distributed Language-based Environments
-
批准号:8802741
-
项目类别:Standard Grant
-
资助金额:$14.63万
-
财政年份:1988
-
负责人:Gail Kaiser
-
依托单位:
海外基金