TWC: Medium: Collaborative: Scaling and Prioritizing Market-Sized Application Analysis
TWC:媒介:协作:扩展和优先考虑市场规模的应用程序分析
基本信息
- 批准号:1564105
- 负责人:
- 金额:$ 54.72万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2016
- 资助国家:美国
- 起止时间:2016-07-01 至 2021-06-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The emergence of smartphones and more generally mobile platforms as a vehicle for communication, entertainment, and commerce has led to a revolution of innovation. Markets now provide a dizzying array of applications that inform and aid every conceivable human need or desire. At the same time, application markets allow previously unknown multitudes of application developers access to user devices through fast- tracked software publishing with well-documented consequent security concerns. The science and tools for performing security analysis of applications have vastly improved over the last decade. However, market providers have limited capability to apply those analyses at scale to the massive software markets. This project is a crosscutting research, educational, and outreach plan improving the scalability and accuracy of smartphone application analysis. The research effort focuses on the creation of new techniques and algorithms to enable analysis of large bodies of applications by reducing analysis cost and prioritizing identified security vulnerabilities by their expected impact. Explored within the context of Android Intent analysis resolution, the team is developing efficient algorithms and study the computational complexity of matching application communication sources and sinks thereby supporting phone-wide information flow analysis, developing empirical models for estimating the likelihoods of inter-component communication, and exploring features and metrics indicating their potential security impacts communication pathways. The approaches are being applied to a commercial markets (Apple iOS) and domains (web, desktop, and server environments) and massive application data sets.
智能手机和更普遍的移动平台作为通信、娱乐和商业工具的出现引发了一场创新革命。现在市场提供了一系列令人眼花缭乱的应用程序,这些应用程序可以满足和帮助每一种可以想象的人类需求或愿望。与此同时,应用程序市场允许以前未知的大量应用程序开发人员通过快速跟踪的软件发布访问用户设备,并记录了随之而来的安全问题。在过去十年中,用于执行应用程序安全分析的科学和工具有了很大的进步。然而,市场提供商将这些分析大规模应用于大规模软件市场的能力有限。该项目是一个跨领域的研究、教育和推广计划,旨在提高智能手机应用程序分析的可扩展性和准确性。研究工作的重点是创建新技术和算法,通过降低分析成本并根据预期影响对已识别的安全漏洞进行优先级排序,从而能够对大型应用程序进行分析。 在 Android Intent 分析解决方案的背景下进行探索,该团队正在开发高效的算法并研究匹配应用程序通信源和接收器的计算复杂性,从而支持手机范围的信息流分析,开发用于估计组件间通信可能性的经验模型,并探索表明其潜在安全影响通信路径的特征和指标。 这些方法正在应用于商业市场(Apple iOS)和领域(Web、桌面和服务器环境)以及海量应用程序数据集。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Patrick McDaniel其他文献
Guest Editors#39; Introduction: Special Issue on Trust, Security, and Privacy in Parallel and Distributed Systemsbr /
客座编辑
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Xu Li;Patrick McDaniel;Patrick McDaniel;Radha Poovendran;Radha Poovendran;Guojun Wang;Guojun Wang;Yang Xiang;Yang Xiang - 通讯作者:
Yang Xiang
A Public and Reproducible Assessment of the Topics API on Real Data
对真实数据上的主题 API 进行公开且可重复的评估
- DOI:
10.1109/spw63631.2024.00005 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Yohan Beugin;Patrick McDaniel - 通讯作者:
Patrick McDaniel
Guest Editors&#39; Introduction: Special Issue on Trust, Security, and Privacy in Parallel and Distributed Systems<br />
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:
- 作者:
Xu Li;Patrick McDaniel;Patrick McDaniel;Radha Poovendran;Radha Poovendran;Guojun Wang;Guojun Wang;Yang Xiang;Yang Xiang; - 通讯作者:
Characterizing the Modification Space of Signature IDS Rules
表征签名 IDS 规则的修改空间
- DOI:
10.1109/milcom58377.2023.10356225 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Ryan Guide;Eric Pauley;Yohan Beugin;Ryan Sheatsley;Patrick McDaniel - 通讯作者:
Patrick McDaniel
Patrick McDaniel的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Patrick McDaniel', 18)}}的其他基金
Collaborative Research: Conference: SaTC: CORE: 2.0 Vision Proposal
协作研究:会议:SaTC:核心:2.0 愿景提案
- 批准号:
2316832 - 财政年份:2023
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for 2023 IEEE Conference on Secure and Trustworthy Machine Learning (IEEE SaTML)
旅行:2023 年 IEEE 安全可信机器学习会议 (IEEE SaTML) 的 NSF 学生旅行补助金
- 批准号:
2317300 - 财政年份:2023
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
Travel: NSF Student Travel Grant for 2023 IEEE Conference on Secure and Trustworthy Machine Learning (IEEE SaTML)
旅行:2023 年 IEEE 安全可信机器学习会议 (IEEE SaTML) 的 NSF 学生旅行补助金
- 批准号:
2233869 - 财政年份:2023
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
CNS Core: Medium: Automated IoT Safety and Security Analysis and Synthesis
CNS 核心:中:自动化物联网安全分析与综合
- 批准号:
2320882 - 财政年份:2022
- 资助金额:
$ 54.72万 - 项目类别:
Continuing Grant
SaTC: CORE: Frontier: Collaborative: End-to-End Trustworthiness of Machine-Learning Systems
SaTC:核心:前沿:协作:机器学习系统的端到端可信度
- 批准号:
2343611 - 财政年份:2022
- 资助金额:
$ 54.72万 - 项目类别:
Continuing Grant
CNS Core: Medium: Automated IoT Safety and Security Analysis and Synthesis
CNS 核心:中:自动化物联网安全分析与综合
- 批准号:
1900873 - 财政年份:2019
- 资助金额:
$ 54.72万 - 项目类别:
Continuing Grant
SaTC: CORE: Frontier: Collaborative: End-to-End Trustworthiness of Machine-Learning Systems
SaTC:核心:前沿:协作:机器学习系统的端到端可信度
- 批准号:
1805310 - 财政年份:2018
- 资助金额:
$ 54.72万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Extending Smart-Phone Application Analysis
TWC:媒介:协作:扩展智能手机应用程序分析
- 批准号:
1228700 - 财政年份:2012
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064900 - 财政年份:2011
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
相似海外基金
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1840790 - 财政年份:2018
- 资助金额:
$ 54.72万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
- 批准号:
1937622 - 财政年份:2018
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
- 批准号:
1855391 - 财政年份:2018
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
- 批准号:
1854000 - 财政年份:2018
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
- 批准号:
1929901 - 财政年份:2018
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
- 批准号:
1801986 - 财政年份:2017
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
- 批准号:
1562888 - 财政年份:2016
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1563848 - 财政年份:2016
- 资助金额:
$ 54.72万 - 项目类别:
Standard Grant