EAGER: Hyperproperty Abstraction for Information Flow Control

EAGER:信息流控制的超属性抽象

基本信息

  • 批准号:
    1649894
  • 负责人:
  • 金额:
    $ 10.48万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2016
  • 资助国家:
    美国
  • 起止时间:
    2016-09-01 至 2018-08-31
  • 项目状态:
    已结题

项目摘要

Due to increasing cyber-attacks, software developers and analysts need better tools. Among the most important tools are programs that analyse other programs to evaluate security and privacy requirements, to detect vulnerabilities, and in general to predict a program's potential behavior. The theory of computation says these analysis problems are impossible to solve in their general form. Effective analyses rely on approximations, that is, simplified models of program behavior, the theory of which is known as abstract interpretation. This theory is widely used as basis for the design of analysis algorithms. Most existing analyses are for so-called trace properties, which pertain to individual program executions. Security and privacy requirements like confidentiality are about the flow of information in programs, which pertains to correlations between multiple executions. This project uses methods of mathematical semantics and formal logic to develop theory and algorithms for information flow analysis. The theory of abstract interpretation is being extended beyond trace properties, to encompass so-called hyperproperties which involve correlations among multiple behaviors of a program. On this basis, new algorithms are being created and evaluated. The main impact of this project will be to enable researchers and commercial tool developers to implement more sophisticated, comprehensive, and effective analyses for information flow in software. This will lead to improved software quality and protection against attacks, and ultimately increased trustworthiness of cyberspace. The theory developed in this project will contribute to growing science of security which will improve cybersecurity education and workforce training.
由于网络攻击的增加,软件开发人员和分析人员需要更好的工具。其中最重要的工具是分析其他程序以评估安全和隐私需求、检测漏洞以及通常预测程序潜在行为的程序。计算理论说,这些分析问题不可能以一般形式解决。有效的分析依赖于近似,即程序行为的简化模型,其理论被称为抽象解释。这一理论被广泛用作分析算法设计的基础。大多数现有的分析都是针对所谓的跟踪属性的,它与单个程序的执行有关。安全和隐私需求(如机密性)与程序中的信息流有关,这与多次执行之间的相关性有关。本项目使用数学语义学和形式逻辑的方法来发展信息流分析的理论和算法。抽象解释理论正在扩展到超越跟踪属性,包括所谓的超属性,它涉及到程序的多个行为之间的相关性。在此基础上,新的算法正在被创建和评估。这个项目的主要影响将是使研究人员和商业工具开发人员能够为软件中的信息流实现更复杂、全面和有效的分析。这将提高软件质量和抵御攻击的能力,并最终提高网络空间的可信度。在这个项目中发展的理论将有助于发展安全科学,这将改善网络安全教育和劳动力培训。

项目成果

期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Assuming you know: Epistemic Semantics of Relational Annotations for Expressive Flow Policies
假设您知道:表达流策略的关系注释的认知语义
Hypercollecting semantics and its application to static analysis of information flow
超集合语义及其在信息流静态分析中的应用
  • DOI:
    10.1145/3093333.3009889
  • 发表时间:
    2017
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Assaf, Mounir;Naumann, David A.;Signoles, Julien;Totel, Éric;Tronel, Frédéric
  • 通讯作者:
    Tronel, Frédéric
A Logical Analysis of Framing for Specifications with Pure Method Calls
纯方法调用规范框架的逻辑分析
Spartan Jester: end-to-end information flow control for hybrid Android applications
Spartan Jester:混合 Android 应用程序的端到端信息流控制
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

David Naumann其他文献

Association between Center Volume and Allocation to Curative Surgery and Long-Term Survival for Retroperitoneal Sarcoma
  • DOI:
    10.1016/j.ejso.2022.11.141
  • 发表时间:
    2023-02-01
  • 期刊:
  • 影响因子:
  • 作者:
    Sivesh Kamarajah;Marco Baia;David Naumann;Fahad Mahmood;Alessandro Parente;Max Almond;Fabio Tirotta;Samuel Ford;Fadi Dahdaleh;Anant Desai
  • 通讯作者:
    Anant Desai
Does pre-operative neoadjuvant systemic therapy affect the number of lymph nodes on histological examination of tissues excised during axillary node clearance surgery?
  • DOI:
    10.1016/j.ejso.2012.02.064
  • 发表时间:
    2012-05-01
  • 期刊:
  • 影响因子:
  • 作者:
    David Naumann;Martin Sintler
  • 通讯作者:
    Martin Sintler
Preconceptions, experience and future expectations of patients undergoing robotic colorectal surgery at a single centre
  • DOI:
    10.1016/j.ejso.2019.11.170
  • 发表时间:
    2020-02-01
  • 期刊:
  • 影响因子:
  • 作者:
    Mariam Baig;Neena Randhawa;David Naumann;Charles Evans;Adeel Bajwa
  • 通讯作者:
    Adeel Bajwa
Are the number of lymph nodes excised during axillary node clearance surgery affected by neoadjuvant chemotherapy?
  • DOI:
    10.1016/j.ijsu.2012.06.053
  • 发表时间:
    2012-01-01
  • 期刊:
  • 影响因子:
  • 作者:
    David Naumann;Martin Sintler
  • 通讯作者:
    Martin Sintler
Systemic review and meta-analysis comparing stapled versus hand-sewn anastomoses following emergency bowel resection
  • DOI:
    10.1016/j.ijsu.2014.07.096
  • 发表时间:
    2014-11-01
  • 期刊:
  • 影响因子:
  • 作者:
    David Naumann;Aneel Bhangu;Michael Kelly;Douglas Bowley
  • 通讯作者:
    Douglas Bowley

David Naumann的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('David Naumann', 18)}}的其他基金

SaTC: CORE: Small: Relational Verification for Information Assurance and Privacy
SaTC:核心:小型:信息保障和隐私的关系验证
  • 批准号:
    1718713
  • 财政年份:
    2017
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Flexible and Practical Information Flow Assurance for Mobile Apps
TWC:媒介:协作:灵活实用的移动应用信息流保障
  • 批准号:
    1228930
  • 财政年份:
    2012
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
SHF: Small: Collaborative Research: Specification Language Foundations for Modular Reasoning Methodologies
SHF:小型:协作研究:模块化推理方法的规范语言基础
  • 批准号:
    0915611
  • 财政年份:
    2009
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
Collaborative Research: CRI: CRD: A JML Community Infrastructure --Revitalizing Tools and Documentation to Aid Formal Methods Research
协作研究:CRI:CRD:JML 社区基础设施——振兴工具和文档以帮助形式化方法研究
  • 批准号:
    0708330
  • 财政年份:
    2007
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Continuing Grant
CT-ISG Collaborative Research: Access Control and Downgrading in Information Flow Assurance
CT-ISG协同研究:信息流保障中的访问控制与降级
  • 批准号:
    0627338
  • 财政年份:
    2006
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
Collaborative Research: Formal Methods for Behavioral Subclassing and Callbacks
协作研究:行为子类化和回调的形式化方法
  • 批准号:
    0429894
  • 财政年份:
    2004
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Continuing Grant
Collaborative Research: Integrating Pointer Confinement and Access Control for Encapsulation
协作研究:集成指针限制和访问控制进行封装
  • 批准号:
    0208984
  • 财政年份:
    2002
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
U.S.-Brazil Cooperative Research: Towards a Practical Calculus of Object-Oriented Programming
美国-巴西合作研究:面向对象编程的实用演算
  • 批准号:
    9813854
  • 财政年份:
    1999
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
Program Derivation for a Data Structures Course
数据结构课程的程序推导
  • 批准号:
    9455660
  • 财政年份:
    1995
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
Tools for Undergraduate Program Derivation
本科生程序推导工具
  • 批准号:
    9451614
  • 财政年份:
    1994
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant

相似海外基金

Collaborative Research: SaTC: CORE: Small: Hyperproperty-based Enforcement of Information-flow Security
协作研究:SaTC:核心:小型:基于超产权的信息流安全执行
  • 批准号:
    2245115
  • 财政年份:
    2023
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Hyperproperty-based Enforcement of Information-flow Security
协作研究:SaTC:核心:小型:基于超产权的信息流安全执行
  • 批准号:
    2245114
  • 财政年份:
    2023
  • 资助金额:
    $ 10.48万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了