CAREER: Next Generation Black-Box Web Application Vulnerability Analysis

职业:下一代黑盒 Web 应用程序漏洞分析

基本信息

  • 批准号:
    1651661
  • 负责人:
  • 金额:
    $ 41.66万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2017
  • 资助国家:
    美国
  • 起止时间:
    2017-05-01 至 2023-04-30
  • 项目状态:
    已结题

项目摘要

Recent sensitive data breaches are caused by overlooked vulnerabilities in web applications. To secure their web applications, companies typically hire professional hackers to break into their web applications. While this process finds vulnerabilities, it is costly and does not scale. Black-box vulnerability scanners attempt to automate this process. By treating the web application as a black-box (no knowledge of the source code of the application), these tools can discover unknown vulnerabilities. Traditionally, these tools work by crawling the web application, identifying input vectors, then injecting malicious input. However, despite being sold commercially for tens of thousands of dollars, the PI has shown that they are ineffective. This project aims to create a novel and effective black-box vulnerability analysis framework that finds unknown vulnerabilities in any web application.The PI proposes a novel technique called inductive reverse engineering which, using recent advances in inductive programming, can automatically reverse engineer an abstraction of the web application's source code. Then, the tool will use static analysis techniques to discover potential vulnerabilities in the abstraction of the reverse engineered code. The goal of this project is advance the state-of-the-art in black-box vulnerability analysis tools. All tools and techniques will be open-sourced, so that researchers and industry can benefit. Use of the tool on real-world software will result in more vulnerabilities found and fixed, thus improving software security as a whole. In addition, the PI will create and lead hands-on workshops that allow all CS students to study and exploit vulnerabilities, as well as understand the ethical considerations. The education modules and the software infrastructure required will be released.
最近的敏感数据泄露是由网络应用程序中被忽视的漏洞造成的。为了保护他们的网络应用程序,公司通常会雇佣专业黑客侵入他们的网络应用程序。虽然这一过程会发现漏洞,但成本很高,而且不能扩展。黑盒漏洞扫描程序试图自动执行此过程。通过将Web应用程序视为黑匣子(对应用程序源代码一无所知),这些工具可以发现未知漏洞。传统上,这些工具的工作方式是爬行Web应用程序,识别输入向量,然后注入恶意输入。然而,尽管PI的商业售价高达数万美元,但它已经表明它们是无效的。该项目旨在创建一个新的有效的黑盒漏洞分析框架,以发现任何Web应用程序中的未知漏洞。PI提出了一种称为归纳逆向工程的新技术,该技术利用归纳编程的最新进展,可以自动对Web应用程序源代码的抽象进行逆向工程。然后,该工具将使用静态分析技术来发现反向工程代码抽象中的潜在漏洞。该项目的目标是推进最先进的黑匣子漏洞分析工具。所有的工具和技术都将是开源的,这样研究人员和产业界都能受益。在现实软件上使用该工具将导致发现和修复更多漏洞,从而提高软件整体安全性。此外,PI将创建和领导实践研讨会,让所有CS学生学习和利用漏洞,并了解伦理考虑。将发布所需的教育模块和软件基础设施。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Adam Doupe其他文献

Adam Doupe的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Adam Doupe', 18)}}的其他基金

SaTC: CORE: Medium: Collaborative: Taming Web Content Through Automated Reduction in Browser Functionality
SaTC:核心:媒介:协作:通过自动减少浏览器功能来驯服 Web 内容
  • 批准号:
    1703644
  • 财政年份:
    2017
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Standard Grant
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
EDU:协作:通过点播现场竞赛教育安全人员
  • 批准号:
    1623269
  • 财政年份:
    2016
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Standard Grant

相似国自然基金

Next Generation Majorana Nanowire Hybrids
  • 批准号:
  • 批准年份:
    2020
  • 资助金额:
    20 万元
  • 项目类别:

相似海外基金

CAREER: Next-generation Logic, Memory, and Agile Microwave Devices Enabled by Spin Phenomena in Emergent Quantum Materials
职业:由新兴量子材料中的自旋现象实现的下一代逻辑、存储器和敏捷微波器件
  • 批准号:
    2339723
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Continuing Grant
CAREER: Securing Next-Generation Transportation Infrastructure: A Traffic Engineering Perspective
职业:保护下一代交通基础设施:交通工程视角
  • 批准号:
    2339753
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Standard Grant
CAREER: Next-Generation Methods for Statistical Integration of High-Dimensional Disparate Data Sources
职业:高维不同数据源统计集成的下一代方法
  • 批准号:
    2422478
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Continuing Grant
CAREER: LoRa Enabled Space-air-ground Integrated Networks for Next-Generation Agricultural IoT
职业生涯:LoRa 支持下一代农业物联网的天地一体化网络
  • 批准号:
    2338976
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Continuing Grant
CAREER: Next-generation protease inhibitor discovery with chemically diversified antibodies
职业:利用化学多样化的抗体发现下一代蛋白酶抑制剂
  • 批准号:
    2339201
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Continuing Grant
CAREER: Next Generation Online Resource Allocation
职业:下一代在线资源分配
  • 批准号:
    2340306
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Standard Grant
CAREER: Next-Generation Flow Cytometry - A New Approach to Cell Heterogeneity
职业:下一代流式细胞术 - 细胞异质性的新方法
  • 批准号:
    2422750
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Standard Grant
CAREER: Non-Local Metamaterials and Metasurfaces for Next Generation Non-Reciprocal Acoustic Devices
职业:下一代非互易声学器件的非局域超材料和超表面
  • 批准号:
    2340782
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Standard Grant
CAREER: Next Generation of High-Level Synthesis for Agile Architectural Design (ArchHLS)
职业:下一代敏捷架构设计高级综合 (ArchHLS)
  • 批准号:
    2338365
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Continuing Grant
CAREER: Engineering next-generation adrenal gland organoids
职业:设计下一代肾上腺类器官
  • 批准号:
    2335133
  • 财政年份:
    2024
  • 资助金额:
    $ 41.66万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了