SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
批准号:
1704253
负责人:
Giovanni Vigna
金额:
$110.16万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-01 至 2023-07-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Traditionally, human analysts have carried out the core analysis tasks when checking software programs for vulnerabilities, while using automated techniques as an aid. In this case, the humans are the orchestrators of the analysis process, and they delegate specific tasks to specific tools (such as a disassembler or a symbolic execution system), taking care of combining and composing the results of multiple tools. Because the automated analysis of binary programs has advanced to sophisticated techniques that scale to large sets of real-world binary programs, it is now proposed that we move to a new paradigm in which automated tools orchestrate the process, with tasks being delegated to humans when appropriate. The research investigates this new approach, in which human actions are leveraged when automated techniques are unable to deal with the semantically rich, application-specific aspects of applications, which are tasks that humans can carry out with little effort. The overall goal is to improve the capabilities of automated vulnerability analysis and patching. The research will develop a well-defined framework in which subtasks are modeled and assigned to actors in a principled way. For example, fuzzing is a technique commonly used in automated vulnerability analysis. This approach requires, as input, a set of test cases, or seeds, that exercise the functionality of the target binary. These seeds are then mutated to explore more and more of the code base and increase the chance of triggering bugs. The seed quality, in terms of how well they exercise the target program, has a scaling effect on the effectiveness of a fuzzer: the more coverage these test cases provide, the more code will be explored by mutating them. Unfortunately, the creation of high-quality test case seeds is a complicated problem, and this is generally seen as a human-provided input into a system.Because humans have an excellent understanding of the semantics of software, they are very effective at creating high-quality test cases. The proposed framework starts the analysis and then generates well-defined "seeding tasklet" to integrate human efforts in a systematic way that does not require expert-level human analysts.These simple tasks represent staged interactions with an application that an unskilled human can carry out (e.g., by executing a transaction or filling a form).Therefore, these tasks can be crowdsourced through various channels (such as Amazon's Mechanical Turk), and their results automatically merged into the overall vulnerability analysis process.The reliance on a formal, well-defined framework supports the discovery of unanticipated combinations of automation and actions performed by humans with different skill levels.By improving the state-of-the-art in binary analysis it is possible to analyze a larger number of binaries in a more complete way.As a result, more vulnerabilities are identified before deployment, contributing to the overall security of software applications, including those that are part of the critical infrastructure.
期刊论文(22)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna]
通讯作者:
Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna
Sleak: automating address space layout derandomization
Sleak:自动化地址空间布局去随机化
DOI:
10.1145/3359789.3359820
发表时间:
2019
期刊:
Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Hauser, Christophe, Menon, Jayakrishna, Shoshitaishvili, Yan, Wang, Ruoyu, Vigna, Giovanni, Kruegel, Christopher]
通讯作者:
Kruegel, Christopher
DOI:
--
发表时间:
2023
期刊:
影响因子:
--
作者:
[Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna]
通讯作者:
Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna
DOI:
10.1145/3133956.3134105
发表时间:
2017-08
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Yan Shoshitaishvili;Michael Weissbacher;Lukas Dresel;Christopher Salls;Ruoyu Wang;Christopher Krügel;Giovanni Vigna]
通讯作者:
Yan Shoshitaishvili;Michael Weissbacher;Lukas Dresel;Christopher Salls;Ruoyu Wang;Christopher Krügel;Giovanni Vigna
Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates
Cloud Strife:降低域验证证书的安全风险
DOI:
10.14722/ndss.2018.23327
发表时间:
2018
期刊:
Internet Society Symposium on Network and Distributed System Security (NDSS
影响因子:
--
作者:
[Borgolte, Kevin, Fiebig, Tobias, Hao, Shuang, Kruegel, Christopher, Vigna, Giovanni]
通讯作者:
Vigna, Giovanni
共 18 条
AI Institute for Agent-based Cyber Threat Intelligence and Operation
-
批准号:2229876
-
项目类别:Cooperative Agreement
-
资助金额:$1999.42万
-
财政年份:2023
-
负责人:Giovanni Vigna
-
依托单位:
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
-
批准号:1623246
-
项目类别:Standard Grant
-
资助金额:$14.54万
-
财政年份:2016
-
负责人:Giovanni Vigna
-
依托单位:
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
-
批准号:1408632
-
项目类别:Standard Grant
-
资助金额:$106.61万
-
财政年份:2014
-
负责人:Giovanni Vigna
-
依托单位:
Organization of Grand Challenges in Cyber Security
-
批准号:0939188
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2009
-
负责人:Giovanni Vigna
-
依托单位:
SGER: Grand Challenges in Cyber Security
-
批准号:0820907
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2008
-
负责人:Giovanni Vigna
-
依托单位:
CT-ER: A Framework for Live Security Exercises and Challenges
-
批准号:0716753
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Modeling and Analyzing Trust in Service-Oriented Architectures
-
批准号:0716095
-
项目类别:Standard Grant
-
资助金额:$85.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Using Structural and Behavioral Models to Detect Malware
-
批准号:0627783
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2006
-
负责人:Giovanni Vigna
-
依托单位:
CT-ISG: Multi-Model Anomaly Detection for Web-Based Applications
-
批准号:0524853
-
项目类别:Continuing grant
-
资助金额:$45.0万
-
财政年份:2005
-
负责人:Giovanni Vigna
-
依托单位:
CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
-
批准号:0238492
-
项目类别:Continuing grant
-
资助金额:$39.99万
-
财政年份:2003
-
负责人:Giovanni Vigna
-
依托单位:
Collaborative Research: MASSA: Mobile Agent System Security Through Analysis
-
批准号:0209065
-
项目类别:Continuing grant
-
资助金额:$23.01万
-
财政年份:2002
-
负责人:Giovanni Vigna
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: