课题基金 / 基金详情

SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity

SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
SaTC:核心:中:通过人类活动增强自动漏洞分析
批准号:
1704253
负责人:
Giovanni Vigna
金额:
$110.16万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-01 至 2023-07-31

项目摘要

项目成果

Giovanni Vigna的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Traditionally, human analysts have carried out the core analysis tasks when checking software programs for vulnerabilities, while using automated techniques as an aid. In this case, the humans are the orchestrators of the analysis process, and they delegate specific tasks to specific tools (such as a disassembler or a symbolic execution system), taking care of combining and composing the results of multiple tools. Because the automated analysis of binary programs has advanced to sophisticated techniques that scale to large sets of real-world binary programs, it is now proposed that we move to a new paradigm in which automated tools orchestrate the process, with tasks being delegated to humans when appropriate. The research investigates this new approach, in which human actions are leveraged when automated techniques are unable to deal with the semantically rich, application-specific aspects of applications, which are tasks that humans can carry out with little effort. The overall goal is to improve the capabilities of automated vulnerability analysis and patching. The research will develop a well-defined framework in which subtasks are modeled and assigned to actors in a principled way. For example, fuzzing is a technique commonly used in automated vulnerability analysis. This approach requires, as input, a set of test cases, or seeds, that exercise the functionality of the target binary. These seeds are then mutated to explore more and more of the code base and increase the chance of triggering bugs. The seed quality, in terms of how well they exercise the target program, has a scaling effect on the effectiveness of a fuzzer: the more coverage these test cases provide, the more code will be explored by mutating them. Unfortunately, the creation of high-quality test case seeds is a complicated problem, and this is generally seen as a human-provided input into a system.Because humans have an excellent understanding of the semantics of software, they are very effective at creating high-quality test cases. The proposed framework starts the analysis and then generates well-defined "seeding tasklet" to integrate human efforts in a systematic way that does not require expert-level human analysts.These simple tasks represent staged interactions with an application that an unskilled human can carry out (e.g., by executing a transaction or filling a form).Therefore, these tasks can be crowdsourced through various channels (such as Amazon's Mechanical Turk), and their results automatically merged into the overall vulnerability analysis process.The reliance on a formal, well-defined framework supports the discovery of unanticipated combinations of automation and actions performed by humans with different skill levels.By improving the state-of-the-art in binary analysis it is possible to analyze a larger number of binaries in a more complete way.As a result, more vulnerabilities are identified before deployment, contributing to the overall security of software applications, including those that are part of the critical infrastructure.
期刊论文(22)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2022
期刊:
影响因子: --
作者: [Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna]
通讯作者: Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna
Sleak: automating address space layout derandomization
Sleak:自动化地址空间布局去随机化
DOI: 10.1145/3359789.3359820
发表时间: 2019
期刊: Proceedings of the 35th Annual Computer Security Applications Conference
影响因子: --
作者: [Hauser, Christophe, Menon, Jayakrishna, Shoshitaishvili, Yan, Wang, Ruoyu, Vigna, Giovanni, Kruegel, Christopher]
通讯作者: Kruegel, Christopher
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者: [Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna]
通讯作者: Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna
DOI: 10.1145/3133956.3134105
发表时间: 2017-08
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Yan Shoshitaishvili;Michael Weissbacher;Lukas Dresel;Christopher Salls;Ruoyu Wang;Christopher Krügel;Giovanni Vigna]
通讯作者: Yan Shoshitaishvili;Michael Weissbacher;Lukas Dresel;Christopher Salls;Ruoyu Wang;Christopher Krügel;Giovanni Vigna
18
    AI Institute for Agent-based Cyber Threat Intelligence and Operation
    • 批准号:
      2229876
    • 项目类别:
      Cooperative Agreement
    • 资助金额:
      $1999.42万
    • 财政年份:
      2023
    • 负责人:
      Giovanni Vigna
    • 依托单位:
    EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
    TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
    Organization of Grand Challenges in Cyber Security
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: