课题基金 / 基金详情

SHF:Small: Rooting Out Data- and Control-Flow Anomalies in Event-Based Systems

SHF:Small: Rooting Out Data- and Control-Flow Anomalies in Event-Based Systems
SHF:Small:根除基于事件的系统中的数据和控制流异常
批准号:
1717963
负责人:
Nenad Medvidovic
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2022-07-31
关键词:

项目摘要

项目成果

Nenad Medvidovic的其他基金

相似基金

相关文献

中文摘要
翻译
分布式基于事件(DEB)的软件系统非常广泛,跨越不同的领域,例如用户界面、金融市场、物流和移动应用程序。与传统的软件系统不同,在DEB系统中,软件组件不直接交互,而是依赖代理来传输数据和不同事件的通知。因此,DEB系统中的组件是高度解耦的,从而产生可伸缩的、易于发展的应用程序。然而,这种灵活性和可伸缩性是有代价的:很难准确地了解DEB系统的结构和功能,这使得很难确保DEB系统的预期行为和没有安全漏洞。为了处理传统软件系统中的类似问题,已经开发了许多技术。然而,这些技术在应用于DEB系统时提供了不充分和/或误导性的信息。该项目提供了一套工具,用于确保针对DEB系统的软件正确性、可靠性和安全性。该项目通过开发新的程序分析、运行时监控和可视化技术来实现这一点,这些技术解释了DEB系统中固有的隐式调用、并发性和模糊接口。该项目的具体重点是(1)导致正确性和可靠性问题的数据流异常,以及(2)导致安全性问题的数据流和控制流异常。这项研究的广泛影响是直接的:它为工程师提供了广泛的重要软件开发领域的分析和可视化技术,这些技术可与传统领域中可用的技术相媲美。一方面,DEB系统的灵活性预示着它们的持续采用和扩展。另一方面,在理解、分析、调试、发展和保护DEB系统方面的障碍阻碍了这种采用。这项研究在提供必要的补救措施和帮助实现DEB系统的全部潜力的方向上迈出了重要的一步。
英文摘要
Distributed event-based (DEB) software systems are widespread, spanning diverse domains such as user interfaces, financial markets, logistics, and mobile applications. Unlike traditional software systems, in DEB systems software components do not directly interact but rely on brokers to transfer data and notifications of different events. Consequently, components in DEB systems are highly decoupled, which yields scalable, easy-to-evolve applications. However, this flexibility and scalability comes at a price: It is difficult to have an accurate insight into the structure and functionality of a DEB system, which makes it difficult to ensure a DEB system's desired behavior and absence of security vulnerabilities. Many techniques have been developed for dealing with analogous issues in traditional software systems. However, those techniques provide inadequate and/or misleading information when applied to DEB systems. This project is providing a suite of tools for ensuring software correctness, reliability, and security that are specifically targeted at DEB systems. The project does so by developing novel program analysis, runtime monitoring, and visualization techniques that account for the implicit invocation, concurrency, and ambiguous interfaces inherent in DEB systems. The project's specific focus is on (1) data-flow anomalies that cause correctness and reliability issues and (2) data- and control-flow anomalies that cause security problems. The broader impact of this research is direct: It provides to engineers in a wide range of important software development domains analysis and visualization techniques that are comparable to techniques available in traditional domains. On one hand, the flexibility of DEB systems bodes well for their continued adoption and expansion. On the other hand, that adoption is impeded by obstacles in understanding, analyzing, debugging, evolving, and securing DEB systems. This research presents a significant step in the direction of providing the necessary remedies and helping to realize the full potential of DEB systems.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3180155.3180249
发表时间: 2018-05
期刊: 2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE)
影响因子: --
作者: [Yixue Zhao;Marcelo Schmitt Laser;Yingjun Lyu;N. Medvidović]
通讯作者: Yixue Zhao;Marcelo Schmitt Laser;Yingjun Lyu;N. Medvidović
SEALANT: A detection and visualization tool for inter-app security vulnerabilities in Android
SEALANT:Android 中应用程序间安全漏洞的检测和可视化工具
DOI: 10.1109/ase.2017.8115699
发表时间: 2017
期刊: 32nd IEEE/ACM International Conference on Automated Software Engineering (ASE 2017
影响因子: --
作者: [Lee, Youn Kyu, Yoodee, Peera, Shahbazian, Arman, Nam, Daye, Medvidovic, Nenad]
通讯作者: Medvidovic, Nenad
DOI: 10.1109/mobilesoft.2019.00017
发表时间: 2019-02
期刊: 2019 IEEE/ACM 6th International Conference on Mobile Software Engineering and Systems (MOBILESoft)
影响因子: --
作者: [Yixue Zhao;N. Medvidović]
通讯作者: Yixue Zhao;N. Medvidović
DOI: 10.1145/3238147.3238215
发表时间: 2018-09
期刊: 2018 33rd IEEE/ACM International Conference on Automated Software Engineering (ASE)
影响因子: --
作者: [Yixue Zhao;Paul Wat;Marcelo Schmitt Laser;N. Medvidović]
通讯作者: Yixue Zhao;Paul Wat;Marcelo Schmitt Laser;N. Medvidović
Collaborative Research: SHF: Medium: A General Framework for Automated Test Transfer
  • 批准号:
    2106871
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2021
  • 负责人:
    Nenad Medvidovic
  • 依托单位:
CRI: CI-NEW: Collaborative Research: Constructing a Community-Wide Software Architecture Infrastructure
  • 批准号:
    1823354
  • 项目类别:
    Standard Grant
  • 资助金额:
    $68.36万
  • 财政年份:
    2018
  • 负责人:
    Nenad Medvidovic
  • 依托单位:
CI-P: Collaborative Research: Planning and Prototyping a Community-Wide Software Architecture Instrument
  • 批准号:
    1629977
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.0万
  • 财政年份:
    2016
  • 负责人:
    Nenad Medvidovic
  • 依托单位:
SHF:Small: Techniques for Pruning Problem and Solution Spaces to Enable Methodical Exploration of Software Development Alternatives
  • 批准号:
    1618231
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2016
  • 负责人:
    Nenad Medvidovic
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: