SaTC: CORE: Small: Practical methods for detecting access permission vulnerabilities caused by sysadmin's configuration errors

SaTC:核心:小:检测由系统管理员配置错误引起的访问权限漏洞的实用方法

基本信息

  • 批准号:
    1814388
  • 负责人:
  • 金额:
    $ 50万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2018
  • 资助国家:
    美国
  • 起止时间:
    2018-09-01 至 2022-08-31
  • 项目状态:
    已结题

项目摘要

As data center systems become ever so complex, it has been ever so daunting for system administrators to configure various permission correctly without accidentally opening up permissions for unintended users (and also malicious users) and resulting in catastrophic security disasters. Since data centers have been used to store and manage data not only for financial, business, communication, but also our daily life such as emails, photos, even home appliances and automobile data, it has become ever so important to prevent human errors (system administrator errors) in access permission configurations to avoid security attacks and privacy leaks. This project will develop new methods to detect and prevent permission configuration errors. The project will involve various educational and outreach activities for students, especially women students in computer science; the investigator has been a role model and a mentor for women high school students, undergraduates, graduates and junior faculty.To address this access-control misconfigurations problem, the project has three main objectives: (i) providing sysadmins with precise, complete information, (ii) detecting suspicious accesses after access permission changes and (iii) eliminating access-control configuration mistakes. These three objectives will be achieved by using a combination of static program analysis, binary instrumentation, profiling, static and quantitative methods, decision tree machine learning, software testing, etc. The proposed research includes the following three synergistic thrusts: (1) Informative Logging for Access Permission-Related Errors. (2) Intelligent monitoring and detection of suspicious accesses. (3) Holistic Cross-component Access-Control Management. The three thrusts together well cover the important security problem that has never been addressed by prior work.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
随着数据中心系统变得如此复杂,系统管理员可以正确配置各种许可,而无意为意外用户(以及恶意用户)打开权限,并导致灾难性的安全灾难。由于数据中心已被用来存储和管理用于财务,业务,通信的数据,而且还用于我们的日常生活,例如电子邮件,照片,甚至家庭用具和汽车数据,因此防止人体错误(系统管理员错误)在访问许可配置中以避免安全攻击和隐私泄漏变得非常重要。该项目将开发新方法来检测和防止权限配置错误。 该项目将涉及针对学生的各种教育和外展活动,尤其是计算机科学领域的女学生; the investigator has been a role model and a mentor for women high school students, undergraduates, graduates and junior faculty.To address this access-control misconfigurations problem, the project has three main objectives: (i) providing sysadmins with precise, complete information, (ii) detecting suspicious accesses after access permission changes and (iii) eliminating access-control configuration mistakes.这三个目标将通过使用静态程序分析,二进制仪器,分析,静态和定量方法,决策树的机器学习,软件测试等的组合来实现这三个目标。拟议的研究包括以下三个协同的推力:(1)提供访问访问许可相关错误的信息记录。 (2)可疑访问的智能监控和检测。 (3)整体跨组件访问控制管理。这三个推力很好地涵盖了先前工作从未解决过的重要安全问题。该奖项反映了NSF的法定任务,并且使用基金会的知识分子优点和更广泛的影响评估标准,被认为值得通过评估来获得支持。

项目成果

期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Towards Continuous Access Control Validation and Forensics
  • DOI:
    10.1145/3319535.3363191
  • 发表时间:
    2019-11
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Chengcheng Xiang;Yudong Wu;Bingyu Shen;Mingyao Shen;Haochen Huang;Tianyin Xu;Yuanyuan Zhou;Cindy Moore;Xinxin Jin;Tianwei Sheng
  • 通讯作者:
    Chengcheng Xiang;Yudong Wu;Bingyu Shen;Mingyao Shen;Haochen Huang;Tianyin Xu;Yuanyuan Zhou;Cindy Moore;Xinxin Jin;Tianwei Sheng
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Yuanyuan Zhou其他文献

Synthesis and photoluminescence properties of a new red emitting phosphor: Ca3(VO4)2:Eu3+; Mn2+
新型红色荧光粉Ca3(VO4)2:Eu3的合成及其光致发光性能;
  • DOI:
    10.1016/j.materresbull.2006.09.002
  • 发表时间:
    2007
  • 期刊:
  • 影响因子:
    5.4
  • 作者:
    Haiping Zhang;M. Lü;Zhiliang Xiu;Shufen Wang;Guangjun Zhou;Yuanyuan Zhou;Shumei Wang;Zifeng Qiu;Aiyu Zhang
  • 通讯作者:
    Aiyu Zhang
Crystal structure of ryanodine receptor SPRY2 domain from the diamondback moth provides insights for development of novel insecticides.
小菜蛾的兰尼碱受体 SPRY2 结构域的晶体结构为新型杀虫剂的开发提供了见解。
The Critical Role of Organoamines in the Irreversible Degradation of Metal Halide Perovskite Precursor: Mechanism and Inhibiting Strategy
有机胺在金属卤化物钙钛矿前驱体不可逆降解中的关键作用:机制和抑制策略
  • DOI:
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    22
  • 作者:
    Qingshun Dong;Yuanyuan Zhou;Xiaoqiang Yu;Wenzhe Shang;Yanfeng Yin;Chen Jiang;Jiming Bian;Bo Song;Shengye Jin;Liduo Wang;Yantao Shi
  • 通讯作者:
    Yantao Shi
Association of Hyponatremia and Renal Function in Type 1 Cardiorenal syndrome.
1 型心肾综合征低钠血症与肾功能的关联。
  • DOI:
  • 发表时间:
    2020
  • 期刊:
  • 影响因子:
    5.5
  • 作者:
    Xin He;Ruicong Xue;Yuzhong Wu;Chen Liu;Bin Dong;Yuanyuan Zhou;Weihao Liang;Yugang Dong;Marvin Owusu-Agyeman;Fangfei Wei;Zexuan Wu
  • 通讯作者:
    Zexuan Wu
Semisupervised Learning-Based SAR ATR via Self-Consistent Augmentation
通过自洽增强实现基于半监督学习的 SAR ATR
  • DOI:
    10.1109/tgrs.2020.3013968
  • 发表时间:
    2021-06
  • 期刊:
  • 影响因子:
    8.2
  • 作者:
    Chen Wang;Jun Shi;Yuanyuan Zhou;Xiaqing Yang;Zenan Zhou;Shunjun Wei;Xiaoling Zhang
  • 通讯作者:
    Xiaoling Zhang

Yuanyuan Zhou的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Yuanyuan Zhou', 18)}}的其他基金

RII Track-4: Novel Electrochemistry in Hybrid Organic-Inorganic Perovskite Materials
RII Track-4:有机-无机杂化钙钛矿材料中的新型电化学
  • 批准号:
    1929019
  • 财政年份:
    2019
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CSR: Small: Practical methods for removing latent configuration errors in cloud platforms
CSR:小:消除云平台中潜在配置错误的实用方法
  • 批准号:
    1526966
  • 财政年份:
    2015
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CSR: Small: Proactive Methods in Handling Configuration Errors in Data Centers and Cloud Infrastructures
CSR:小:处理数据中心和云基础设施中配置错误的主动方法
  • 批准号:
    1321006
  • 财政年份:
    2013
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CSR: SMALL: Automatically Detecting, Diagnosing and Resolving Abnormal Battery Drain Issues on Smartphone Systems
CSR:小:自动检测、诊断和解决智能手机系统上的异常电池消耗问题
  • 批准号:
    1217408
  • 财政年份:
    2012
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
I-Corps: Automating People Research with Intelligent Analysis and Mining of Social Network Data on the Internet
I-Corps:通过智能分析和挖掘互联网上的社交网络数据实现人员研究自动化
  • 批准号:
    1264250
  • 财政年份:
    2012
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CSR: Small: Improving Software Diagnosability via Automatic Log Inferrence and Informative Logging
CSR:小:通过自动日志推断和信息记录提高软件可诊断性
  • 批准号:
    1017784
  • 财政年份:
    2010
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
SHF: Small: Software and Hardware Support for Detecting Concurrency, Sequential and Distributed Bugs via Data-Flow Invariants
SHF:小型:通过数据流不变量检测并发、顺序和分布式错误的软件和硬件支持
  • 批准号:
    1017804
  • 财政年份:
    2010
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CAREER: Improving Storage System Performance, Dependability and Manageability Using System Mining Techniques
职业:使用系统挖掘技术提高存储系统性能、可靠性和可管理性
  • 批准号:
    1001158
  • 财政年份:
    2009
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
CSR---PDOS: Online Production-Run Software Failure Diagnosis at the User Site
CSR---PDOS:用户现场生产运行软件故障在线诊断
  • 批准号:
    1022830
  • 财政年份:
    2009
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Collaborative Research: Application-adaptive I/O Stack for Data-intensive Scientific Computing
协作研究:用于数据密集型科学计算的应用自适应 I/O 堆栈
  • 批准号:
    1001160
  • 财政年份:
    2009
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant

相似国自然基金

基于NRF2调控KPNB1促进PD-L1核转位介导非小细胞肺癌免疫治疗耐药的机制研究
  • 批准号:
    82303969
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
小胶质细胞调控外侧隔核-腹侧被盖区神经环路介导社交奖赏障碍的机制研究
  • 批准号:
    82304474
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
肾去交感神经术促进下丘脑室旁核小胶质细胞M2型极化减轻心衰损伤的机制研究
  • 批准号:
    82370387
  • 批准年份:
    2023
  • 资助金额:
    49 万元
  • 项目类别:
    面上项目
空间邻近标记技术研究莱茵衣藻蛋白核小管与碳浓缩机制的潜在关系
  • 批准号:
    32300220
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
polyG蛋白聚集体诱导小胶质细胞活化在神经元核内包涵体病中的作用及机制研究
  • 批准号:
    82301603
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
  • 批准号:
    2327427
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
  • 批准号:
    2343387
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
  • 批准号:
    2341206
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了