课题基金 / 基金详情

SaTC: CORE: Small: Enabling Systematic Evaluation of the Soundness of Android Security Analysis Techniques

SaTC: CORE: Small: Enabling Systematic Evaluation of the Soundness of Android Security Analysis Techniques
SaTC:CORE:小型:支持对 Android 安全分析技术的健全性进行系统评估
批准号:
1815336
负责人:
Adwait Nadkarni
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-09-01 至 2023-08-31

项目摘要

项目成果

Adwait Nadkarni的其他基金

相似基金

相关文献

中文摘要
翻译
移动设备已经成为我们当前消费者计算环境的结构,这是由它们支持的各种“应用程序”推动的,这些应用程序允许用户执行复杂的计算任务。这些设备和应用程序已经变得非常个人化,因此可以访问隐私敏感的资源和信息。为了防止这种访问被滥用,必须了解保护移动应用程序的挑战,实际上是了解当前安全分析方法的真实能力。针对恶意应用程序的第一道防线是分析应用程序以检测安全漏洞或恶意行为的工具,理想情况下是在应用程序发布到应用程序市场之前。对于这些工具来说,重要的是要“健全”,即检测正在分析的应用程序中的所有不良行为实例。先前的工作已经表明,由于实际原因(例如,为了合理的分析时间),这类工具可能经常牺牲可靠性,从而导致工具是可靠的(即,大部分是可靠的,但带有一些不可靠的假设)。然而,这些以安全为重点的程序分析技术的有效性并未得到很好的理解,因为不可靠的假设可能不会超出一小群专家的范围,从而导致此类工具的用户产生错误的安全感。这项研究开发了一个框架,用于系统地评估现有的安全技术,以揭示以前未知的不合理的假设。在本研究过程中开发的方法有可能产生重大的经济和社会影响,因为改进的安全工具改进了对移动应用程序的审查,防止或减少了私人信息的丢失或被盗。此外,虽然这项工作的深远影响将是提高最终用户应用程序的可靠性,但更直接的影响可以在教育活动中看到。也就是说,这个项目在软件工程和安全课程中融入了安全移动应用程序开发的最佳实践,以及通过这个项目开发的新的安全评估技术,同时向更广泛的研究社区传播对不可靠分析的危险的认识。本研究项目开发了一种新的方法来评估Android的以安全为重点的静态分析工具,通过从功能软件测试领域采用突变分析的原理来系统地识别不合理的假设。该方法包括三个主要部分:(1)通过检查安全分析工具的声明、开源应用程序中的安全漏洞和恶意软件样本,经验推导出针对安全的突变操作符(即安全操作符)的规范;(2)在使用特定于上下文的突变方案评估的安全技术的上下文中实例化和播种操作符;以及(3)通过运行关于突变的静态分析工具以及检测和解决漏洞来扩展Android静态程序分析工具的健全核心。这项研究项目跨越了计算机安全和软件工程的互补学科,并解决了几个目前在这两个学科中都没有解决的公开研究问题。更具体地说,这个项目建立在突变分析的理论基础之上,该分析旨在评估功能软件测试的有效性,并在以安全为重点的环境中实例化它们。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Mobile devices have become the fabric of our current consumer computing landscape, driven by the diverse "apps" they support, which allow users to carry out complex computing tasks. These devices and apps have become deeply personal, and as such have access to privacy-sensitive resources and information. To prevent misuse of this access, it is imperative to understand the challenges in securing mobile apps, and in effect, the true capabilities of current approaches for security analysis. The first line of defense against malicious applications are tools that analyze applications to detect security vulnerabilities or malicious behavior, ideally before apps are published to application markets. It is important for such tools to be "sound", i.e., to detect all instances of bad behavior in the application being analyzed. Prior work has indicated that such tools may often sacrifice soundness for practical reasons (e.g., for a reasonable analysis time), leading to tools that are soundy (i.e., mostly sound, but with some unsound assumptions). However, the effectiveness of these security-focused program analysis techniques is not well understood, as the unsound assumptions may not be known beyond a small community of experts, leading to a false sense of security among the users of such tools. This research develops a framework for systematically evaluating existing security techniques to uncover previously unknown unsound assumptions. The methodology developed in the course of this research has the potential for a large economic and societal impact, as improving security tools improves the vetting of mobile applications and prevents or mitigates the loss or theft of private information. Moreover, while the far-reaching impact of this work will be in increasing reliability of applications for end users, more immediate impact can be seen in educational activities. That is, this project incorporates into software engineering and security courses the best-practices for secure mobile application development, and novel security evaluation techniques developed via this project, while disseminating awareness regarding the dangers of unsound analyses to the broader research community.This research project develops a new methodology for assessing security-focused static analysis tools for Android, by adopting the principles of mutation analysis from the field of functional software testing to systematically identify unsound assumptions. This methodology consists of three major components: (1) empirical derivation of specifications for security-focused mutation operators (i.e., security operators) through the examination of claims by security analysis tools, security bugs in open source apps, and malware samples; (2) the instantiation and seeding operators in the context of the security technique being evaluated using context-specific mutation schemes; and (3) expansion of the sound core of static program analysis tools for Android by running static analysis tools on mutants and detecting and addressing vulnerabilities. This research project cuts across the complementary disciplines of computer security and software engineering and tackles several open research questions that are currently unaddressed in both disciplines. More specifically, this project builds upon the theoretical underpinnings of mutation analysis, which aims at evaluating the efficacy of functional software tests and instantiates them in a security-focused context.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2018-06
期刊: ArXiv
影响因子: --
作者: [R. Bonett;Kaushal Kafle;Kevin Moran;Adwait Nadkarni;D. Poshyvanyk]
通讯作者: R. Bonett;Kaushal Kafle;Kevin Moran;Adwait Nadkarni;D. Poshyvanyk
DeepMutation: A Neural Mutation Tool
DeepMutation:神经突变工具
DOI: --
发表时间: 2020
期刊: 2020 IEEE/ACM 42nd International Conference on Software Engineering: Companion Proceedings (ICSE-Companion
影响因子: --
作者: [Tufano, Michele and]
通讯作者: Tufano, Michele and
µSE: Mutation-Based Evaluation of Security-Focused Static Analysis Tools for Android
µSE:基于突变的 Android 安全静态分析工具评估
DOI: 10.1109/icse-companion52605.2021.00034
发表时间: 2021
期刊: 2021 IEEE/ACM 43rd International Conference on Software Engineering: Companion Proceedings (ICSE-Companion
影响因子: --
作者: [Ami, Amit Seal, Kafle, Kaushal, Nadkarni, Adwait, Poshyvanyk, Denys, Moran, Kevin]
通讯作者: Moran, Kevin
DOI: 10.1145/3439802
发表时间: 2021-02
期刊: ACM Transactions on Privacy and Security (TOPS)
影响因子: --
作者: [Amit Seal Ami;Kaushal Kafle;Kevin Moran;Adwait Nadkarni;D. Poshyvanyk]
通讯作者: Amit Seal Ami;Kaushal Kafle;Kevin Moran;Adwait Nadkarni;D. Poshyvanyk
8
    CAREER: Integrating Trust and Accountability into Compliance Enforcement for a Secure Internet of Things
    • 批准号:
      2237012
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $53.77万
    • 财政年份:
      2023
    • 负责人:
      Adwait Nadkarni
    • 依托单位:
    Collaborative Research: CPS: Medium: Enabling Data-Driven Security and Safety Analyses for Cyber-Physical Systems
    • 批准号:
      2132281
    • 项目类别:
      Standard Grant
    • 资助金额:
      $79.98万
    • 财政年份:
      2022
    • 负责人:
      Adwait Nadkarni
    • 依托单位:
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: