CICI: SSC: SciTrust: Enhancing Security for Modern Software Programming Cyberinfrastructure
CICI:SSC:SciTrust:增强现代软件编程网络基础设施的安全性
基本信息
- 批准号:1839909
- 负责人:
- 金额:$ 64.92万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-10-01 至 2019-10-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Software plays a vital role supporting scientific communities. Modern software programming cyberinfrastructure (CI), consisting of online discussion platforms (such as Stack Overflow) and social coding repositories (such as Github), offers an open-source and collaborative environment for distributed scientific communities to expedite the process of software development. Within the ecosystem, researchers and developers can reuse code snippets and libraries, or adapt existing ready-to-use software to solve their own problems. Despite the apparent benefits of this new social coding paradigm, its potential security-related risks have been largely overlooked; insecure or malicious codes could be easily embedded and distributed, which could severely damage the scientific credibility of CI. Therefore, there is an urgent need for developing scalable techniques and tools to automatically detect these open-source insecure or malicious codes. To address this issue, this proposed project seeks to explore innovative links between Artificial Intelligence (AI) and cybersecurity to enhance the security of modern software programming CI. The key components of the proposed research are three-fold: (1) a novel AI-based solution (iTrustSO) utilizing social coding properties is developed to automatically identify suspicious insecure code snippets on Stack Overflow; (2) a cross-platform model is constructed to represent the complex interplay between GitHub and Stack Overflow; deep learning techniques are then utilized to build a predictive model (iTrustGH) for automatic detection of malicious codes on GitHub; and (3) a user-friendly tool (SciTrust) is developed to enhance code security for software development. The broader impacts of this work include benefits to scientific communities and the whole society by promoting the efficiency of cyber-enabled software development without sacrificing the security. The establishment of a Cybersecurity Lab through this project enhances the education and workforce training in cybersecurity. The project integrates research with education through curriculum development and student mentoring activities for the newly-established cybersecurity degree program. It is also expected to increase the participation of underrepresented groups including minority and women.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
软件在支持科学界方面发挥着至关重要的作用。现代软件编程网络基础设施(CI)由在线讨论平台(如Stack Overflow)和社交编码库(如Github)组成,为分布式科学社区提供了一个开源和协作环境,以加快软件开发过程。在这个生态系统中,研究人员和开发人员可以重用代码片段和库,或者调整现有的即用型软件来解决他们自己的问题。尽管这种新的社会编码范式有明显的好处,但其潜在的安全相关风险在很大程度上被忽视了;不安全或恶意代码可以很容易地嵌入和分发,这可能严重损害CI的科学可信度。因此,迫切需要开发可扩展的技术和工具来自动检测这些开源的不安全或恶意代码。为了解决这个问题,这个拟议的项目旨在探索人工智能(AI)和网络安全之间的创新联系,以提高现代软件编程CI的安全性。所提出的研究的关键组成部分有三个方面:(1)一种新的基于AI的解决方案(2)构建了一个跨平台模型来描述GitHub和Stack Overflow之间复杂的交互关系;然后利用深度学习技术构建预测模型(iTrustGH),用于自动检测GitHub上的恶意代码;(3)开发用户友好的工具(SciTrust),以增强软件开发的代码安全性。这项工作的更广泛的影响包括通过提高网络软件开发的效率而不牺牲安全性,为科学界和整个社会带来好处。通过该项目建立的网络安全实验室加强了网络安全方面的教育和劳动力培训。该项目通过新设立的网络安全学位课程的课程开发和学生辅导活动将研究与教育相结合。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
ICSD: An Automatic System for Insecure Code Snippet Detection in Stack Overflow over Heterogeneous Information Network
- DOI:10.1145/3274694.3274742
- 发表时间:2018-12
- 期刊:
- 影响因子:0
- 作者:Yanfang Ye;Shifu Hou;Lingwei Chen;X. Li;Liang Zhao;Shouhuai Xu;Jiabin Wang;Qi Xiong
- 通讯作者:Yanfang Ye;Shifu Hou;Lingwei Chen;X. Li;Liang Zhao;Shouhuai Xu;Jiabin Wang;Qi Xiong
Enhancing Robustness of Deep Neural Networks against Adversarial Malware Samples: Principles, Framework, and Application to AICS’2019 Challenge
增强深度神经网络针对对抗性恶意软件样本的鲁棒性:原则、框架和 AICS 2019 挑战赛的应用
- DOI:
- 发表时间:2019
- 期刊:
- 影响因子:0
- 作者:Li, Deqiang;Li, Qianmu;Ye, Yanfang;Xu, Shouhuai
- 通讯作者:Xu, Shouhuai
KADetector: Automatic Identification of Key Actors in Online Hack Forums Based on Structured Heterogeneous Information Network
- DOI:10.1109/icbk.2018.00028
- 发表时间:2018-11
- 期刊:
- 影响因子:0
- 作者:Yiming Zhang;Yujie Fan;Yanfang Ye;Liang Zhao;Jiabin Wang;Qi Xiong;Fudong Shao
- 通讯作者:Yiming Zhang;Yujie Fan;Yanfang Ye;Liang Zhao;Jiabin Wang;Qi Xiong;Fudong Shao
iDev: Enhancing Social Coding Security by Cross-platform User Identification Between GitHub and Stack Overflow
- DOI:10.24963/ijcai.2019/315
- 发表时间:2019-08
- 期刊:
- 影响因子:0
- 作者:Yujie Fan;Yiming Zhang;Shifu Hou;Lingwei Chen;Yanfang Ye;C. Shi;Liang Zhao;Shouhuai Xu
- 通讯作者:Yujie Fan;Yiming Zhang;Shifu Hou;Lingwei Chen;Yanfang Ye;C. Shi;Liang Zhao;Shouhuai Xu
Your Style Your Identity: Leveraging Writing and Photography Styles for Drug Trafficker Identification in Darknet Markets over Attributed Heterogeneous Information Network
- DOI:10.1145/3308558.3313537
- 发表时间:2019-05
- 期刊:
- 影响因子:0
- 作者:Yiming Zhang;Yujie Fan;Wei Song;Shifu Hou;Yanfang Ye;X. Li;Liang Zhao;C. Shi;Jiabin Wang;Qi Xiong
- 通讯作者:Yiming Zhang;Yujie Fan;Wei Song;Shifu Hou;Yanfang Ye;X. Li;Liang Zhao;C. Shi;Jiabin Wang;Qi Xiong
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Yanfang Ye其他文献
Classifying construction site photos for roof detection
对施工现场照片进行分类以进行屋顶检测
- DOI:
- 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Madhuri Siddula;F. Dai;Yanfang Ye;Jianping Fan - 通讯作者:
Jianping Fan
Efficacy and safety of cadonilimab (PD-1/CTLA-4 bispecific) in combination with chemotherapy in anti-PD-1-resistant recurrent or metastatic nasopharyngeal carcinoma: a single-arm, open-label, phase 2 trial
- DOI:
10.1186/s12916-025-03985-4 - 发表时间:
2025-03-11 - 期刊:
- 影响因子:8.300
- 作者:
Yaofei Jiang;Weixin Bei;Lin Wang;Nian Lu;Cheng Xu;Hu Liang;Liangru Ke;Yanfang Ye;Shuiqing He;Shuhui Dong;Qin Liu;Chuanrun Zhang;Xuguang Wang;Weixiong Xia;Chong Zhao;Ying Huang;Yanqun Xiang;Guoying Liu - 通讯作者:
Guoying Liu
THERMO-SENSITIVE SPIKELET DEFECTS 1 acclimatizes rice spikelet initiation and development to high temperature
热敏小穗缺陷 1 使水稻小穗的萌生和发育适应高温
- DOI:
10.1093/plphys/kiac576 - 发表时间:
2023 - 期刊:
- 影响因子:7.4
- 作者:
Zhengzheng Cai;Gang Wang;Jieqiong Li;Lan Kong;Weiqi Tang;Xuequn Chen;Xiaojie Qu;Chenchen Lin;Yulin Peng;Yang Liu;Zhanlin Deng;Yanfang Ye;Weiren Wu;Yuanlin Duan - 通讯作者:
Yuanlin Duan
ISMCS: An intelligent instruction sequence based malware categorization system
ISMCS:基于智能指令序列的恶意软件分类系统
- DOI:
- 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
Kaiming Huang;Yanfang Ye;Qinshan Jiang - 通讯作者:
Qinshan Jiang
Survival neural networks for time-to-event prediction in longitudinal study
用于纵向研究中事件发生时间预测的生存神经网络
- DOI:
10.1007/s10115-020-01472-1 - 发表时间:
2020-05 - 期刊:
- 影响因子:2.7
- 作者:
张健飞;陈黎飞;Yanfang Ye;郭躬德;Rongbo Chen;Alain Vanasse;王声瑞 - 通讯作者:
王声瑞
Yanfang Ye的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Yanfang Ye', 18)}}的其他基金
EAGER: A New Explainable Multi-objective Learning Framework for Personalized Dietary Recommendations against Opioid Misuse and Addiction
EAGER:一种新的可解释的多目标学习框架,用于针对阿片类药物滥用和成瘾的个性化饮食建议
- 批准号:
2334193 - 财政年份:2023
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
III: Small: A New Machine Learning Paradigm Towards Effective yet Efficient Foundation Graph Learning Models
III:小型:一种新的机器学习范式,实现有效且高效的基础图学习模型
- 批准号:
2321504 - 财政年份:2023
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
D-ISN: An AI-augmented Framework to Detect, Disrupt, and Dismantle Opioid Trafficking Networks
D-ISN:用于检测、破坏和拆除阿片类药物贩运网络的人工智能增强框架
- 批准号:
2146076 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
CAREER: Securing Cyberspace: Gaining Deep Insights into the Online Underground Ecosystem
职业:保护网络空间:深入了解在线地下生态系统
- 批准号:
2203261 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Continuing Grant
EAGER: An AI-driven Paradigm for Collective and Collaborative Community Resilience in the COVID-19 Era and Beyond
EAGER:COVID-19 时代及以后的集体和协作社区复原力的人工智能驱动范式
- 批准号:
2209814 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
III: Small: Mining Heterogeneous Network Built from Multiple Data Sources to Reduce Opioid Overdose Risks
III:小型:挖掘由多个数据源构建的异构网络以减少阿片类药物过量风险
- 批准号:
2214376 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
III: Medium: A Data-driven and AI-augmented Framework for Collaborative Decision Making to Combat Infectious Disease Outbreaks
III:媒介:数据驱动和人工智能增强的框架,用于对抗传染病爆发的协作决策
- 批准号:
2217239 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Continuing Grant
CICI: SSC: SciTrust: Enhancing Security for Modern Software Programming Cyberinfrastructure
CICI:SSC:SciTrust:增强现代软件编程网络基础设施的安全性
- 批准号:
2218762 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
EAGER: A Holistic Heterogeneous Temporal Graph Transformer Framework with Meta-learning to Combat Opioid Epidemic
EAGER:利用元学习对抗阿片类药物流行病的整体异构时间图转换器框架
- 批准号:
2203262 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
III: Medium: A Data-driven and AI-augmented Framework for Collaborative Decision Making to Combat Infectious Disease Outbreaks
III:媒介:数据驱动和人工智能增强的框架,用于对抗传染病爆发的协作决策
- 批准号:
2107172 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Continuing Grant
相似国自然基金
Bach1调控巨噬细胞极化重建肺泡上皮修复的免疫微环境参与SSc相关肺纤维化发病的机制研究
- 批准号:
- 批准年份:2024
- 资助金额:0 万元
- 项目类别:地区科学基金项目
CD84+单核巨噬细胞招募至肺组织形成niche促进SSc-ILD进展
- 批准号:82370073
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
基于LUBAC调控肺成纤维细胞铁死亡探究大麻素2型受体激动剂干预SSc-ILD的作用机制
- 批准号:2023JJ40582
- 批准年份:2023
- 资助金额:0.0 万元
- 项目类别:省市级项目
湿热海洋环境下3D打印FRP筋SSC梁长期抗剪性能及计算方法研究
- 批准号:52308288
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
VMP1棕榈酰化调控Sertoli细胞外泌体在SSC微环境中的作用和机制研究
- 批准号:
- 批准年份:2022
- 资助金额:54 万元
- 项目类别:面上项目
新型125ksi级低合金油井管钢的抗SSC性能及机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
Fstl1调控血管内皮细胞活化和炎症参与系统性硬化症相关间质性肺疾病(SSc-ILD)的作用机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:面上项目
苛刻H2S体系多晶型硫铁化合物对油套管钢SSC敏感性的影响机制研究
- 批准号:
- 批准年份:2021
- 资助金额:30 万元
- 项目类别:青年科学基金项目
低氧环境下温阳化浊通络方调控内皮细胞线粒体自噬和EndoMT改善SSc肺微血管损伤的作用机制
- 批准号:82074415
- 批准年份:2020
- 资助金额:56 万元
- 项目类别:面上项目
lnc001186/ssc-let-7i/TARBP2在C型产气荚膜梭菌感染性仔猪腹泻中的作用及机制研究
- 批准号:31960646
- 批准年份:2019
- 资助金额:40.0 万元
- 项目类别:地区科学基金项目
相似海外基金
A platelet-fibroblast axis connecting bioenergetics and metabolism in SSc-pulmonary arterial hypertension
连接 SSc 肺动脉高压生物能学和代谢的血小板-成纤维细胞轴
- 批准号:
10404145 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
SSCを用いた運動制御について:前腕屈筋における腱動態特性の解明
关于使用 SSC 进行运动控制:阐明前臂屈肌肌腱动态特性
- 批准号:
22K17683 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
CICI: SSC: Horizon: Secure Large-Scale Scientific Cloud Computing
CICI:SSC:地平线:安全大规模科学云计算
- 批准号:
2341138 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
A platelet-fibroblast axis connecting bioenergetics and metabolism in SSc-pulmonary arterial hypertension
连接 SSc 肺动脉高压生物能学和代谢的血小板-成纤维细胞轴
- 批准号:
10705673 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
Systemic sclerosis (SSc) vasculopathy: Improved clinical monitoring and treatment
系统性硬化症 (SSc) 血管病:改进临床监测和治疗
- 批准号:
10613002 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
SSC-CIVIC-PG TRACK B: Streamlining and Supporting Access to Public Assistance Programs in Louisiana
SSC-CIVIC-PG 轨道 B:简化和支持路易斯安那州的公共援助计划
- 批准号:
2228726 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant
Systemic sclerosis (SSc) vasculopathy: Improved clinical monitoring and treatment
系统性硬化症 (SSc) 血管病:改进临床监测和治疗
- 批准号:
10252115 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
Systemic sclerosis (SSc) vasculopathy: Improved clinical monitoring and treatment
系统性硬化症 (SSc) 血管病:改进临床监测和治疗
- 批准号:
10426267 - 财政年份:2022
- 资助金额:
$ 64.92万 - 项目类别:
Defining pathogenic B cell regulation and role in scleroderma-associated interstitial lung disease (SSc-ILD)
定义致病性 B 细胞调节及其在硬皮病相关间质性肺疾病 (SSc-ILD) 中的作用
- 批准号:
MR/V030108/1 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Fellowship
CICI: SSC: SciTrust: Enhancing Security for Modern Software Programming Cyberinfrastructure
CICI:SSC:SciTrust:增强现代软件编程网络基础设施的安全性
- 批准号:
2218762 - 财政年份:2021
- 资助金额:
$ 64.92万 - 项目类别:
Standard Grant