课题基金 / 基金详情

EAGER: Finding Semantic Security Bugs with Pseudo-Oracle Testing

EAGER: Finding Semantic Security Bugs with Pseudo-Oracle Testing
EAGER:通过伪 Oracle 测试查找语义安全漏洞
批准号:
1842456
负责人:
Baishakhi Ray
金额:
$20.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-10-01 至 2020-09-30

项目摘要

项目成果

Baishakhi Ray的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Semantic security bugs cause serious vulnerabilities across a wide range of software. For example, in a recent incident, attackers exploited a semantic security bug in Apache Struts to steal sensitive personal data of up to 143 million customers from Equifax servers. In fact, such vulnerabilities are quite common in practice. The total number of Common Vulnerabilities and Exposure Identifiers (CVEs) assigned to different types of semantic security bugs exceeds 2,000 just this year alone. The goal of this project is to improve security and reliability by automatically detecting such semantic vulnerabilities in critical software. Automatically detecting these bugs is hard because unlike crash bugs they may not show any obvious side effects. In contrast, semantic security bugs (e.g., bypassing security checks, gaining access to sensitive information, escalating privileges) usually result from violation of high-level safety/security specifications which, in practice, are rarely written formally. This project will investigate whether learning domain-specific metamorphic relations can help in detecting semantic bugs. In Software Engineering, metamorphic relations, which correlate outputs from multiple executions of a program with different inputs, have been shown to be effective at finding simple functional bugs. While metamorphic relations have promise to detect semantic security vulnerabilities, they are not able to detect semantic security vulnerabilities in their current form, as security properties cannot be expressed as simple input-output based properties. The approach uses pseudo-oracle testing techniques like differential testing and metamorphic testing. The project will use targeted path exploration techniques, with automata-learning algorithms to discover metamorphic testing rules. The project will learn how the semantics of metamorphic relations can be augmented to detect semantic security bugs. The research envisions a unified framework based on pseudo-random Oracles, which can automatically detect semantic security bugs without the need for manually creating formal specifications to compare program behaviors of related executions. As a first step, the objective of this EAGER project is to empirically measure whether there is a comprehensive range of semantically expressive pseudo-oracle relations that can detect semantic security vulnerabilities.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2020
期刊:
影响因子: --
作者: [Aditya Sridhar;Guanming Qiao;G. Kaiser]
通讯作者: Aditya Sridhar;Guanming Qiao;G. Kaiser
Testing DNN Image Classifier for Confusion & Bias Errors
测试 DNN 图像分类器的混淆情况
DOI: --
发表时间: 2020
期刊: 42nd International Conference on Software Engineering
影响因子: --
作者: [Tian, Yuchi, Zhong, Ziyuan, Ordonez, Vicente, Kaiser, Gail, Ray, Baishakhi]
通讯作者: Ray, Baishakhi
Side Channel Attack on Smartphone Sensors to Infer Gender of the User
对智能手机传感器进行侧信道攻击以推断用户性别
DOI: --
发表时间: 2019
期刊: 17th ACM Conference on Embedded Networked Sensor Systems (SenSys
影响因子: --
作者: [Singh, Shirish, Shila, Devu Manikantan, Kaiser, Gail]
通讯作者: Kaiser, Gail
Binary Quilting to Generate Patched Executables without Compilation
二进制绗缝以生成修补的可执行文件而无需编译
DOI: --
发表时间: 2020
期刊: 2020 ACM Workshop on Forming an Ecosystem Around Software Transformation
影响因子: --
作者: [Saieva, Anthony, Kaiser, Gail]
通讯作者: Kaiser, Gail
7
    Collaborative Research: SHF: Medium: Learning Semantics of Code To Automate Software Assurance Tasks
    • 批准号:
      2313055
    • 项目类别:
      Standard Grant
    • 资助金额:
      $66.6万
    • 财政年份:
      2023
    • 负责人:
      Baishakhi Ray
    • 依托单位:
    Collaborative Research: SHF: Medium: Causal Performance Debugging for Highly-Configurable Systems
    • 批准号:
      2107405
    • 项目类别:
      Standard Grant
    • 资助金额:
      $37.3万
    • 财政年份:
      2021
    • 负责人:
      Baishakhi Ray
    • 依托单位:
    Workshop on Deep Learning and Software Engineering
    • 批准号:
      1945999
    • 项目类别:
      Standard Grant
    • 资助金额:
      $4.99万
    • 财政年份:
      2019
    • 负责人:
      Baishakhi Ray
    • 依托单位:
    TWC: Small: Collaborative: Automated Detection and Repair of Error Handling Bugs in SSL/TLS Implementations
    • 批准号:
      1946068
    • 项目类别:
      Standard Grant
    • 资助金额:
      $4.31万
    • 财政年份:
      2019
    • 负责人:
      Baishakhi Ray
    • 依托单位:
    海外基金