CAREER: Amplifying Developer-Written Tests for Code Injection Vulnerability Detection
CAREER: Amplifying Developer-Written Tests for Code Injection Vulnerability Detection
批准号:
1844880
负责人:
Jonathan Bell
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-05-01 至 2020-12-31
中文摘要
代码注入漏洞是一类越来越经常被利用的安全漏洞,包括备受瞩目的2017年Equifax漏洞以及最近对我国选举和金融系统的许多攻击。这些漏洞非常难以检测,并且没有现有的自动化技术来保护关键软件免受这些危险缺陷的影响。该项目正在开发新的和变革性的方法,用于检测复杂的大型系统中的代码注入漏洞。高可靠性软件和通用软件之间的界限越来越模糊,因为现在几乎任何不安全的软件都可能产生严重的经济后果。因此,该项目正在开发,验证和传播更好的工具,任何工程师都可以在测试过程中使用这些工具来检测应用程序中的代码注入漏洞(而不需要专门的安全知识)。为了检测这些漏洞,该项目利用了人类开发人员和自动动态程序分析的综合能力,将现有的测试套件与动态分析相结合。给定一个现有的(可能是低质量的)开发人员编写的测试套件,该项目同时增加了每个测试的深度(为每个测试添加新的安全相关检查)和每个测试的广度(确保测试套件彻底验证每个安全检查)。当其中一个测试表明可能存在漏洞时,该工具将生成一个证明漏洞利用的测试用例,该测试用例证明漏洞利用的存在,并允许开发人员理解和调试问题,防止它逃逸到野外。这些工具将经过精心设计,可供日常软件工程师采用,而不需要程序分析的专业知识,易于与现有工具和持续集成基础设施集成。该项目涉及本科生和研究生的研究。该项目产生的所有软件和课程将免费公开;产生的工具将公开传播,预计将对其他测试和安全研究人员有用。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Code injection vulnerabilities are a class of security vulnerabilities that have been exploited increasingly often, including in the high-profile 2017 Equifax breach as well as in many recent attacks on our country's election and financial systems. These vulnerabilities are very tricky to detect, and there are no existing automated techniques to protect critical software from being released with these dangerous flaws. This project is developing new and transformative approaches for detecting code injection vulnerabilities in complex, large-scale systems. The line between high-assurance and general-purpose software is increasingly blurred, as nowadays nearly any insecure software can have severe economic consequences. Hence, this project is developing, validating and disseminating better tools that any engineer can use to detect code injection vulnerabilities in their applications during testing (without requiring specialized security knowledge).To detect these vulnerabilities, this project harnesses the combined power of both human developers and automated dynamic program analysis, combining existing test suites with dynamic dataflow analysis. Given an existing (and perhaps low quality) developer-written test suite, this project simultaneously increases the depth of each test (adding new security-related checks to each test) and the breadth of each test (ensuring that the test suite thoroughly validates each security check). When one of these tests suggests that there might be a vulnerability, the tool will generate a proof-of-exploit test case that demonstrates the existence of the exploit and allows developers to understand and debug the issue, preventing it from escaping to the wild. The tools will be carefully designed to be adoptable by everyday software engineers without requiring specialized knowledge of program analysis, with easy integration with existing tooling and continuous integration infrastructure. This project involves undergraduate and graduate students in research. All software and curricula resulting from this project will be freely and publicly available; the resulting tools will be publicly disseminated and are expected to be useful for other testing and security researchers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3377811.3380326
发表时间:
2020-06
期刊:
2020 IEEE/ACM 42nd International Conference on Software Engineering (ICSE)
影响因子:
--
作者:
[Katherine Hough;G. B. Welearegai;Christian Hammer;Jonathan Bell]
通讯作者:
Katherine Hough;G. B. Welearegai;Christian Hammer;Jonathan Bell
Travel: NSF Student Travel Grant for 2024 ACM/IEEE International Conference on Software Engineering
-
批准号:2413092
-
项目类别:Standard Grant
-
资助金额:$3.0万
-
财政年份:2024
-
负责人:Jonathan Bell
-
依托单位:
CAREER: Amplifying Developer-Written Tests for Code Injection Vulnerability Detection
-
批准号:2100015
-
项目类别:Continuing Grant
-
资助金额:$40.48万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
Collaborative Research: RAPID: Virtual Conference Platform
-
批准号:2035003
-
项目类别:Standard Grant
-
资助金额:$3.02万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
SHF: Medium: Collaborative Research: Enhancing Continuous Integration Testing for the Open-Source Ecosystem
-
批准号:2100037
-
项目类别:Continuing Grant
-
资助金额:$32.84万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
Collaborative Research: RAPID: Virtual Conference Platform
-
批准号:2055193
-
项目类别:Standard Grant
-
资助金额:$0.79万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
NSF Student Travel Grant for 2019 ACM SIGPLAN Conference on Systems, Programming, Languages and Applications: Software for Humanity (SPLASH)
-
批准号:1940760
-
项目类别:Standard Grant
-
资助金额:$3.0万
-
财政年份:2019
-
负责人:Jonathan Bell
-
依托单位:
SHF: Medium: Collaborative Research: Enhancing Continuous Integration Testing for the Open-Source Ecosystem
-
批准号:1763822
-
项目类别:Continuing Grant
-
资助金额:$39.96万
-
财政年份:2018
-
负责人:Jonathan Bell
-
依托单位:
NSF Student Travel Grant for 2018 ACM SIGPLAN Conference on Systems, Programming, Languages and Applications: Software for Humanity (SPLASH)
-
批准号:1838986
-
项目类别:Standard Grant
-
资助金额:$3.0万
-
财政年份:2018
-
负责人:Jonathan Bell
-
依托单位:
Radical Democrats: Ideology and Political Change in California in the Post-World War Two Era
-
批准号:AH/G002681/1
-
项目类别:Research Grant
-
资助金额:$2.33万
-
财政年份:2009
-
负责人:Jonathan Bell
-
依托单位:
REU Summer Program in Computational Biology
-
批准号:0354034
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Jonathan Bell
-
依托单位:
Scientific Computing Research Environments for the Mathematical Sciences - SCREMS
-
批准号:0215373
-
项目类别:Standard Grant
-
资助金额:$7.5万
-
财政年份:2002
-
负责人:Jonathan Bell
-
依托单位:
Some Direct and Inverse Problems in Receptor Neurodynamics
-
批准号:0196480
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2000
-
负责人:Jonathan Bell
-
依托单位:
Some Direct and Inverse Problems in Receptor Neurodynamics
-
批准号:9706307
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:1997
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Mathematical Modeling of Transductions of Somatosensory Stimuli
-
批准号:9404517
-
项目类别:Continuing Grant
-
资助金额:$17.9万
-
财政年份:1994
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Mathematical Modeling in Somatosensory Physiology
-
批准号:9101498
-
项目类别:Continuing Grant
-
资助金额:$5.85万
-
财政年份:1991
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Analysis of Biomathematical Models inSensory Physiology
-
批准号:8801502
-
项目类别:Standard Grant
-
资助金额:$6.98万
-
财政年份:1988
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences Research Equipment
-
批准号:8703673
-
项目类别:Standard Grant
-
资助金额:$3.6万
-
财政年份:1987
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Mathematical Modelling of Hearing and Other Sensory Systems
-
批准号:8615739
-
项目类别:Standard Grant
-
资助金额:$1.63万
-
财政年份:1987
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Modelling Transduction in Hair Cells
-
批准号:8502307
-
项目类别:Continuing Grant
-
资助金额:$3.63万
-
财政年份:1985
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Myelinated Axon Models
-
批准号:8301724
-
项目类别:Standard Grant
-
资助金额:$3.12万
-
财政年份:1983
-
负责人:Jonathan Bell
-
依托单位:
海外基金