CAREER: Amplifying Developer-Written Tests for Code Injection Vulnerability Detection
CAREER: Amplifying Developer-Written Tests for Code Injection Vulnerability Detection
批准号:
1844880
负责人:
Jonathan Bell
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-05-01 至 2020-12-31
中文摘要
代码注入漏洞是一类越来越频繁地被利用的安全漏洞,包括在2017年备受瞩目的Equifax漏洞以及最近对我国选举和金融系统的许多攻击中。这些漏洞很难检测,而且现有的自动化技术不能保护关键软件不被发布时带有这些危险的漏洞。该项目正在开发新的、变革性的方法来检测复杂、大规模系统中的代码注入漏洞。高保证软件和通用软件之间的界限越来越模糊,因为现在几乎任何不安全的软件都可能产生严重的经济后果。因此,该项目正在开发、验证和传播更好的工具,任何工程师都可以使用这些工具在测试过程中检测应用程序中的代码注入漏洞(不需要专门的安全知识)。为了检测这些漏洞,该项目利用人工开发人员和自动化动态程序分析的组合力量,将现有的测试套件与动态数据流分析相结合。给定现有的(可能是低质量的)开发人员编写的测试套件,该项目同时增加了每个测试的深度(向每个测试添加新的与安全相关的检查)和每个测试的广度(确保测试套件彻底验证每个安全检查)。当这些测试之一表明可能存在漏洞时,该工具将生成一个漏洞利用证明测试用例,该测试用例可以证明漏洞的存在,并允许开发人员了解和调试该问题,防止其逃脱。这些工具将经过精心设计,可供日常软件工程师采用,不需要程序分析方面的专业知识,可与现有工具和持续集成基础设施轻松集成。这个项目涉及本科生和研究生参与研究。这个项目产生的所有软件和课程都将是免费和公开的;产生的工具将被公开传播,并有望对其他测试和安全研究人员有用。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Code injection vulnerabilities are a class of security vulnerabilities that have been exploited increasingly often, including in the high-profile 2017 Equifax breach as well as in many recent attacks on our country's election and financial systems. These vulnerabilities are very tricky to detect, and there are no existing automated techniques to protect critical software from being released with these dangerous flaws. This project is developing new and transformative approaches for detecting code injection vulnerabilities in complex, large-scale systems. The line between high-assurance and general-purpose software is increasingly blurred, as nowadays nearly any insecure software can have severe economic consequences. Hence, this project is developing, validating and disseminating better tools that any engineer can use to detect code injection vulnerabilities in their applications during testing (without requiring specialized security knowledge).To detect these vulnerabilities, this project harnesses the combined power of both human developers and automated dynamic program analysis, combining existing test suites with dynamic dataflow analysis. Given an existing (and perhaps low quality) developer-written test suite, this project simultaneously increases the depth of each test (adding new security-related checks to each test) and the breadth of each test (ensuring that the test suite thoroughly validates each security check). When one of these tests suggests that there might be a vulnerability, the tool will generate a proof-of-exploit test case that demonstrates the existence of the exploit and allows developers to understand and debug the issue, preventing it from escaping to the wild. The tools will be carefully designed to be adoptable by everyday software engineers without requiring specialized knowledge of program analysis, with easy integration with existing tooling and continuous integration infrastructure. This project involves undergraduate and graduate students in research. All software and curricula resulting from this project will be freely and publicly available; the resulting tools will be publicly disseminated and are expected to be useful for other testing and security researchers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3377811.3380326
发表时间:
2020-06
期刊:
2020 IEEE/ACM 42nd International Conference on Software Engineering (ICSE)
影响因子:
--
作者:
[Katherine Hough;G. B. Welearegai;Christian Hammer;Jonathan Bell]
通讯作者:
Katherine Hough;G. B. Welearegai;Christian Hammer;Jonathan Bell
Travel: NSF Student Travel Grant for 2024 ACM/IEEE International Conference on Software Engineering
-
批准号:2413092
-
项目类别:Standard Grant
-
资助金额:$3.0万
-
财政年份:2024
-
负责人:Jonathan Bell
-
依托单位:
CAREER: Amplifying Developer-Written Tests for Code Injection Vulnerability Detection
-
批准号:2100015
-
项目类别:Continuing Grant
-
资助金额:$40.48万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
Collaborative Research: RAPID: Virtual Conference Platform
-
批准号:2035003
-
项目类别:Standard Grant
-
资助金额:$3.02万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
SHF: Medium: Collaborative Research: Enhancing Continuous Integration Testing for the Open-Source Ecosystem
-
批准号:2100037
-
项目类别:Continuing Grant
-
资助金额:$32.84万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
Collaborative Research: RAPID: Virtual Conference Platform
-
批准号:2055193
-
项目类别:Standard Grant
-
资助金额:$0.79万
-
财政年份:2020
-
负责人:Jonathan Bell
-
依托单位:
NSF Student Travel Grant for 2019 ACM SIGPLAN Conference on Systems, Programming, Languages and Applications: Software for Humanity (SPLASH)
-
批准号:1940760
-
项目类别:Standard Grant
-
资助金额:$3.0万
-
财政年份:2019
-
负责人:Jonathan Bell
-
依托单位:
SHF: Medium: Collaborative Research: Enhancing Continuous Integration Testing for the Open-Source Ecosystem
-
批准号:1763822
-
项目类别:Continuing Grant
-
资助金额:$39.96万
-
财政年份:2018
-
负责人:Jonathan Bell
-
依托单位:
NSF Student Travel Grant for 2018 ACM SIGPLAN Conference on Systems, Programming, Languages and Applications: Software for Humanity (SPLASH)
-
批准号:1838986
-
项目类别:Standard Grant
-
资助金额:$3.0万
-
财政年份:2018
-
负责人:Jonathan Bell
-
依托单位:
Radical Democrats: Ideology and Political Change in California in the Post-World War Two Era
-
批准号:AH/G002681/1
-
项目类别:Research Grant
-
资助金额:$2.33万
-
财政年份:2009
-
负责人:Jonathan Bell
-
依托单位:
REU Summer Program in Computational Biology
-
批准号:0354034
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Jonathan Bell
-
依托单位:
Scientific Computing Research Environments for the Mathematical Sciences - SCREMS
-
批准号:0215373
-
项目类别:Standard Grant
-
资助金额:$7.5万
-
财政年份:2002
-
负责人:Jonathan Bell
-
依托单位:
Some Direct and Inverse Problems in Receptor Neurodynamics
-
批准号:0196480
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:2000
-
负责人:Jonathan Bell
-
依托单位:
Some Direct and Inverse Problems in Receptor Neurodynamics
-
批准号:9706307
-
项目类别:Standard Grant
-
资助金额:$9.0万
-
财政年份:1997
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Mathematical Modeling of Transductions of Somatosensory Stimuli
-
批准号:9404517
-
项目类别:Continuing Grant
-
资助金额:$17.9万
-
财政年份:1994
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Mathematical Modeling in Somatosensory Physiology
-
批准号:9101498
-
项目类别:Continuing Grant
-
资助金额:$5.85万
-
财政年份:1991
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Analysis of Biomathematical Models inSensory Physiology
-
批准号:8801502
-
项目类别:Standard Grant
-
资助金额:$6.98万
-
财政年份:1988
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences Research Equipment
-
批准号:8703673
-
项目类别:Standard Grant
-
资助金额:$3.6万
-
财政年份:1987
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Mathematical Modelling of Hearing and Other Sensory Systems
-
批准号:8615739
-
项目类别:Standard Grant
-
资助金额:$1.63万
-
财政年份:1987
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Modelling Transduction in Hair Cells
-
批准号:8502307
-
项目类别:Continuing Grant
-
资助金额:$3.63万
-
财政年份:1985
-
负责人:Jonathan Bell
-
依托单位:
Mathematical Sciences: Myelinated Axon Models
-
批准号:8301724
-
项目类别:Standard Grant
-
资助金额:$3.12万
-
财政年份:1983
-
负责人:Jonathan Bell
-
依托单位:
海外基金