课题基金 / 基金详情

SHF: Small: Detecting the 1%: Growing the Science of Vulnerability Detection

SHF: Small: Detecting the 1%: Growing the Science of Vulnerability Detection
SHF:%20小型:%20检测%20the%201%:%20增长%20the%20科学%20of%20漏洞%20检测
批准号:
1909516
负责人:
Laurie Williams
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2023-09-30

项目摘要

项目成果

Laurie Williams的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Daily, news reports reveal the latest increasingly sophisticated security attacks that threaten our national security, our cyber infrastructure, our health, our finances, our children, and democracy itself. Yet, studies indicate that discovered vulnerabilities can be very damaging but are rare, appearing in about 1-4% of software files. Finding vulnerabilities has been described as "searching for a needing in a haystack." But, protecting the American people, the American homeland, and the American way of life means that software organizations need to detect vulnerabilities so that they can be fixed before the product is used by customers, which makes the vulnerabilities available to attackers. This project will perform studies to understand the characteristics and location of the most risky vulnerabilities so that special effort can be spent and automated tools can be developed to detect the vulnerabilities. The work will improve the ability of software organizations to produce secure software products so that people can rely upon computer systems to perform critical functions and to process, store, and communicate sensitive information securely. The research project also involves the mentoring of PhD students and innovation in software-security teaching for undergraduate and graduate students.Making informed decisions on what code to review and test can improve a team's ability to find and remove more vulnerabilities. Therefore, security engineers looking to prioritize security inspection and testing efforts may be better served by vulnerability-based detection techniques and tools and effective vulnerability prediction. The goal of this project is to aid software practitioners in detecting exploitable vulnerabilities through empirical study of the characteristics of vulnerabilities and through the development and evaluation of prediction models enhanced with recent research from artificial intelligence. The project will explore characteristics of vulnerabilities with a focus on those that pose the highest security risk. Knowledge about the fundamental characteristics of vulnerabilities can be used in the development of vulnerability-focused tools to aid teams in effectively and efficiently detecting vulnerabilities. The fundamental vulnerability characteristics can also be used to develop novel metrics and methods for building vulnerability prediction models enhanced with recent research from artificial intelligence. The project team will also provide a testbed and test data to help other security researchers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3524842.3528437
发表时间: 2022-03
期刊: 2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR)
影响因子: --
作者: [Rui Shu;Tianpei Xia;Laurie A. Williams;T. Menzies]
通讯作者: Rui Shu;Tianpei Xia;Laurie A. Williams;T. Menzies
DOI: 10.1007/s10664-020-09906-8
发表时间: 2019-11
期刊: Empirical Software Engineering
影响因子: 4.1
作者: [Rui Shu;Tianpei Xia;Jianfeng Chen;L. Williams;T. Menzies]
通讯作者: Rui Shu;Tianpei Xia;Jianfeng Chen;L. Williams;T. Menzies
Improving Vulnerability Inspection Efficiency Using Active Learning
利用主动学习提高漏洞检查效率
DOI: 10.1109/tse.2019.2949275
发表时间: 2019
期刊: IEEE Transactions on Software Engineering
影响因子: 7.4
作者: [Yu, Zhe, Theisen, Christopher, Williams, Laurie, Menzies, Tim]
通讯作者: Menzies, Tim
Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard
围绕 OWASP 应用程序安全验证标准构建全面的软件安全课程
DOI: --
发表时间: 2021
期刊: Proceedings of the International Conference on Software Engineering
影响因子: --
作者: [Elder, Sarah, Zahan, Nusrat, Kozarev, Val, Shu, Rui, Menzies, Tim, Williams, Laurie]
通讯作者: Williams, Laurie
Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain
  • 批准号:
    2207008
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $634.45万
  • 财政年份:
    2022
  • 负责人:
    Laurie Williams
  • 依托单位:
SaTC: CORE: Small: Risk-based Secure Checked-in Credential Reduction for Software Development
  • 批准号:
    2055554
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.97万
  • 财政年份:
    2021
  • 负责人:
    Laurie Williams
  • 依托单位:
Collaborative Research: DarkSide-20k: A Global Program for the Direct Detection of Dark Matter Using Low-Radioactivity Argon
  • 批准号:
    1812480
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2018
  • 负责人:
    Laurie Williams
  • 依托单位:
EAGER: Cognitive modeling of strategies for dealing with errors in mobile touch interfaces
  • 批准号:
    1451172
  • 项目类别:
    Standard Grant
  • 资助金额:
    $28.11万
  • 财政年份:
    2014
  • 负责人:
    Laurie Williams
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: