课题基金 / 基金详情

SaTC: CORE: Small: Black-Box Flaw Discovery in Web Authentication and Authorization Mechanisms

SaTC: CORE: Small: Black-Box Flaw Discovery in Web Authentication and Authorization Mechanisms
SaTC:核心:小:Web 身份验证和授权机制中的黑盒缺陷发现
批准号:
1934597
负责人:
Jason Polakis
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2023-09-30
关键词:

项目摘要

项目成果

Jason Polakis的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Technical advancements in modern smartphones and the widespread availability of Internet on-the-go have resulted in the world wide web becoming an inextricable part of everyday lives, pervading professional, social and personal activities. At the core of all this lies the ability to identify (i.e., authenticate) users and devices and allowing (i.e., authorizing) them to access accounts and sensitive resources. Flaws in existing authentication and authorization mechanisms allow cybercriminals as well as nation-state adversaries to gain illegal access, which can critically affect citizens, corporations, and government organizations alike. This project aims to better secure the world wide web through the analysis of prevalent and emerging authentication systems. The subsequent design of robust mechanisms that prevent illicit access from malicious entities will secure popular and critical web applications against current and unforeseen threats. The underlying research necessitates the development of novel techniques for analyzing web applications, and the proactive demonstration of novel attacks for guiding a data-driven design of more effective authentication mechanisms. The main research problems that the project seeks to study will form the basis for the training of both undergraduate and graduate students. The investigator is committed to working with minorities and underrepresented groups.The complexity of modern web applications and the intricacies of security mechanisms often result in flaws that expose users to significant security and privacy threats. This is exacerbated by the continuous evolution of the web ecosystem and new authentication and authorization mechanisms being deployed without prior analysis by the security community. This project aims to explore existing and emerging authentication and authorization systems and practices in the modern web ecosystem, and develop modular application-agnostic and protocol-independent techniques and frameworks that advance current capabilities for auditing modern web applications along these dimensions. This includes the development of multiple components that employ differential testing techniques, each designed to explore a different dimension of authentication and authorization by leveraging a unique attack vector, thus, enabling the automated black-box detection of flaws at an Internet-wide scale. These techniques and systems provide a holistic evaluation and treatment of the current web authentication landscape, enable the forecasting and prevention of future threats, and can facilitate research across multiple disciplines.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(22)
专著(0)
科研奖励(0)
会议论文
Escaping the Confines of Time: Continuous Browser Extension Fingerprinting Through Ephemeral Modifications
逃离时间的限制:通过短暂修改进行连续浏览器扩展指纹识别
DOI: 10.1145/3548606.3560576
发表时间: 2022
期刊: ACM SIGSAC Conference on Computer and Communications Security (CCS
影响因子: --
作者: [Solomos, Konstantinos, Ilia, Panagiotis, Nikiforakis, Nick, Polakis, Jason]
通讯作者: Polakis, Jason
Exploring the security and privacy risks of chatbots in messaging services
探索消息服务中聊天机器人的安全和隐私风险
DOI: 10.1145/3517745.3561433
发表时间: 2022
期刊: ACM Internet Measurement Conference (IMC
影响因子: --
作者: [Edu, Jide, Mulligan, Cliona, Pierazzi, Fabio, Polakis, Jason, Suarez-Tangil, Guillermo, Such, Jose]
通讯作者: Such, Jose
DOI: 10.1109/sp46214.2022.9833753
发表时间: 2022-05
期刊: 2022 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者: [Mohammad Ghasemisharif;Chris Kanich;Jason Polakis]
通讯作者: Mohammad Ghasemisharif;Chris Kanich;Jason Polakis
DOI: --
发表时间: 2022
期刊:
影响因子: --
作者: [Soroush Karami;Faezeh Kalantari;Mehrnoosh Zaeifi;Xavier J. Maso;Erik Trickel;Panagiotis Ilia;Yan Shoshitaishvili;Adam Doupé;Jason Polakis]
通讯作者: Soroush Karami;Faezeh Kalantari;Mehrnoosh Zaeifi;Xavier J. Maso;Erik Trickel;Panagiotis Ilia;Yan Shoshitaishvili;Adam Doupé;Jason Polakis
18
    CAREER: Tracking on the Modern Web: Novel Attacks, Measurements, and Defenses
    • 批准号:
      2143363
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $50.0万
    • 财政年份:
      2022
    • 负责人:
      Jason Polakis
    • 依托单位:
    Collaborative Research: SaTC: CORE: Medium: App-driven Web Browsing: Novel Risks, Vulnerabilities, and Defenses
    • 批准号:
      2211574
    • 项目类别:
      Standard Grant
    • 资助金额:
      $50.0万
    • 财政年份:
      2022
    • 负责人:
      Jason Polakis
    • 依托单位:
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: