CAREER: Building Secure Applications with Non-Static Information Flow Policies

职业:使用非静态信息流策略构建安全应用程序

基本信息

  • 批准号:
    1942851
  • 负责人:
  • 金额:
    $ 51.39万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2020
  • 资助国家:
    美国
  • 起止时间:
    2020-07-01 至 2023-11-30
  • 项目状态:
    已结题

项目摘要

Many security concerns in computer systems can be understood in terms of information flows: private and untrusted data, as well as data derived from them, should never flow to unintended channels in a computer system. In real-world systems, such security concerns typically change over time. For example, a payment system is allowed to use credit card details during a transaction, but it should not retain any record of credit card details once the transaction is complete. The dynamic nature of security concerns makes it challenging to build, verify and debug applications with non-static information flow policies. Consequently, the information flow policies of many security-sensitive applications are currently either unspecified at all, or being treated in an ad-hoc manner, resulting in large trusted computing bases and many security bugs in real applications. This award investigates an integrated research and education plan designed to transform the way that programmers understand, specify, verify and debug non-static information flow policies. It contains three components to address the key obstacles of building secure applications with non-static policy: (1) Dependent policy gives a simple, declarative and unified view of non-static policies, including dynamic policy, downgrading policy and erasure policy that are currently formalized and checked with unconnected semantic goals, (2) CONST, a constraint language for analyzing non-static policies in applications, and (3) An error diagnosis module that provides useful feedbacks when a program violates the specified non-static policy. This research will also develop and open-source a new toolchain that integrates the three novel components, making it feasible to specify, verify and debug real applications with non-static information flow policy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
计算机系统中的许多安全问题可以从信息流的角度来理解:私有的和不可信的数据,以及来自它们的数据,永远不应该流向计算机系统中意想不到的通道。在现实世界的系统中,这种安全问题通常会随着时间的推移而改变。例如,允许支付系统在交易过程中使用信用卡详细信息,但一旦交易完成,它不应该保留任何信用卡详细信息记录。安全问题的动态性使得使用非静态信息流策略构建、验证和调试应用程序具有挑战性。因此,目前许多对安全敏感的应用程序的信息流策略要么根本没有指定,要么以一种特殊的方式处理,从而导致实际应用程序中存在大量可信计算基础和许多安全错误。该奖项调查了一个集成的研究和教育计划,旨在改变程序员理解、指定、验证和调试非静态信息流策略的方式。它包含三个组件来解决使用非静态策略构建安全应用程序的主要障碍:(1)依赖策略提供了一个简单的、声明性的和统一的非静态策略视图,包括动态策略、降级策略和擦除策略,这些策略目前是形式化的,并使用不相关的语义目标进行检查;(2)CONST,一种用于分析应用程序中的非静态策略的约束语言;(3)错误诊断模块,当程序违反指定的非静态策略时提供有用的反馈。本研究还将开发并开源一个新的工具链,该工具链集成了这三个新组件,使得使用非静态信息流策略指定、验证和调试实际应用程序变得可行。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
SpecSafe: detecting cache side channels in a speculative world
  • DOI:
    10.1145/3485506
  • 发表时间:
    2021-10
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Robert Brotzman;Danfeng Zhang;M. Kandemir;Gang Tan
  • 通讯作者:
    Robert Brotzman;Danfeng Zhang;M. Kandemir;Gang Tan
Towards a General-Purpose Dynamic Information Flow Policy
迈向通用动态信息流政策
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Danfeng Zhang其他文献

Comparison of four quantitative techniques for monitoring microalgae disruption by low frequency ultrasound and acoustic energy efficiency.
通过低频超声和声能效率监测微藻破坏的四种定量技术的比较。
  • DOI:
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    11.4
  • 作者:
    Xiao Tan;Danfeng Zhang;Keshab Parajuli;Sanjina Upadhyay;Yuji Jiang;Zhipeng Duan
  • 通讯作者:
    Zhipeng Duan
Long Noncoding RNA LINC00941 Promotes Cell Proliferation and Invasion by Interacting with hnRNPK in Oral Squamous Cell Carcinoma
长非编码RNA LINC00941通过与口腔鳞状细胞癌中的hnRNPK相互作用促进细胞增殖和侵袭
  • DOI:
    10.1080/01635581.2022.2027473
  • 发表时间:
    2022-01
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jie Liu;Zhenxing Li;Ting Zhang;Chunhui Wang;Wen Chen;Danfeng Zhang;Junyu Wang
  • 通讯作者:
    Junyu Wang
Estrogen Responsive Gene MAST4 Regulates Myeloma Bone Disease
  • DOI:
    doi: 10.1002/jbmr.4507.
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
  • 作者:
    Yushan Cui;Fangfang Wang;Danfeng Zhang;Jingcao Huang;Yan Yang;Juan Xu;Yuhan Gao;Hong Ding;Ying Qu;Wenyan Zhang;Weiping Liu;Ling Pan;Li Zhang;Zhigang Liu;Ting Niu;Ting Liu;Yuhuan Zheng
  • 通讯作者:
    Yuhuan Zheng
Toward general diagnosis of static errors
静态错误的一般诊断
Decoding tumor microenvironment: EMT modulation in breast cancer metastasis and therapeutic resistance, and implications of novel immune checkpoint blockers
  • DOI:
    10.1016/j.biopha.2024.117714
  • 发表时间:
    2024-12-01
  • 期刊:
  • 影响因子:
  • 作者:
    Jie Yuan;Li Yang;Hua Zhang;Narasimha M. Beeraka;Danfeng Zhang;Qun Wang;Minghua Wang;Hemanth Vikram PR;Gautam Sethi;Geng Wang
  • 通讯作者:
    Geng Wang

Danfeng Zhang的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Danfeng Zhang', 18)}}的其他基金

Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
  • 批准号:
    2401496
  • 财政年份:
    2023
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Continuing Grant
CAREER: Building Secure Applications with Non-Static Information Flow Policies
职业:使用非静态信息流策略构建安全应用程序
  • 批准号:
    2401182
  • 财政年份:
    2023
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
  • 批准号:
    2207197
  • 财政年份:
    2022
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Continuing Grant
CRII: SHF: General, Precise and Accurate Fault Localization
CRII:SHF:通用、精准、准确的故障定位
  • 批准号:
    1566411
  • 财政年份:
    2016
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Standard Grant

相似国自然基金

基于支链淀粉building blocks构建优质BE突变酶定向修饰淀粉调控机制的研究
  • 批准号:
    31771933
  • 批准年份:
    2017
  • 资助金额:
    60.0 万元
  • 项目类别:
    面上项目

相似海外基金

Building public trust in technologies to secure Australia’s water future
建立公众对技术的信任,确保澳大利亚水的未来
  • 批准号:
    IM240100086
  • 财政年份:
    2024
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Mid-Career Industry Fellowships
SALIENT: Building a Secure and Resilient World: Research and Coordination Hub
突出:建立一个安全和有弹性的世界:研究和协调中心
  • 批准号:
    AH/Y505316/1
  • 财政年份:
    2024
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Research Grant
CAREER: Building Secure Applications with Non-Static Information Flow Policies
职业:使用非静态信息流策略构建安全应用程序
  • 批准号:
    2401182
  • 财政年份:
    2023
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Continuing Grant
NSF Convergence Accelerator Track G: Building Resilient and Secure 5G Systems (BRASS)
NSF 融合加速器轨道 G:构建弹性且安全的 5G 系统 (BRASS)
  • 批准号:
    2226555
  • 财政年份:
    2022
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Standard Grant
Roots of Resilience: building secure societies through preserving cultural heritage (Follow-On to Build Back Better AH/V006355/1)
复原力的根源:通过保护文化遗产建设安全的社会(重建更好的后续行动 AH/V006355/1)
  • 批准号:
    AH/W006979/1
  • 财政年份:
    2021
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Research Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
  • 批准号:
    2128607
  • 财政年份:
    2021
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Standard Grant
Collaborative Research: CISE-MSI: DP: CCF: SHF: MSI/HSI Research Capacity Building via Secure and Efficient Hardware Implementation of Cellular Computational Networks
合作研究:CISE-MSI:DP:CCF:SHF:通过安全高效的蜂窝计算网络硬件实现进行 MSI/HSI 研究能力建设
  • 批准号:
    2131070
  • 财政年份:
    2021
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Standard Grant
Collaborative Research: CISE-MSI: DP: CCF: SHF: MSI/HSI Research Capacity Building via Secure and Efficient Hardware Implementation of Cellular Computational Networks
合作研究:CISE-MSI:DP:CCF:SHF:通过安全高效的蜂窝计算网络硬件实现进行 MSI/HSI 研究能力建设
  • 批准号:
    2131163
  • 财政年份:
    2021
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Standard Grant
PFI-RP: Building a Modular, Reliable, Scalable, and Secure Internet of Things Infrastructure
PFI-RP:构建模块化、可靠、可扩展且安全的物联网基础设施
  • 批准号:
    1919159
  • 财政年份:
    2019
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Standard Grant
SCC: Building Safe and Secure Communities through Real-Time Edge Video Analytics
SCC:通过实时边缘视频分析构建安全可靠的社区
  • 批准号:
    1831795
  • 财政年份:
    2018
  • 资助金额:
    $ 51.39万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了