Collaborative Research: SaTC: TTP: Small: eSLIC: Enhanced Security Static Analysis for Detecting Insecure Configuration Scripts
Collaborative Research: SaTC: TTP: Small: eSLIC: Enhanced Security Static Analysis for Detecting Insecure Configuration Scripts
批准号:
2026869
负责人:
Akond Ashfaque Rahman
金额:
$24.47万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2022-10-31
中文摘要
信息技术(IT)组织使用配置脚本管理基础架构。配置脚本帮助从业者完成广泛的工作,包括云计算,科学研究和大规模数据分析。尽管配置脚本可以实现可扩展和快速的软件交付,但配置脚本中的安全漏洞(如硬编码密码)可能会导致数据泄露等安全和隐私问题。当前对配置脚本安全性的研究仅限于发现可检测到的问题类型、防止误报和启用可操作性-所有这些都禁止从业者对已识别的安全弱点采取行动,从而可能使计算系统对安全攻击敞开大门。该项目旨在解决这些限制。该项目的创新之处在于开发了技术和工具,可以自动检测使用广泛的语言开发的配置脚本中的安全漏洞,这些语言在工业中大量使用。该项目的影响涉及确保国家网络基础设施的安全,对下一代IT劳动力进行网络安全教育,以及通过招募代表性不足的社区扩大参与。 该项目将侧重于开发技术和工具,以自动检测使用工业中大量使用的各种语言开发的配置脚本中的安全弱点。本项目将研究三项主要任务。首先,应用定性分析,以确定一个全面的列表的安全弱点,多种配置脚本语言,并设计静态分析技术,自动识别每一类的安全弱点。接下来,基于语法的解析和机器学习技术被应用、评估并集成到派生的静态分析中,从而减少误报。最后,来自开源和专有领域的从业者的开发环境将被系统地挖掘,以生成可操作的警报和建议,这将使从业者能够修复安全漏洞。沿着这三项技术任务,将组织行业小组,来自行业的从业人员将对开发的技术和工具提供反馈。该项目的调查结果将分发给政府,行业和开源从业人员,以及正在学习与网络安全相关的研究生和本科生课程的学生。该项目预计将产生安全代码审查的最佳实践,自动化工具和安全配置脚本开发所必需的教育材料。作为一个过渡到实践(TTP)项目,它将促进与行业从业者的合作,从而实现全面、整体、对安全人员友好的安全静态分析,以确保配置脚本的开发和管理。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Information technology (IT) organizations manage infrastructure using configuration scripts. Configuration scripts help practitioners to accomplish a wide range of jobs, including cloud computing, scientific research, and large-scale data analytics. Even though configuration scripts enable scalable and rapid delivery of software, security weaknesses in configuration scripts, such as hard-coded passwords, can result in security and privacy problems such as data breaches. Current research of configuration script security is limited in finding types of problems that can be detected, preventing false positives, and enabling actionability—all of which prohibits practitioners to take actions on the identified security weaknesses, potentially leaving computing systems open to security attacks. The project aims to address these limitations. The project’s novelties are development of techniques and tools that will automatically detect security weaknesses in configuration scripts developed using a wide range of languages, heavily used in industry. The project's impacts are related to securing the national cyber infrastructure, educating the next generation IT workforce on cybersecurity, and broadening of participation through recruitment of underrepresented communities. The project will focus on the development of techniques and tools that will automatically detect security weaknesses in configuration scripts developed using a wide range of languages heavily used in industry. Three main tasks will be investigated for this project. First, qualitative analysis is applied in order to determine a comprehensive list of security weaknesses for multiple configuration script languages, and devise static analysis techniques for automatically identifying each category of security weakness. Next, grammar-based parsing and machine learning techniques are applied, evaluated, and integrated into the derived static analysis so that false positives are reduced. Finally, the development context of practitioners from the open source and proprietary domain will be systematically mined to generate actionable alerts and suggestions, which will enable practitioners to fix security weaknesses. Along with the three technical tasks, industry panels will be organized, where practitioners from industry will give feedback on the developed techniques and tools. Findings from the project will be disseminated to government, industry and open source practitioners, as well as to students who are learning about configuration management in graduate and undergraduate level courses related to cybersecurity. The project is expected to generate best practices for security code review, automated tools, and education materials essential to secure configuration script development. As a transition to practice (TTP) project, it will facilitate collaboration with industry practitioners, so that a comprehensive, holistic, practitioner-friendly security static analysis is achieved to secure configuration script development and management.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(14)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
How Do Students Feel About Automated Security Static Analysis Exercises?
学生对自动安全静态分析练习有何看法?
DOI:
10.1109/fie49875.2021.9637201
发表时间:
2021
期刊:
2021 IEEE Frontiers in Education Conference (FIE
影响因子:
--
作者:
[Rahman, Akond, Shahriar, Hossain, Bose, Dibyendu Brinto]
通讯作者:
Bose, Dibyendu Brinto
Lessons from Research to Practice on Writing Better Quality Puppet Scripts
编写更高质量的木偶脚本的研究和实践的经验教训
DOI:
10.1109/saner53432.2022.00019
发表时间:
2022
期刊:
Evolution and Reengineering (SANER
影响因子:
--
作者:
[Rahman, Akond, Sharma, Tushar]
通讯作者:
Sharma, Tushar
DOI:
10.1109/compsac51774.2021.00105
发表时间:
2021
期刊:
and Applications Conference (COMPSAC
影响因子:
--
作者:
[Cottrell, Kaitlyn, Bose, Dibyendu Brinto, Shahriar, Hossain, Rahman, Akond]
通讯作者:
Rahman, Akond
Different Kind of Smells: Security Smells in Infrastructure as Code Scripts
不同类型的气味:基础设施中的安全气味作为代码脚本
DOI:
10.1109/msec.2021.3065190
发表时间:
2021
期刊:
IEEE Security & Privacy
影响因子:
1.9
作者:
[Rahman, Akond, Williams, Laurie]
通讯作者:
Williams, Laurie
Vision for a secure Elixir ecosystem: an empirical study of vulnerabilities in Elixir programs
安全 Elixir 生态系统的愿景:Elixir 程序漏洞的实证研究
DOI:
10.1145/3476883.3520204
发表时间:
2022
期刊:
2022 ACM Southeast Conference
影响因子:
--
作者:
[Bose, Dibyendu Brinto, Cottrell, Kaitlyn, Rahman, Akond]
通讯作者:
Rahman, Akond
共 14 条
SHF: Small: Resilient Operations for Deployment Units Used in Container Orchestration
-
批准号:2312321
-
项目类别:Standard Grant
-
资助金额:$55.33万
-
财政年份:2023
-
负责人:Akond Ashfaque Rahman
-
依托单位:
Authentic Learning Modules for DevOps Security Education
-
批准号:2310179
-
项目类别:Standard Grant
-
资助金额:$15.4万
-
财政年份:2023
-
负责人:Akond Ashfaque Rahman
-
依托单位:
Authentic Learning Modules for DevOps Security Education
-
批准号:2209636
-
项目类别:Standard Grant
-
资助金额:$15.4万
-
财政年份:2022
-
负责人:Akond Ashfaque Rahman
-
依托单位:
Collaborative Research: SaTC: TTP: Small: eSLIC: Enhanced Security Static Analysis for Detecting Insecure Configuration Scripts
-
批准号:2247141
-
项目类别:Standard Grant
-
资助金额:$24.47万
-
财政年份:2022
-
负责人:Akond Ashfaque Rahman
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: