Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security

协作研究:SaTC:核心:中:重新思考安全性模糊测试

基本信息

  • 批准号:
    2031390
  • 负责人:
  • 金额:
    $ 59.98万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2020
  • 资助国家:
    美国
  • 起止时间:
    2020-10-01 至 2024-09-30
  • 项目状态:
    已结题

项目摘要

In software, a vulnerability is a flaw in the code that can be exploited by a malicious actor to perform unauthorized activities or change the behavior of the software. Although a topic heavily studied by security researchers, finding software vulnerabilities is becoming increasingly challenging because the software widely used in day-to-day life is growing larger and more complicated. This project addresses this challenge by rethinking a classic technique called fuzzing for finding vulnerabilities from large software. The high-level idea of fuzzing is to create a large number of random inputs to run software and in turn trigger vulnerabilities. The novelties of this project are the new approaches, techniques, and tools that revolutionize fuzzing and make the nearly random testing process more intelligent and targeted. This way, this project will enhance security of various types of widely used software, ranging from web browsers to server-side programs.To that end, this project is investigating vulnerability-coverage-driven fuzzing. Existing fuzzing techniques primarily followed an approach called code-coverage-driven fuzzing, motivated by the belief that code coverage and vulnerability finding are strongly correlated. Challenging this widely held belief, this project shows that code coverage has weaker-than-expected ties with vulnerabilities and code-coverage-driven fuzzing is not well suited for vulnerability finding. Pioneering vulnerability-coverage-driven fuzzing, this project invents a series of novel techniques to (1) obtain feedback on vulnerability coverage (2) prioritize test inputs that can reach more vulnerabilities and (3) maximize the chance to trigger vulnerabilities reached by the test inputs. This project also produces new metrics, new benchmarks, and new frameworks for comprehensively evaluating the use of fuzzing for vulnerability finding. With the investigators' experience in research of software security and system security, this project provides a group of education, training, and research opportunities for both undergraduate and graduate students. Through industry outreach, the investigators pursue technology transfers and raise the awareness of software security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在软件中,漏洞是代码中的缺陷,恶意行为者可以利用该缺陷来执行未经授权的活动或更改软件的行为。尽管安全研究人员对此进行了大量研究,但由于日常生活中广泛使用的软件变得越来越大和越来越复杂,查找软件漏洞变得越来越具有挑战性。这个项目通过重新思考一种名为Fuzing的经典技术来解决这一挑战,该技术用于从大型软件中查找漏洞。模糊的高级思想是创建大量随机输入来运行软件,进而触发漏洞。这个项目的新颖性在于新的方法、技术和工具,这些方法、技术和工具彻底改变了模糊,并使几乎随机的测试过程更加智能和有针对性。这样,该项目将增强各种类型的广泛使用的软件的安全性,从Web浏览器到服务器端程序。为此,该项目正在研究漏洞覆盖驱动的模糊。现有的模糊技术主要遵循一种称为代码覆盖驱动模糊的方法,其动机是代码覆盖和漏洞查找紧密相关。该项目挑战了这一普遍持有的信念,表明代码覆盖与漏洞的联系弱于预期,代码覆盖驱动的模糊不太适合漏洞查找。该项目开创了漏洞覆盖驱动模糊的先河,发明了一系列新技术来(1)获得漏洞覆盖的反馈(2)确定可触及更多漏洞的测试输入的优先顺序,以及(3)最大限度地增加触发测试输入触及的漏洞的机会。该项目还产生了新的指标、新的基准和新的框架,用于全面评估Fuzing用于漏洞查找的使用情况。凭借研究人员在软件安全和系统安全方面的研究经验,本项目为本科生和研究生提供了一批教育、培训和研究机会。通过行业外展,调查人员寻求技术转让并提高软件安全意识。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Engin Kirda其他文献

PoX: Protecting users from malicious Facebook applications
  • DOI:
    10.1016/j.comcom.2012.04.016
  • 发表时间:
    2012-07-01
  • 期刊:
  • 影响因子:
  • 作者:
    Manuel Egele;Andreas Moser;Christopher Kruegel;Engin Kirda
  • 通讯作者:
    Engin Kirda
Chromosome
染色体
  • DOI:
    10.1007/978-1-4419-5906-5_1259
  • 发表时间:
    2011
  • 期刊:
  • 影响因子:
    3.5
  • 作者:
    Lars R. Knudsen;Gregor Leander;Friedrich L. Bauer;Christophe De Cannière;Christophe De Cannière;Christophe Petit;Jean;Bart Preneel;Carlisle M. Adams;Anton Stiglic;Alexander W. Dent;R. Housley;S. Turner;Matthias Schunter;Gerrit Bleumer;Mike Just;David Naccache;H. V. Tilborg;S. Vimercati;Pierangela Samarati;Ebru Celikel Cankaya;Alex Biryukov;Lee McFearin;Sabrina De Capitani di Vimercati;Burt Kaliski;Caroline Fontaine;D. Micciancio;N. Sendrier;Nadia Heninger;Jelena Mirkovic;Anne Canteaut;Claude Crépeau;Tom Caddy;P. Salvaneschi;Markus G. Kuhn;Salil Vadhan;Igor Shparlinski;Xiaofeng Wang;G. Dr;Moritz Riesner;M. Vauclair;Arnon Rosenthal;E. Sciore;M. Soete;Michael T. Hunter;C. Carlet;F. Cuppens;Nora Cuppens;Yvo Desmedt;Torben P. Pedersen;M. Locasto;Dan Boneh;Adam J. Lee;Engin Kirda;Tor Helleseth;David accache;Hideki Imai;Atsuhiro Yamagishi;Marion Videau;P. Charpin
  • 通讯作者:
    P. Charpin
Dissertation Trading Dependability, Performance, and Security in First-Price Sealed-Bid Online Auctions with Temporal Decoupling ausgeführt zum Zwecke der Erlangung des akademischen Grades eines Doktors der technischen Wissenschaften unter der Leitung von
具有时间解耦的一价密封投标在线拍卖中论文交易的可靠性、性能和安全性
  • DOI:
  • 发表时间:
    2011
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Engin Kirda
  • 通讯作者:
    Engin Kirda
Hypervisor-based malware protection with AccessMiner
  • DOI:
    10.1016/j.cose.2015.03.007
  • 发表时间:
    2015-07-01
  • 期刊:
  • 影响因子:
  • 作者:
    Aristide Fattori;Andrea Lanzi;Davide Balzarotti;Engin Kirda
  • 通讯作者:
    Engin Kirda

Engin Kirda的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Engin Kirda', 18)}}的其他基金

Collaborative Research: EAGER: Understanding User Needs for Access Control Systems in Smart Settings
合作研究:EAGER:了解智能设置中访问控制系统的用户需求
  • 批准号:
    2219921
  • 财政年份:
    2022
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Flanker: Automatically Detecting Lateral Movement in Organizations Using Heterogeneous Data and Graph Representation Learning
协作研究:SaTC:核心:小型:侧翼:使用异构数据和图表示学习自动检测组织中的横向运动
  • 批准号:
    2127200
  • 财政年份:
    2021
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Standard Grant
SaTC: CORE: Medium: Collaborative: Taming Web Content Through Automated Reduction in Browser Functionality
SaTC:核心:媒介:协作:通过自动减少浏览器功能来驯服 Web 内容
  • 批准号:
    1703454
  • 财政年份:
    2017
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software
TWC:媒介:协作:商品软件的自动逆向工程
  • 批准号:
    1409738
  • 财政年份:
    2014
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Standard Grant
TC: Small: Automatically Identifying Botnet Command and Control Infrastructures
TC:小型:自动识别僵尸网络命令和控制基础设施
  • 批准号:
    1116777
  • 财政年份:
    2011
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Standard Grant

相似国自然基金

Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 批准年份:
    2024
  • 资助金额:
    0.0 万元
  • 项目类别:
    省市级项目
Cell Research
  • 批准号:
    31224802
  • 批准年份:
    2012
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research
  • 批准号:
    31024804
  • 批准年份:
    2010
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Cell Research (细胞研究)
  • 批准号:
    30824808
  • 批准年份:
    2008
  • 资助金额:
    24.0 万元
  • 项目类别:
    专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
  • 批准号:
    10774081
  • 批准年份:
    2007
  • 资助金额:
    45.0 万元
  • 项目类别:
    面上项目

相似海外基金

Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330940
  • 财政年份:
    2024
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317232
  • 财政年份:
    2024
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338301
  • 财政年份:
    2024
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
  • 批准号:
    2317233
  • 财政年份:
    2024
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
  • 批准号:
    2338302
  • 财政年份:
    2024
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
  • 批准号:
    2330941
  • 财政年份:
    2024
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
  • 批准号:
    2413046
  • 财政年份:
    2024
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
  • 批准号:
    2312057
  • 财政年份:
    2023
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
  • 批准号:
    2317830
  • 财政年份:
    2023
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
  • 批准号:
    2318843
  • 财政年份:
    2023
  • 资助金额:
    $ 59.98万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了