课题基金 / 基金详情

Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security

Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
协作研究:SaTC:核心:中:重新思考安全性模糊测试
批准号:
2031377
负责人:
Jun Xu
金额:
$59.6万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-10-01 至 2022-02-28

项目摘要

项目成果

Jun Xu的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
In software, a vulnerability is a flaw in the code that can be exploited by a malicious actor to perform unauthorized activities or change the behavior of the software. Although a topic heavily studied by security researchers, finding software vulnerabilities is becoming increasingly challenging because the software widely used in day-to-day life is growing larger and more complicated. This project addresses this challenge by rethinking a classic technique called fuzzing for finding vulnerabilities from large software. The high-level idea of fuzzing is to create a large number of random inputs to run software and in turn trigger vulnerabilities. The novelties of this project are the new approaches, techniques, and tools that revolutionize fuzzing and make the nearly random testing process more intelligent and targeted. This way, this project will enhance security of various types of widely used software, ranging from web browsers to server-side programs.To that end, this project is investigating vulnerability-coverage-driven fuzzing. Existing fuzzing techniques primarily followed an approach called code-coverage-driven fuzzing, motivated by the belief that code coverage and vulnerability finding are strongly correlated. Challenging this widely held belief, this project shows that code coverage has weaker-than-expected ties with vulnerabilities and code-coverage-driven fuzzing is not well suited for vulnerability finding. Pioneering vulnerability-coverage-driven fuzzing, this project invents a series of novel techniques to (1) obtain feedback on vulnerability coverage (2) prioritize test inputs that can reach more vulnerabilities and (3) maximize the chance to trigger vulnerabilities reached by the test inputs. This project also produces new metrics, new benchmarks, and new frameworks for comprehensively evaluating the use of fuzzing for vulnerability finding. With the investigators' experience in research of software security and system security, this project provides a group of education, training, and research opportunities for both undergraduate and graduate students. Through industry outreach, the investigators pursue technology transfers and raise the awareness of software security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1007/978-3-030-90022-9_10
发表时间: 2021-09
期刊: ArXiv
影响因子: --
作者: [Yifan Wang;Yuchen Zhang;Chengbin Pang;Peng Li;Nikolaos Triandopoulos;Jun Xu]
通讯作者: Yifan Wang;Yuchen Zhang;Chengbin Pang;Peng Li;Nikolaos Triandopoulos;Jun Xu
CAREER: Fuzzing Large Software: Principles, Methods, and Tools
  • 批准号:
    2340198
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $55.55万
  • 财政年份:
    2024
  • 负责人:
    Jun Xu
  • 依托单位:
Travel: NSF Student Travel Grant for 2023 ACM Conference on Computer and Communications Security (CCS)
  • 批准号:
    2341773
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.5万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure
  • 批准号:
    2319880
  • 项目类别:
    Standard Grant
  • 资助金额:
    $119.81万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2213727
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2022
  • 负责人:
    Jun Xu
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)