课题基金 / 基金详情

CAREER: Black-Box Learning of Web Application Authorization Policies

CAREER: Black-Box Learning of Web Application Authorization Policies
职业:Web 应用程序授权策略的黑盒学习
批准号:
2047623
负责人:
Amirreza Masoumzadeh
金额:
$57.47万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-10-01 至 2026-09-30

项目摘要

项目成果

Amirreza Masoumzadeh的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Web applications have become the de facto way to access services and functionalities. It is vital to ensure that different users of web applications are only allowed to access what they are supposed to, i.e., implementing correct authorization. But, unfortunately, broken access control and authorization has been constantly ranked as one of the top web application vulnerabilities. In fact, many web applications cannot provide an accurate specification of their enforced authorization policies due to challenges such as code complexity and fast-paced development. Neither end users nor even developers of the applications could reason about data protection in this environment. To address this problem, this research project devises a novel framework for learning fine-grained authorization policies from web applications without relying on access to their source codes or understanding other internal complexities. The project develops an integrated research and education program to train the next generation of cybersecurity workforce at the intersection of security/privacy, machine learning, and web technologies. Since web-based systems are pervasive in our society, the developed framework and associated solutions will significantly contribute to system safety and user privacy. Furthermore, due to their black-box design, the developed techniques will be critical assets to investigate data authorization practices of applications outside their development environments by application adopters (e.g., companies deploying outsourced applications) and third parties acting in the interest of end users (e.g., security/privacy researchers and regulators investigating compliance with privacy laws and expectations). The project engages a diverse body of students especially from underrepresented groups in security and privacy research and exposes the broad community to security and privacy topics through outreach activities.This research project develops a novel paradigm for automated learning of web application authorization policies that significantly improves ensuring the security and privacy of web applications. A key characteristic of this research is to treat web applications as black boxes, i.e., learning authorizations by interacting with and observing them as would regular end users. The black-box approach allows abstracting away internal complexities of web applications and focusing instead on what matters: learning what policies are enforced on users as they access application data. The research is carried out in three thrusts. First, a theoretical policy learning framework will be devised for efficiently probing the authorization space of applications as black boxes and constructing formal specifications of their policies. Second, a methodology and associated techniques for learning representation of data objects, relationships, and operations from black-box web applications will be developed in order to realize practical deployment of the theoretical framework in the web domain. Third, the project will develop techniques for analysis and integration of the learned authorization policies to improve the security and privacy of web applications. This paradigm will be transformative for web security/privacy research and practice by providing researchers, developers, and analysts an automated approach to learn the specifications of authorization policies. In addition to enabling them to understand the authorization behavior of web applications, it will revitalize research in formal policy testing and verification techniques that rely on concrete policy specifications. Furthermore, the general framework will be applicable beyond web applications to other domains such as mobile app ecosystems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
Towards Automated Learning of Access Control Policies Enforced by Web Applications
实现 Web 应用程序执行的访问控制策略的自动学习
DOI: 10.1145/3589608.3594743
发表时间: 2023
期刊: Proceedings of the 28th ACM Symposium on Access Control Models and Technologies
影响因子: --
作者: [Iyer, Padmavathi, Masoumzadeh, Amir]
通讯作者: Masoumzadeh, Amir
Effective Evaluation of Relationship-Based Access Control Policy Mining
基于关系的访问控制策略挖掘的有效评估
DOI: 10.1145/3532105.3535022
发表时间: 2022
期刊: Proceedings of the 27th ACM Symposium on Access Control Models and Technologies
影响因子: --
作者: [Iyer, Padmavathi, Masoumzadeh, Amirreza]
通讯作者: Masoumzadeh, Amirreza
DOI: 10.1145/3517121
发表时间: 2022-08-01
期刊: ACM TRANSACTIONS ON PRIVACY AND SECURITY
影响因子: 2.3
作者: [Iyer,Padmavathi, Masoumzadeh,Amirreza]
通讯作者: Masoumzadeh,Amirreza
Travel: NSF Student Travel Grant for 5th IEEE International Conference on Trust, Privacy, and Security in Intelligent Systems and Applications (IEEE TPS 2023)
  • 批准号:
    2333916
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2023
  • 负责人:
    Amirreza Masoumzadeh
  • 依托单位:
NSF Student Travel Grant for 2019 IEEE International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (IEEE TPS)
  • 批准号:
    2002916
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2019
  • 负责人:
    Amirreza Masoumzadeh
  • 依托单位:
国内基金
海外基金
空间分数阶 Black-Scholes 方程的波动率反演 问题
  • 批准号:
    Q24A010012
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    蒋晓颖
  • 依托单位:
Black-Scholes期权定价模型的时间自适应算法与分析
  • 批准号:
    12271142
  • 项目类别:
    面上项目
  • 资助金额:
    45万元
  • 批准年份:
    2022
  • 负责人:
    任金城
  • 依托单位:
Shining light on the black hole mass distribution
  • 批准号:
    12073029
  • 项目类别:
    面上项目
  • 资助金额:
    61.0万元
  • 批准年份:
    2020
  • 负责人:
    Roberto Soria
  • 依托单位:
新老岛弧斑岩铜(金)矿中间岩浆房过程对比研究:以菲律宾 Black Mountain和我国多宝山为例