SBIR Phase I: Securing open source software supply chain
SBIR Phase I: Securing open source software supply chain
批准号:
2112368
负责人:
Ashish Bijlani
金额:
$25.58万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
已结题
起止时间:
2021-08-01 至 2023-02-28
中文摘要
小企业创新研究(SBIR)第一阶段项目的更广泛影响将是改善网络安全。 据报道,在流行的语言生态系统(例如,Python),已经被下载了数百万次。 这类攻击具有很高的破坏性,因为恶意软件可能会进入应用程序,可能会危及数百万用户的隐私;此外,OSS是构建现代应用程序和服务的事实上的标准方式。该项目将开发一种新型的大规模自动化审查基础设施,以分析数百万OSS软件包并减轻OSS供应链攻击。 这将提高OSS开发人员社区在网络安全领域的生产力,包括恶意软件分析,暴露不受信任的第三方OSS代码中的不良行为,维护开发人员的信任和声誉,检测隐藏的软件漏洞,以及加强OSS生态系统的安全性。这个小型企业创新研究(SBIR)第一阶段项目将推进最先进的研究技术,并探索检测和缓解开源软件(OSS)供应链攻击的新实用方法-当采用不可信的第三方OSS代码时,开发人员和组织会面临直接的网络安全威胁。该项目将:1)为OSS项目的详尽代码和元数据分析创建新颖的自动化技术; 2)开发一套广泛的强大特征配置文件,用于有效检测恶意代码。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The broader impact of this Small Business Innovation Research (SBIR) Phase I project will be to improve cybersecurity. Thousands of open-source software (OSS) packages containing purposefully harmful software (malware) have been reported across popular language ecosystems (e.g., Python), which have been downloaded millions of times. Such attacks are highly damaging as the malware may find its way into apps, potentially compromising the privacy of millions of users; moreover, OSS is the de facto standard way to build modern applications and services.This project will develop a novel large-scale automated vetting infrastructure to analyze millions of OSS packages and mitigate OSS supply chain attacks. This will enhance productivity for the OSS developer community across the cybersecurity spectrum, including malware analysis, exposing undesired behavior in untrusted third-party OSS code, maintaining developer trust and reputation, detecting hidden software vulnerabilities, and enforcing security of OSS ecosystems. This Small Business Innovation Research (SBIR) Phase I project will advance state-of-the-art research techniques as well as explore novel practical approaches for detection and mitigation of Open-Source Software (OSS) supply chain attacks — a direct cybersecurity threat posed to developers and organizations when adopting untrusted third-party OSS code. This project will: 1) create novel automated techniques for exhaustive code as well as metadata analysis of OSS projects, and 2) develop an extensive set of robust characteristic profiles for effective detection of malicious code.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
登录
查看更多内容
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark
Supercooled Phase Transition
-
批准号:24ZR1429700
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:YUICHIRO NAKAI
-
依托单位:
ATLAS实验探测器Phase 2升级
-
批准号:11961141014
-
项目类别:国际(地区)合作与交流项目
-
资助金额:3350万元
-
批准年份:2019
-
负责人:刘衍文
-
依托单位:
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
-
批准号:41802035
-
项目类别:青年科学基金项目
-
资助金额:12.0万元
-
批准年份:2018
-
负责人:张里
-
依托单位:
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究
-
批准号:61675216
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2016
-
负责人:叶青
-
依托单位:
基于Phase-type分布的多状态系统可靠性模型研究
-
批准号:71501183
-
项目类别:青年科学基金项目
-
资助金额:17.4万元
-
批准年份:2015
-
负责人:陈童
-
依托单位:
纳米(I-Phase+α-Mg)准共晶的临界半固态形成条件及生长机制
-
批准号:51201142
-
项目类别:青年科学基金项目
-
资助金额:25.0万元
-
批准年份:2012
-
负责人:张英波
-
依托单位:
连续Phase-Type分布数据拟合方法及其应用研究
-
批准号:11101428
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2011
-
负责人:黄卓
-
依托单位:
D-Phase准晶体的电子行为各向异性的研究
-
批准号:19374069
-
项目类别:面上项目
-
资助金额:6.4万元
-
批准年份:1993
-
负责人:张殿琳
-
依托单位: