课题基金 / 基金详情

CICI:SIVD:Context-Aware Vulnerability Detection in Configurable Scientific Computing Environments

CICI:SIVD:Context-Aware Vulnerability Detection in Configurable Scientific Computing Environments
CICI:SIVD:可配置科学计算环境中的上下文感知漏洞检测
批准号:
2115167
负责人:
Mu Zhang
金额:
$49.98万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-07-01 至 2025-06-30

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Computational infrastructures have increasingly become the enabling factor for scientific discovery, in critical application domains including seismic imaging, air quality monitoring, epidemiology, drug discovery and nuclear engineering. The security of these infrastructures is thus of crucial importance, as the vulnerabilities in their unique software stacks can cause significant damage to economy, environment, public health, and national security. This project aims to safeguard scientific computing infrastructures via automatically identifying hidden software vulnerabilities in a timely manner. Particularly, the goal of this project is to address the challenging problem of configuration-related security bugs in highly customizable high-performance computing environments. Detecting such vulnerabilities is a hard problem. The stateof- the-art general vulnerability analyzers are unable to capture the specific runtime contexts of multiple interdependent software elements in specialized scientific computing environments. To bridge this gap, this project connects advanced bug-finding techniques to dedicated high-performance computing settings. In addition, it also seeks to leverage the unique characteristics of scientific computing environments to facilitate vulnerability discovery. Hence, this research provides a comprehensive understanding of the software security problems in real-world scientific computing systems, and builds robust solutions to secure these systems.Specifically, this project develops novel deployment-specific vulnerability detection techniques, that can (a) discover seemingly well-formed, yet inconsistent configuration values within scientific computing contexts, (b) detect cross-component vulnerabilities caused by the settings of interconnected computing software, and (c) take full advantage of the de facto workflow of high-performance computing systems to reduce the complexity of finding bugs. This research consists of three tasks: (1) it investigates the deployment contexts in real-world high-performance computing systems and develops both offline and online tools to automatically collect contextual information; (2) it applies extracted contexts to detecting misconfiguration and configuration-triggered code vulnerabilities at both deployment time and incrementally at runtime; (3) it tests the novel technique in real-world testbeds and scientific computing environments to evaluate its accuracy, efficiency and effectiveness.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3597926.3598132
发表时间: 2023-07
期刊: Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis
影响因子: --
作者: [Yufei Pan;Zhichao Xu;Li Li-Li;Yunhe Yang;Mu Zhang]
通讯作者: Yufei Pan;Zhichao Xu;Li Li-Li;Yunhe Yang;Mu Zhang
Arvin: Greybox Fuzzing Using Approximate Dynamic CFG Analysis
Arvin:使用近似动态 CFG 分析进行灰盒模糊测试
DOI: 10.1145/3579856.3582813
发表时间: 2023
期刊: Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security
影响因子: --
作者: [Shahini, Sirus, Zhang, Mu, Payer, Mathias, Ricci, Robert]
通讯作者: Ricci, Robert
国内基金
海外基金
基于空间协方差分析建立的AD和SIVD脑灌注模式:生物标志物和机制研究
  • 批准号:
    81870831
  • 项目类别:
    面上项目
  • 资助金额:
    56.0万元
  • 批准年份:
    2018
  • 负责人:
    张楠
  • 依托单位:
基于DTI探讨白质超微结构改变在化瘀通络灸干预SIVD中的作用
  • 批准号:
    81574075
  • 项目类别:
    面上项目
  • 资助金额:
    59.0万元
  • 批准年份:
    2015
  • 负责人:
    张庆萍
  • 依托单位: