FMitF: Track II: Usability, Scalability, and Deployment Improvement of VerioT
FMITF:轨道 II:VerioT 的可用性、可扩展性和部署改进
基本信息
- 批准号:2124225
- 负责人:
- 金额:$ 10万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-07-01 至 2023-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The Internet-of-Things (IoT) access-delegation paradigm is emerging and supported by mainstream IoT vendors. In this paradigm, companies provide support to delegate device access to a delegatee cloud/vendor (such as Google Home, SmartThings, and Apple Home), thus permitting a user to manage multiple devices from different vendors through a single app of the delegatee. Flawed design and implementation of IoT delegation protocols incur serious security and safety consequences, such as unauthorized control of smart door locks and health devices. This project improves and extends VerioT (built on the Spin model-checker), the first formal-verification tool for real-world IoT delegation protocols. The project’s novelties are in new methods to facilitate (1) IoT security analysis leveraging usability-enhanced verification reporting, (2) automatic, scalability-enhanced model construction, and (3) integrating verification techniques to modern IoT software development lifecycle. The project’s impacts will be to enable IoT stakeholders and developers to find security flaws earlier --- ideally as soon as the flaws are introduced --- and to increase assurance in the security of IoT systems.The project includes three main tasks. First, to increase the usability of VerioT, the investigators are improving bug reporting by automatically annotating the reported counter-examples with IoT contexts and operations in natural language texts, producing industry-standard security-bug reports. Second, to increase scalability, the investigators are automating model construction by adopting novel Natural Language Processing (NLP) based document analysis techniques, called Dilution, which can precisely construct protocol state machines from unstructured documentation. Third, the investigators are developing support for enterprise-level deployment by integrating VerioT into modern Continuous Integration/Continuous Deployment (CI/CD) pipelines in the software-engineering and IoT industries. The project is intended to yield an industry-strength IoT protocol verifier that keeps up with the development of verification technology and IoT software practices, and helps developers proactively identify new bugs in IoT protocols and software before they are deployed in production.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
物联网(IoT)访问委托模式正在兴起,并得到主流IoT供应商的支持。在此范例中,公司提供支持以将设备访问委托给被委托者云/供应商(诸如Google Home、SmartThings和Apple Home),从而允许用户通过被委托者的单个应用管理来自不同供应商的多个设备。物联网委托协议的设计和实施存在缺陷,会导致严重的安全和安全后果,例如未经授权控制智能门锁和健康设备。该项目改进和扩展了VerioT(构建在Spin模型检查器上),这是第一个用于真实世界物联网委托协议的正式验证工具。该项目的创新之处在于新方法,以促进(1)物联网安全分析,利用可用性增强的验证报告,(2)自动化,可扩展性增强的模型构建,以及(3)将验证技术集成到现代物联网软件开发生命周期中。 该项目的影响将是使物联网利益相关者和开发人员能够更早地发现安全漏洞--理想情况下,一旦引入漏洞--并提高物联网系统安全性的保证。该项目包括三个主要任务。首先,为了提高VerioT的可用性,研究人员正在改进错误报告,通过自然语言文本中的物联网上下文和操作自动注释报告的反例,生成行业标准的安全错误报告。其次,为了提高可扩展性,研究人员正在通过采用新的基于自然语言处理(NLP)的文档分析技术(称为Dilution)来自动化模型构建,该技术可以从非结构化文档中精确构建协议状态机。第三,研究人员正在通过将VerioT集成到软件工程和物联网行业的现代持续集成/持续部署(CI/CD)管道中,为企业级部署提供支持。该项目旨在产生一个行业实力的物联网协议验证器,跟上验证技术和物联网软件实践的发展,并帮助开发人员在物联网协议和软件部署到生产中之前主动识别新的错误。该奖项反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(3)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
MQTTactic: Security Analysis and Verification for Logic Flaws in MQTT Implementations
MQTTactic:MQTT 实现中逻辑缺陷的安全分析和验证
- DOI:
- 发表时间:2024
- 期刊:
- 影响因子:0
- 作者:B. Yuan, Z. Song
- 通讯作者:B. Yuan, Z. Song
Who's In Control? On Security Risks of Disjointed IoT Device Management Channels
- DOI:10.1145/3460120.3484592
- 发表时间:2021-11
- 期刊:
- 影响因子:0
- 作者:Yan Jia;Bin Yuan;Luyi Xing;Dongfang Zhao;Yifan Zhang;Xiaofeng Wang;Yijing Liu;Kaimin Zheng;Peyton Crnjak;Yuqing Zhang;Deqing Zou;Hai Jin
- 通讯作者:Yan Jia;Bin Yuan;Luyi Xing;Dongfang Zhao;Yifan Zhang;Xiaofeng Wang;Yijing Liu;Kaimin Zheng;Peyton Crnjak;Yuqing Zhang;Deqing Zou;Hai Jin
P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access Policies
- DOI:10.1145/3548606.3560680
- 发表时间:2022-11
- 期刊:
- 影响因子:0
- 作者:Ze Jin;Luyi Xing;Yiwei Fang;Yan Jia;Bin Yuan;Qixu Liu
- 通讯作者:Ze Jin;Luyi Xing;Yiwei Fang;Yan Jia;Bin Yuan;Qixu Liu
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Luyi Xing其他文献
Superoxide radical mediated persulfate activation by nitrogen doped bimetallic MOF (FeCo/N-MOF) for efficient tetracycline degradation, , 282 (2022): 120124.
氮掺杂双金属 MOF (FeCo/N-MOF) 介导的超氧自由基介导的过硫酸盐活化可有效降解四环素,, , 282 (2022): 120124。
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:8.6
- 作者:
Yifei Zhang;Jia Wei;Luyi Xing;Jiamei Li;Mengdie Xu;Guoping Pan;Jun Li - 通讯作者:
Jun Li
A chip thermal management method realizing integrated applications of cooling, power generation and heat flow measurement based on thermoelectric effect
- DOI:
10.1016/j.applthermaleng.2024.124739 - 发表时间:
2025-01-15 - 期刊:
- 影响因子:
- 作者:
Liuyijie Huang;Luyi Xing;Yihua Zheng;Huimin Yao - 通讯作者:
Huimin Yao
Cloud repository as a malicious service: challenge, identification and implication
云存储库作为恶意服务:挑战、识别和影响
- DOI:
- 发表时间:
2018 - 期刊:
- 影响因子:0
- 作者:
Xiaojing Liao;Sumayah A. Alrwais;Kan Yuan;Luyi Xing;Xiaofeng Wang;S. Hao;R. Beyah - 通讯作者:
R. Beyah
SmartPatch: Verifying the Authenticity of the Trigger-Event in the IoT Platform
SmartPatch:验证物联网平台中触发事件的真实性
- DOI:
10.1109/tdsc.2022.3162312 - 发表时间:
2023-03 - 期刊:
- 影响因子:7.3
- 作者:
Bin Yuan;Yuhan Wu;Maogen Yang;Luyi Xing;Xuchang Wang;Deqing Zou;Hai Jin - 通讯作者:
Hai Jin
Luyi Xing的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Luyi Xing', 18)}}的其他基金
Collaborative Research: EAGER: Towards Safeguarding the Emerging Miniapp Paradigm in Mobile Super Apps
合作研究:EAGER:捍卫移动超级应用中新兴的小应用范式
- 批准号:
2330265 - 财政年份:2023
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
CAREER: Foundations for IoT Cloud Security
职业:物联网云安全的基础
- 批准号:
2145675 - 财政年份:2022
- 资助金额:
$ 10万 - 项目类别:
Continuing Grant
相似海外基金
FMitF: Track II: Educating Developers about Ownership in Rust
FMITF:轨道 II:对开发人员进行 Rust 所有权教育
- 批准号:
2319014 - 财政年份:2023
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
FMitF: Track II: SMT-Based Reachability Analyzer of NGAC Policies
FMitF:轨道 II:NGAC 策略的基于 SMT 的可达性分析器
- 批准号:
2318891 - 财政年份:2023
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
Collaborative Research: FMitF: Track II: Cross-Language Support for Runtime Verification
合作研究:FMitF:轨道 II:运行时验证的跨语言支持
- 批准号:
2319473 - 财政年份:2023
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
FMitF: Track II: Bringing Verification-Aware Languages and Federated Authentication to Enable Secure Computing for Scientific Communities
FMITF:轨道 II:引入验证感知语言和联合身份验证,为科学界提供安全计算
- 批准号:
2319190 - 财政年份:2023
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
FMitF: Track II: Cybolic: a symbolic execution technique and tool for analyzing CMake build scripts
FMITF:轨道 II:Cybolic:用于分析 CMake 构建脚本的符号执行技术和工具
- 批准号:
2319131 - 财政年份:2023
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
Collaborative Research: FMitF: Track II: Cross-Language Support for Runtime Verification
合作研究:FMitF:轨道 II:运行时验证的跨语言支持
- 批准号:
2319472 - 财政年份:2023
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
Collaborative Research: FMitF: Track II: Enhancing the Neural Network Verification (NNV) Tool for Industrial Applications
合作研究:FMitF:轨道 II:增强工业应用的神经网络验证 (NNV) 工具
- 批准号:
2220418 - 财政年份:2022
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
Collaborative Research: FMitF: Track II: Enhancing the Neural Network Verification (NNV) Tool for Industrial Applications
合作研究:FMitF:轨道 II:增强工业应用的神经网络验证 (NNV) 工具
- 批准号:
2220426 - 财政年份:2022
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
FmitF: Track II: KeenEye: Enhancing Scenario Exploration
FmitF:轨道 II:KeenEye:增强场景探索
- 批准号:
2123341 - 财政年份:2021
- 资助金额:
$ 10万 - 项目类别:
Standard Grant
FMitF: Track II: FMCloak: Practitioners Using Formal Methods Without Knowing It
FMitF:轨道 II:FMClak:从业者在不知情的情况下使用形式化方法
- 批准号:
2123550 - 财政年份:2021
- 资助金额:
$ 10万 - 项目类别:
Standard Grant