Collaborative Research: SaTC: CORE: Small: Improving Sanitization and Avoiding Denial of Service Through Correct and Safe Regexes
协作研究:SaTC:核心:小型:通过正确和安全的正则表达式改进清理并避免拒绝服务
基本信息
- 批准号:2135156
- 负责人:
- 金额:$ 27.4万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-06-15 至 2025-05-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
This project will improve the security of software. The project will focus on cybersecurity issues in regular expressions. Regular expressions are an important tool used by computer programmers to manipulate data. Regular expressions are applied in many ways, including to validate input in a web form and to check internet traffic for malicious activity. Unfortunately, computer programmers often use regular expressions incorrectly, leading to insecure program behavior. These behaviors result in errors with serious cybersecurity consequences, including allowing malicious actors to steal personal information, seize control of a computer, or cause many websites to crash. This project will address these limitations by improving regular expression engineering practices, and by and making more trustworthy the infrastructure on which regular expressions rely. The team will incorporate undergraduate researchers, develop educational material, and engage with K-12 students. The successful completion of the project will be a significant step towards eliminating cybersecurity incidents related to regular expressions.This project will design, develop, and evaluate (Part 1) New techniques to make it easier for programmers to re-use high-quality regular expressions; and (Part 2) Novel regex engines that are safe from regular expression denial of service (ReDoS). In Part One, the team proposes processes and tools to help engineers develop correct regexes. The approach is grounded in the re-use paradigm, helping engineers learn from others' expertise. However, to enable re-use, open problems must be addressed in regex indexing, querying, matching, ranking, and comparison. Building on a dataset of 853,818 regexes, the team will develop regex clustering techniques, and integrate novel tool development with user studies to understand modalities and metrics for querying, ranking, and comparison. Synthesizing these techniques, machine learning and new algorithms to enable the reuse-based composition, synthesis, and repair of security sensitive regexes will be applied. Project findings will be embodied in a novel publicly-accessible regex search engine and accompanying tools. In Part Two, the team will improve the trustworthiness of regex engines by eliminating the problematic worst-case characteristics. The team has begun exploring algorithmic advances that address its worst-case super-linear behavior. The team will design a ReDoS-safe algorithm with a provably constant space bound and develop novel worst-case analyses for extended features (e.g., backreferences). For practicality, the team's regex engine changes must be transparent. However, backwards compatibility checking for regex engines is an open problem. The team will develop the first regex engine semantic testing techniques, based on metamorphic and differential testing; and enable regex engine performance regression testing through the first systematic regex performance benchmark.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目将提高软件的安全性。该项目将重点关注正则表达式中的网络安全问题。正则表达式是计算机程序员用来操作数据的重要工具。正则表达式应用于许多方面,包括验证Web表单中的输入以及检查恶意活动的Internet流量。不幸的是,计算机程序员经常错误地使用正则表达式,导致不安全的程序行为。这些行为会导致严重的网络安全后果,包括允许恶意行为者窃取个人信息,控制计算机或导致许多网站崩溃。这个项目将通过改进正则表达式工程实践来解决这些限制,并使正则表达式所依赖的基础设施更加值得信赖。该团队将包括本科研究人员,开发教育材料,并与K-12学生接触。该项目的成功完成将是消除与正则表达式相关的网络安全事件的重要一步。该项目将设计、开发和评估(第1部分)使程序员更容易重用高质量正则表达式的新技术;以及(第2部分)防止正则表达式拒绝服务(ReDoS)的新型正则表达式引擎。在第一部分中,团队提出了帮助工程师开发正确的正则表达式的过程和工具。该方法基于重用范式,帮助工程师学习他人的专业知识。然而,为了实现重用,必须解决正则表达式索引、查询、匹配、排名和比较中的开放问题。基于853,818个正则表达式的数据集,该团队将开发正则表达式聚类技术,并将新工具开发与用户研究相结合,以了解查询,排名和比较的模式和指标。综合这些技术,机器学习和新的算法,使基于重用的组合,合成和修复安全敏感的正则表达式将被应用。项目结果将体现在一个新的公开访问的正则表达式搜索引擎和配套工具。在第二部分中,团队将通过消除有问题的最坏情况特征来提高正则表达式引擎的可信度。该团队已经开始探索算法的进步,以解决其最坏情况下的超线性行为。该团队将设计一个具有可证明的恒定空间边界的ReDoS安全算法,并为扩展功能(例如,反向引用)。为了实用,团队的正则表达式引擎更改必须是透明的。然而,正则表达式引擎的向后兼容性检查是一个开放的问题。该团队将开发第一个基于变形和差分测试的正则表达式引擎语义测试技术;并通过第一个系统化的正则表达式性能基准来实现正则表达式引擎性能回归测试。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估而被认为值得支持。
项目成果
期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Improving Developers’ Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix Strategies
- DOI:10.1109/sp46215.2023.10179442
- 发表时间:2022-12
- 期刊:
- 影响因子:0
- 作者:Sk Adnan Hassan;Zainab Aamir;Dongyoon Lee;James C. Davis;Francisco Servant
- 通讯作者:Sk Adnan Hassan;Zainab Aamir;Dongyoon Lee;James C. Davis;Francisco Servant
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
James Davis其他文献
NITRATION: A SELECTIVE ELECTROCHEMICAL LABEL FOR THE DETERMINATION OF ACTIVATED AROMATICS
硝化:用于测定活化芳烃的选择性电化学标记
- DOI:
- 发表时间:
2002 - 期刊:
- 影响因子:0
- 作者:
E. L. Beckett;N. Lawrence;James Davis;R. Compton - 通讯作者:
R. Compton
分子間水素結合ダイナミクスを利用した液晶性強誘電体の設計
利用分子间氢键动力学设计液晶铁电材料
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Douglas R. MacFarlane;Naoki Tachikawa;Maria Forsyth;Jennifer M. Pringle;Patrick Howlett;Gloria D. Elliott;James Davis;Masayoshi Watanabe;Patrice Simon;C. Austen Angell;芥川智行 - 通讯作者:
芥川智行
A clinical assessment of direct electrochemical urate measurements.
直接电化学尿酸盐测量的临床评估。
- DOI:
10.1016/j.talanta.2005.08.020 - 发表时间:
2006 - 期刊:
- 影响因子:0
- 作者:
Jodi S. N. Dutt;C. Livingstone;M. Cardosi;S. J. Wilkins;James Davis - 通讯作者:
James Davis
Incidence of hypophosphataemia in patients on parenteral nutrition
肠外营养患者低磷血症的发生率
- DOI:
- 发表时间:
2007 - 期刊:
- 影响因子:0
- 作者:
Marvin;C. May;C. Livingstone;James Davis - 通讯作者:
James Davis
The discovery of an orally efficacious positive allosteric modulator of the calcium sensing receptor containing a dibenzylamine core.
发现一种口服有效的含有二苄胺核心的钙传感受体正变构调节剂。
- DOI:
10.1016/j.bmcl.2010.07.060 - 发表时间:
2010 - 期刊:
- 影响因子:2.7
- 作者:
P. Harrington;D. J. St Jean;Jeff Clarine;T. Coulter;Michael Croghan;Adam J Davenport;James Davis;C. Ghiron;J. Hutchinson;M. Kelly;Fred D Lott;J. Lu;David A. Martin;S. Morony;Steve F. Poon;Elena Portero;J. Reagan;K. Regal;A. Tasker;Minghan Wang;Yuhua Yang;Guomin Yao;Q. Zeng;C. Henley;C. Fotsch - 通讯作者:
C. Fotsch
James Davis的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('James Davis', 18)}}的其他基金
Workshops on Smart Manufacturing with Open and Scaled Data Sharing in Semiconductor and Microelectronics Manufacturing; Virtual and In-Person; Washington, DC; October/November 2023
半导体和微电子制造中开放和规模化数据共享的智能制造研讨会;
- 批准号:
2334590 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
MICA: Stomasense: A New Route to the Proactive Detection and Management of Leaks within Ostomy Pouches
MICA:Stomasense:主动检测和管理造口袋内泄漏的新途径
- 批准号:
MR/W029561/1 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Research Grant
Symposium on the Strategy for Resilient Manufacturing Ecosystems through AI
通过人工智能打造弹性制造生态系统战略研讨会
- 批准号:
2132067 - 财政年份:2021
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
CAS: Collaborative Research: Boronium Ionic Liquids - Impact of Structure on Chemistry, Electrochemical Stability, Ion Dynamics, and Charge Transport
CAS:合作研究:硼离子液体 - 结构对化学、电化学稳定性、离子动力学和电荷传输的影响
- 批准号:
2102978 - 财政年份:2021
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Workshop: Aligning AI and U.S. Advanced Manufacturing Competitiveness
研讨会:人工智能与美国先进制造业竞争力的结合
- 批准号:
2049670 - 财政年份:2020
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Finite Fields and their Applications at Simon Fraser University
西蒙弗雷泽大学的有限域及其应用
- 批准号:
1905024 - 财政年份:2019
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Topology of Manifolds: Interactions between High and Low Dimensions
流形拓扑:高维和低维之间的相互作用
- 批准号:
1850620 - 财政年份:2019
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Ionic and Molecular Materials of High Thermal Stability: Design, Structure, and Function
高热稳定性离子和分子材料:设计、结构和功能
- 批准号:
1800122 - 财政年份:2018
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Summer School on Surgery and the Classification of Manifolds
外科和歧管分类暑期学校
- 批准号:
1638464 - 财政年份:2016
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
相似国自然基金
复杂电子产品超精密加工及检测关键技术研究与应用
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
基于合成生物学的动物底盘品种优化及中试应用研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
运用组学整合技术探索萆薢分清散联合化疗治疗晚期胰腺癌的临床研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
九里香等提取物多靶向制剂抗肺癌的作用及机制研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
升血小板方治疗原发免疫性血小板减少症的临床研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
八髎穴微波热疗在女性膀胱过度活动症治疗中的价值研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
基于 miR-455-5p 介导的氧化应激机制探讨糖尿病视网膜病变中医分型治疗的临床研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
基于 UPLC-Q-TOF-MS/MS 分析的 异功散活性成分评价及提取工艺研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
无创电针对于痉挛型双瘫脑 瘫患儿的有效性与安全性研究:一项随机 单盲前瞻性队列研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
弹压式手法与体外冲击波治疗肱骨外上髁炎的对比研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
- 批准号:
2413046 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
- 批准号:
2312057 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
- 批准号:
2317830 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
- 批准号:
2318843 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant