Collaborative Research: SaTC: CORE: Small: Improving Sanitization and Avoiding Denial of Service Through Correct and Safe Regexes
协作研究:SaTC:核心:小型:通过正确和安全的正则表达式改进清理并避免拒绝服务
基本信息
- 批准号:2135157
- 负责人:
- 金额:$ 27.4万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-06-15 至 2025-05-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
This project will improve the security of software. The project will focus on cybersecurity issues in regular expressions. Regular expressions are an important tool used by computer programmers to manipulate data. Regular expressions are applied in many ways, including to validate input in a web form and to check internet traffic for malicious activity. Unfortunately, computer programmers often use regular expressions incorrectly, leading to insecure program behavior. These behaviors result in errors with serious cybersecurity consequences, including allowing malicious actors to steal personal information, seize control of a computer, or cause many websites to crash. This project will address these limitations by improving regular expression engineering practices, and by and making more trustworthy the infrastructure on which regular expressions rely. The team will incorporate undergraduate researchers, develop educational material, and engage with K-12 students. The successful completion of the project will be a significant step towards eliminating cybersecurity incidents related to regular expressions.This project will design, develop, and evaluate (Part 1) New techniques to make it easier for programmers to re-use high-quality regular expressions; and (Part 2) Novel regex engines that are safe from regular expression denial of service (ReDoS). In Part One, the team proposes processes and tools to help engineers develop correct regexes. The approach is grounded in the re-use paradigm, helping engineers learn from others' expertise. However, to enable re-use, open problems must be addressed in regex indexing, querying, matching, ranking, and comparison. Building on a dataset of 853,818 regexes, the team will develop regex clustering techniques, and integrate novel tool development with user studies to understand modalities and metrics for querying, ranking, and comparison. Synthesizing these techniques, machine learning and new algorithms to enable the reuse-based composition, synthesis, and repair of security sensitive regexes will be applied. Project findings will be embodied in a novel publicly-accessible regex search engine and accompanying tools. In Part Two, the team will improve the trustworthiness of regex engines by eliminating the problematic worst-case characteristics. The team has begun exploring algorithmic advances that address its worst-case super-linear behavior. The team will design a ReDoS-safe algorithm with a provably constant space bound and develop novel worst-case analyses for extended features (e.g., backreferences). For practicality, the team's regex engine changes must be transparent. However, backwards compatibility checking for regex engines is an open problem. The team will develop the first regex engine semantic testing techniques, based on metamorphic and differential testing; and enable regex engine performance regression testing through the first systematic regex performance benchmark.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该项目将提高软件的安全性。该项目将重点关注正则表达式中的网络安全问题。正则表达式是计算机程序员用来操作数据的重要工具。正则表达式应用于许多方面,包括验证Web表单中的输入以及检查恶意活动的Internet流量。不幸的是,计算机程序员经常错误地使用正则表达式,导致不安全的程序行为。这些行为会导致严重的网络安全后果,包括允许恶意行为者窃取个人信息,控制计算机或导致许多网站崩溃。这个项目将通过改进正则表达式工程实践来解决这些限制,并使正则表达式所依赖的基础设施更加值得信赖。该团队将包括本科研究人员,开发教育材料,并与K-12学生接触。该项目的成功完成将是消除与正则表达式相关的网络安全事件的重要一步。该项目将设计、开发和评估(第1部分)使程序员更容易重用高质量正则表达式的新技术;以及(第2部分)防止正则表达式拒绝服务(ReDoS)的新型正则表达式引擎。在第一部分中,团队提出了帮助工程师开发正确的正则表达式的过程和工具。该方法基于重用范式,帮助工程师学习他人的专业知识。然而,为了实现重用,必须解决正则表达式索引、查询、匹配、排名和比较中的开放问题。基于853,818个正则表达式的数据集,该团队将开发正则表达式聚类技术,并将新工具开发与用户研究相结合,以了解查询,排名和比较的模式和指标。综合这些技术,机器学习和新的算法,使基于重用的组合,合成和修复安全敏感的正则表达式将被应用。项目结果将体现在一个新的公开访问的正则表达式搜索引擎和配套工具。在第二部分中,团队将通过消除有问题的最坏情况特征来提高正则表达式引擎的可信度。该团队已经开始探索算法的进步,以解决其最坏情况下的超线性行为。该团队将设计一个具有可证明的恒定空间边界的ReDoS安全算法,并为扩展功能(例如,反向引用)。为了实用,团队的正则表达式引擎更改必须是透明的。然而,正则表达式引擎的向后兼容性检查是一个开放的问题。该团队将开发第一个基于变形和差分测试的正则表达式引擎语义测试技术;并通过第一个系统化的正则表达式性能基准来实现正则表达式引擎性能回归测试。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估而被认为值得支持。
项目成果
期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Improving Developers’ Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix Strategies
- DOI:10.1109/sp46215.2023.10179442
- 发表时间:2022-12
- 期刊:
- 影响因子:0
- 作者:Sk Adnan Hassan;Zainab Aamir;Dongyoon Lee;James C. Davis;Francisco Servant
- 通讯作者:Sk Adnan Hassan;Zainab Aamir;Dongyoon Lee;James C. Davis;Francisco Servant
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Dongyoon Lee其他文献
ProRace
职业竞赛
- DOI:
10.1145/3093336.3037708 - 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Tong Zhang;Changhee Jung;Dongyoon Lee - 通讯作者:
Dongyoon Lee
Low-cost soft error resilience with unified data verification and fine-grained recovery for acoustic sensor based detection
低成本的软错误恢复能力,具有统一的数据验证和细粒度恢复,用于基于声学传感器的检测
- DOI:
- 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Qingrui Liu;Changhee Jung;Dongyoon Lee;Devesh Tiwari - 通讯作者:
Devesh Tiwari
Monitoring Runtime Metrics of Fog Manufacturing via a Qualitative and Quantitative (QQ) Control Chart
通过定性和定量 (QQ) 控制图监控雾制造的运行时指标
- DOI:
10.1145/3501262 - 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Yifu Li;Lening Wang;Dongyoon Lee;R. Jin - 通讯作者:
R. Jin
Clover: Compiler Directed Lightweight Soft Error Resilience
Clover:编译器导向的轻量级软错误恢复能力
- DOI:
10.1145/2670529.2754959 - 发表时间:
2015 - 期刊:
- 影响因子:0
- 作者:
Qingrui Liu;Changhee Jung;Dongyoon Lee;Devesh Tiwari - 通讯作者:
Devesh Tiwari
Comparison of structural variant callers for massive whole-genome sequence data
海量全基因组序列数据的结构变异调用者比较
- DOI:
10.1186/s12864-024-10239-9 - 发表时间:
2024 - 期刊:
- 影响因子:4.4
- 作者:
Soobok Joe;Jong;Jun Kim;Sangok Kim;Ji;Min;Dongyoon Lee;Jin Ok Yang;Seon - 通讯作者:
Seon
Dongyoon Lee的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Dongyoon Lee', 18)}}的其他基金
Collaborative Research: SHF: Small: Enabling Caches and GPUs for Energy Harvesting Systems
合作研究:SHF:小型:为能量收集系统启用缓存和 GPU
- 批准号:
2153747 - 财政年份:2022
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
CSR: Small: Repurposing Spatial Memory Safety Support in Commodity Processors for Temporal Memory Safety, Other Program Analyses, Hardware-Accelerated Data Structures, and More
CSR:小:重新利用商品处理器中的空间内存安全支持,以实现临时内存安全、其他程序分析、硬件加速数据结构等
- 批准号:
2029720 - 财政年份:2020
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
CSR: Small: Repurposing Spatial Memory Safety Support in Commodity Processors for Temporal Memory Safety, Other Program Analyses, Hardware-Accelerated Data Structures, and More
CSR:小:重新利用商品处理器中的空间内存安全支持,以实现临时内存安全、其他程序分析、硬件加速数据结构等
- 批准号:
1814430 - 财政年份:2018
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
相似国自然基金
复杂电子产品超精密加工及检测关键技术研究与应用
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
基于合成生物学的动物底盘品种优化及中试应用研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
运用组学整合技术探索萆薢分清散联合化疗治疗晚期胰腺癌的临床研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
九里香等提取物多靶向制剂抗肺癌的作用及机制研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
升血小板方治疗原发免疫性血小板减少症的临床研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
八髎穴微波热疗在女性膀胱过度活动症治疗中的价值研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
基于 miR-455-5p 介导的氧化应激机制探讨糖尿病视网膜病变中医分型治疗的临床研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
基于 UPLC-Q-TOF-MS/MS 分析的 异功散活性成分评价及提取工艺研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
无创电针对于痉挛型双瘫脑 瘫患儿的有效性与安全性研究:一项随机 单盲前瞻性队列研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
弹压式手法与体外冲击波治疗肱骨外上髁炎的对比研究
- 批准号:
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
- 批准号:
2413046 - 财政年份:2024
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
- 批准号:
2312057 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
- 批准号:
2317830 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
- 批准号:
2318843 - 财政年份:2023
- 资助金额:
$ 27.4万 - 项目类别:
Continuing Grant