Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
协作研究:SaTC:核心:中:大胆探索:通过智能文档分析自动发现网络系统中的安全缺陷
基本信息
- 批准号:2154199
- 负责人:
- 金额:$ 55万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-07-01 至 2026-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Specifications, developer guides and other documentations of networked systems (e.g., Internet applications, carrier networks) describe how these systems are designed, used and operate. These documentations are important sources for understanding security weaknesses in these systems and have not been fully leveraged due to the difficulty in analyzing their imprecise, convoluted and ambiguous content. Project Audacity (AUtomated Documentation Analysis for seCurITY) aims at addressing the challenge for security weakness discovery and remedy. Its novelties are the development of innovative technologies to enable automated document analysis for security protection. The project’s broader significance and importance include transferring the technologies to industry, involving members from under-represented groups in the project and disseminating outcomes through K9-12 outreach and community services. The project focuses on mitigating security risks of both design flaws and implementation vulnerabilities in networked systems, through automatically recovering security-related information (e.g., models, security properties) and confusing descriptions (e.g., inconsistent statements) from documentations to evaluate their security implications (e.g., verification of system designs, validation of predicted weaknesses on system implementations). This purpose is served by novel techniques based upon machine learning and natural language processing for analyzing different types of documentations, such as those for payment, single-sign-on, and for the 3rd Generation Partnership Project or 3GPP. Examples of such techniques include sentiment analysis for finding the statements related to security requirements and a similarity and differential analysis that compares different statements about similar security-critical operations to capture inconsistency. Furthermore, the project studies emerging techniques such as service syndication through comparing the documentations of different services and the 3GPP ecosystem from analyzing its public text data for risk measurement, identification and mitigation. This work complements program analysis to help enhance the security quality of networked systems, contributing to a better procedure and ecosystem that make security-critical documentations more precise, more consistent and less error-prone.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
网络系统(如Internet应用程序、载波网络)的规范、开发指南和其他文档描述了这些系统是如何设计、使用和操作的。这些文档是了解这些系统中的安全弱点的重要来源,但由于难以分析其不精确、复杂和模糊的内容,这些文档尚未得到充分利用。项目Audacity(安全自动化文档分析)的目标是处理安全弱点发现和补救的挑战。它的新颖之处在于开发了创新技术,以实现安全保护的自动文档分析。该项目更广泛的意义和重要性包括将技术转让给工业界,让项目中代表性不足的群体的成员参与,并通过K9-12外展和社区服务传播成果。该项目侧重于减轻网络系统中设计缺陷和实现漏洞的安全风险,通过自动从文档中恢复与安全相关的信息(例如,模型,安全属性)和令人困惑的描述(例如,不一致的陈述)来评估其安全含义(例如,系统设计的验证,系统实现上预测的弱点的验证)。基于机器学习和自然语言处理的新技术可以用于分析不同类型的文档,例如用于支付、单点登录和第三代合作伙伴项目(3GPP)的文档,从而实现这一目的。此类技术的示例包括用于查找与安全需求相关的语句的情感分析,以及用于比较关于类似安全关键操作的不同语句以捕获不一致性的相似性和差异分析。此外,该项目还研究了新兴技术,如服务联合,通过比较不同服务的文档和3GPP生态系统,分析其公共文本数据,以进行风险测量、识别和缓解。这项工作补充了程序分析,有助于提高网络系统的安全质量,有助于建立更好的程序和生态系统,使安全关键文件更精确、更一致、更少出错。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Seeing the Forest for the Trees: Understanding Security Hazards in the 3GPP Ecosystem through Intelligent Analysis on Change Requests
- DOI:
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Yi Chen;Di Tang;Yepeng Yao;Mingming Zha;Xiaofeng Wang;Xiaozhong Liu;Haixu Tang;Dongfang Zhao
- 通讯作者:Yi Chen;Di Tang;Yepeng Yao;Mingming Zha;Xiaofeng Wang;Xiaozhong Liu;Haixu Tang;Dongfang Zhao
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
XiaoFeng Wang其他文献
Feasibility analysis of radiation balanced laser
- DOI:
10.1016/j.optcom.2009.01.017 - 发表时间:
2009-05-01 - 期刊:
- 影响因子:
- 作者:
Mu Zhou;XiaoFeng Wang;JiChun Tan - 通讯作者:
JiChun Tan
A fundamental research on combustion chemical kinetic model’s precision property
- DOI:
10.1007/s11431-010-3225-z - 发表时间:
2010-07-15 - 期刊:
- 影响因子:4.900
- 作者:
Ran Zhao;Hao Liu;Han Hu;ZhiQiang Yan;XiaoFeng Wang;FanHai Kong;JianRong Qiu - 通讯作者:
JianRong Qiu
Trust Beyond Border: Lightweight, Verifiable User Isolation for Protecting In-Enclave Services
超越边界的信任:用于保护 Enclave 内服务的轻量级、可验证的用户隔离
- DOI:
10.1109/tdsc.2021.3138427 - 发表时间:
2023-01 - 期刊:
- 影响因子:0
- 作者:
王文浩;Weijie Liu;Hongbo Chen;XiaoFeng Wang;Hongliang Tian;林东岱 - 通讯作者:
林东岱
XiaoFeng Wang的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('XiaoFeng Wang', 18)}}的其他基金
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
- 批准号:
2207231 - 财政年份:2022
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
BIGDATA: IA: Enabling Large-Scale, Privacy-Preserving Genomic Computing with a Hardware-Assisted Secure Big-Data Analytics Framework
BIGDATA:IA:利用硬件辅助的安全大数据分析框架实现大规模、隐私保护的基因组计算
- 批准号:
1838083 - 财政年份:2019
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Understanding and Discovering Illicit Online Business Through Automatic Analysis of Online Text Traces
SaTC:核心:媒介:协作:通过自动分析在线文本痕迹理解和发现非法在线业务
- 批准号:
1801432 - 财政年份:2018
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
TWC: Small: Safeguarding Mobile Cloud Services: New Challenges and Solutions
TWC:小型:保护移动云服务:新挑战和解决方案
- 批准号:
1618493 - 财政年份:2016
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
TWC: Small: Understanding and Mitigating the Security Hazards of Mobile Fragmentation
TWC:小:了解和减轻移动碎片的安全隐患
- 批准号:
1527141 - 财政年份:2015
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Broker Leads for Privacy-Preserving Discovery in Health Information Exchange
TWC:媒介:协作:经纪人主导健康信息交换中的隐私保护发现
- 批准号:
1408874 - 财政年份:2014
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
TWC: Small: Knowing Your Enemy: Understanding and Counteracting Web Malvertising
TWC:小:了解你的敌人:理解和对抗网络恶意广告
- 批准号:
1223477 - 财政年份:2012
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
TWC: Small: Secure Data-Intensive Computing on Hybrid Clouds
TWC:小型:混合云上的安全数据密集型计算
- 批准号:
1223495 - 财政年份:2012
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
TC: Small: Plugging Logic Loopholes in Hybrid Web Applications to Secure Web Commerce
TC:小:堵塞混合 Web 应用程序中的逻辑漏洞以保护 Web 商务
- 批准号:
1117106 - 财政年份:2011
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
TC: Small: Reining in Side-Channel Information Leaks in the Software-as-a-Service Era
TC:小型:控制软件即服务时代的侧通道信息泄漏
- 批准号:
1017782 - 财政年份:2010
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
- 批准号:
2413046 - 财政年份:2024
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: EDU: RoCCeM: Bringing Robotics, Cybersecurity and Computer Science to the Middled School Classroom
合作研究:SaTC:EDU:RoCCeM:将机器人、网络安全和计算机科学带入中学课堂
- 批准号:
2312057 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
- 批准号:
2317830 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
- 批准号:
2318843 - 财政年份:2023
- 资助金额:
$ 55万 - 项目类别:
Continuing Grant