Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain

协作提案:SaTC:前沿:实现安全可信的软件供应链

基本信息

  • 批准号:
    2206859
  • 负责人:
  • 金额:
    $ 86.48万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2022
  • 资助国家:
    美国
  • 起止时间:
    2022-10-01 至 2027-09-30
  • 项目状态:
    未结题

项目摘要

The modern world relies on software in almost every human endeavor, and a typical software product includes 80% open source components. Attackers find and exploit accidentally-injected security vulnerabilities and, increasingly, aggressively implant vulnerabilities or malicious code directly into the software supply chain -- the open source software and its build and deployment pipelines. This Frontiers project establishes the Secure Software Supply Chain Center (S3C2), a large-scale, multi-institution effort designed to aid the software industry re-establish trust in the software supply chain through the development of scientific principles, synergistic tools, metrics, and models in the context of human behavior among software supply chain stakeholders. The project’s novelties include the contributions to a diverse workforce that is trained in secure software supply chain methods through research and outreach initiatives, including summer research experiences for undergraduates (REU), summer camps, and the development of course modules for undergraduates, graduate students, and practitioners. The project’s broader significance and importance are the ways in which S3C2 will facilitate rapid innovation with increased confidence in software supply chain security. S3C2 focuses on interconnected research thrusts for two supply chain attack vectors: (1) upstream dependencies and (2) the build process in the context of a continuous integration/continuous deployment (CI/CD) pipeline. Thrust One focuses on developing tools and techniques to aid practitioners with the risk of upstream dependencies. It enhances the utility of the Software Bill of Materials (SBoM) by identifying exploitability of vulnerabilities and changes to attack surfaces and isolates risky code as a stop-gap before patching is possible. Thrust Two focuses on developing tools and techniques to aid practitioners with the risk of build processes. It enables strong guarantees for build integrity through analysis of CI/CD configuration and techniques that help developers achieve reproducible builds.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
现代世界几乎每一项人类工作都依赖于软件,一个典型的软件产品包括80%的开源组件。攻击者发现并利用意外注入的安全漏洞,并日益咄咄逼人地将漏洞或恶意代码直接植入软件供应链--开源软件及其构建和部署管道。这个Frontiers项目建立了安全软件供应链中心(S3C2),这是一个大规模的、多机构的努力,旨在通过在软件供应链利益相关者之间的人类行为背景下开发科学原则、协同工具、指标和模型来帮助软件行业重新建立对软件供应链的信任。该项目的新颖性包括通过研究和推广计划,包括本科生暑期研究体验(REU)、夏令营和为本科生、研究生和实践者开发课程模块,为接受安全软件供应链方法培训的多样化劳动力做出贡献。该项目更广泛的意义和重要性在于,S3C2将促进快速创新,增强对软件供应链安全的信心。S3C2专注于两个供应链攻击矢量的相互关联的研究推力:(1)上游依赖关系和(2)持续集成/持续部署(CI/CD)管道中的构建过程。第一推力专注于开发工具和技术,以帮助实践者应对上游依赖的风险。它通过识别漏洞的可利用性和对攻击面的更改来增强软件材料清单(SBoM)的效用,并在可能打补丁之前隔离风险代码作为权宜之计。第二个重点是开发工具和技术来帮助实践者应对构建过程的风险。它通过分析CI/CD配置和帮助开发商实现可复制建筑的技术,为建筑完整性提供强有力的保证。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Christian Kastner其他文献

The Leadership factor: A study of leadership-styles in transformation
领导因素:转型中的领导风格研究
  • DOI:
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Christian Kastner
  • 通讯作者:
    Christian Kastner
Multi-laboratory evaluation of the reproducibility of polymer biodegradation assessments applying standardized and modified respirometry methods
应用标准化和改良呼吸测定法对聚合物生物降解评估的再现性的多实验室评估
  • DOI:
    10.1016/j.scitotenv.2023.166339
  • 发表时间:
    2023-11-25
  • 期刊:
  • 影响因子:
    8.000
  • 作者:
    Kathleen McDonough;Glauco Battagliarin;Jennifer Menzies;Jared Bozich;Marlies Bergheim;Bjorn Hidding;Christian Kastner;Bahar Koyuncu;Georg Kreutzer;Hans Leijs;Yash Parulekar;Meera Raghuram;Nathalie Vallotton
  • 通讯作者:
    Nathalie Vallotton
The Role of a Leader: Transformational Efforts in Innovation and Change
领导者的角色:创新和变革中的转型努力
  • DOI:
    10.1007/978-3-030-57642-4_6
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Christian Kastner
  • 通讯作者:
    Christian Kastner
MAREG and WinMAREG A tool for marginal regression models
MAREG 和 WinMAREG 边际回归模型工具
  • DOI:
  • 发表时间:
    1997
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Christian Kastner;Andreas Fieger;C. Heumann
  • 通讯作者:
    C. Heumann

Christian Kastner的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Christian Kastner', 18)}}的其他基金

Collaborative Research: SHF: Core: Medium: Causal Performance Debugging for Highly-Configurable Systems
协作研究:SHF:核心:中:高度可配置系统的因果性能调试
  • 批准号:
    2106853
  • 财政年份:
    2021
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
Collaborative Research: DASS: Policy Design for Holding AI-Supported Systems Accountable
合作研究:DASS:让人工智能支持的系统承担责任的政策设计
  • 批准号:
    2131477
  • 财政年份:
    2021
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
NSF Student and Early-Career Faculty Travel Grant for IEEE International Conference on Software Engineering 2020 (ICSE)
NSF 学生和早期职业教师 2020 年 IEEE 国际软件工程会议 (ICSE) 旅费补助
  • 批准号:
    2002420
  • 财政年份:
    2020
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
NSF Student and Early-Career Faculty Travel Grant for IEEE International Conference on Software Engineering 2019 (ICSE)
NSF 学生和早期职业教师 2019 年 IEEE 国际软件工程会议 (ICSE) 旅费补助
  • 批准号:
    1922878
  • 财政年份:
    2019
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
SHF: SMALL: Streamlining Fork-Based Software Development
SHF:小型:简化基于分叉的软件开发
  • 批准号:
    1813598
  • 财政年份:
    2018
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Trustworthy Dependency Management
SaTC:核心:小型:值得信赖的依赖管理
  • 批准号:
    1717022
  • 财政年份:
    2017
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
CAREER:VARIATIONAL EXECUTION
职业:变量执行
  • 批准号:
    1552944
  • 财政年份:
    2016
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
SHF: Small: Reverse Engineering Variability Implementations
SHF:小型:逆向工程可变性实施
  • 批准号:
    1318808
  • 财政年份:
    2013
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant

相似海外基金

Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
  • 批准号:
    2401496
  • 财政年份:
    2023
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
Collaborative Research: Conference: SaTC: CORE: 2.0 Vision Proposal
协作研究:会议:SaTC:核心:2.0 愿景提案
  • 批准号:
    2316833
  • 财政年份:
    2023
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
Collaborative Research: Conference: SaTC: CORE: 2.0 Vision Proposal
协作研究:会议:SaTC:核心:2.0 愿景提案
  • 批准号:
    2316832
  • 财政年份:
    2023
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Standard Grant
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
协作提案:SaTC:前沿:确保边缘化和弱势群体的计算未来
  • 批准号:
    2207019
  • 财政年份:
    2022
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
  • 批准号:
    2207216
  • 财政年份:
    2022
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
协作提案:SaTC:前沿:确保边缘化和弱势群体的计算未来
  • 批准号:
    2205171
  • 财政年份:
    2022
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain
协作提案:SaTC:前沿:实现安全可信的软件供应链
  • 批准号:
    2206921
  • 财政年份:
    2022
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
  • 批准号:
    2207218
  • 财政年份:
    2022
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
  • 批准号:
    2207214
  • 财政年份:
    2022
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
协作提案:SaTC:前沿:确保边缘化和弱势群体的计算未来
  • 批准号:
    2206950
  • 财政年份:
    2022
  • 资助金额:
    $ 86.48万
  • 项目类别:
    Continuing Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了