课题基金 / 基金详情

Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain

Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain
协作提案:SaTC:前沿:实现安全可信的软件供应链
批准号:
2206921
负责人:
Michel Cukier
金额:
$100.14万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-10-01 至 2027-09-30

项目摘要

项目成果

Michel Cukier的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The modern world relies on software in almost every human endeavor, and a typical software product includes 80% open source components. Attackers find and exploit accidentally-injected security vulnerabilities and, increasingly, aggressively implant vulnerabilities or malicious code directly into the software supply chain -- the open source software and its build and deployment pipelines. This Frontiers project establishes the Secure Software Supply Chain Center (S3C2), a large-scale, multi-institution effort designed to aid the software industry re-establish trust in the software supply chain through the development of scientific principles, synergistic tools, metrics, and models in the context of human behavior among software supply chain stakeholders. The project’s novelties include the contributions to a diverse workforce that is trained in secure software supply chain methods through research and outreach initiatives, including summer research experiences for undergraduates (REU), summer camps, and the development of course modules for undergraduates, graduate students, and practitioners. The project’s broader significance and importance are the ways in which S3C2 will facilitate rapid innovation with increased confidence in software supply chain security. S3C2 focuses on interconnected research thrusts for two supply chain attack vectors: (1) upstream dependencies and (2) the build process in the context of a continuous integration/continuous deployment (CI/CD) pipeline. Thrust One focuses on developing tools and techniques to aid practitioners with the risk of upstream dependencies. It enhances the utility of the Software Bill of Materials (SBoM) by identifying exploitability of vulnerabilities and changes to attack surfaces and isolates risky code as a stop-gap before patching is possible. Thrust Two focuses on developing tools and techniques to aid practitioners with the risk of build processes. It enables strong guarantees for build integrity through analysis of CI/CD configuration and techniques that help developers achieve reproducible builds.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SFS for ACES
  • 批准号:
    1753857
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $504.63万
  • 财政年份:
    2018
  • 负责人:
    Michel Cukier
  • 依托单位:
REU Site: Undergraduates Engaged in Cyber Security Research
  • 批准号:
    1062820
  • 项目类别:
    Standard Grant
  • 资助金额:
    $35.45万
  • 财政年份:
    2011
  • 负责人:
    Michel Cukier
  • 依托单位:
TC: Small: Discovering Designer Intent through Dynamic Analysis of Malware
REU Sites: Undergraduates Engaged in the Experimental Evaluation of Computer Security
  • 批准号:
    0647321
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.86万
  • 财政年份:
    2007
  • 负责人:
    Michel Cukier
  • 依托单位:
海外基金