Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
批准号:
2213727
负责人:
Jun Xu
金额:
$59.6万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-01-01 至 2024-09-30
中文摘要
在软件中,漏洞是代码中的缺陷,恶意行为者可以利用该缺陷来执行未经授权的活动或更改软件的行为。尽管安全研究人员对此进行了大量研究,但由于日常生活中广泛使用的软件变得越来越大和越来越复杂,查找软件漏洞变得越来越具有挑战性。这个项目通过重新思考一种名为Fuzing的经典技术来解决这一挑战,该技术用于从大型软件中查找漏洞。模糊的高级思想是创建大量随机输入来运行软件,进而触发漏洞。这个项目的新颖性在于新的方法、技术和工具,这些方法、技术和工具彻底改变了模糊,并使几乎随机的测试过程更加智能和有针对性。这样,该项目将增强各种类型的广泛使用的软件的安全性,从Web浏览器到服务器端程序。为此,该项目正在研究漏洞覆盖驱动的模糊。现有的模糊技术主要遵循一种称为代码覆盖驱动模糊的方法,其动机是代码覆盖和漏洞查找紧密相关。该项目挑战了这一普遍持有的信念,表明代码覆盖与漏洞的联系弱于预期,代码覆盖驱动的模糊不太适合漏洞查找。作为漏洞覆盖驱动模糊技术的先驱,该项目发明了一系列新技术,以(1)获取漏洞覆盖的反馈;(2)确定可触及更多漏洞的测试输入的优先顺序;(3)最大限度地增加测试输入触发漏洞的机会。该项目还产生了新的指标、新的基准和新的框架,用于全面评估Fuzing用于漏洞查找的使用情况。凭借研究人员在软件安全和系统安全方面的研究经验,本项目为本科生和研究生提供了一批教育、培训和研究机会。通过行业外展,调查人员寻求技术转让并提高软件安全意识。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
In software, a vulnerability is a flaw in the code that can be exploited by a malicious actor to perform unauthorized activities or change the behavior of the software. Although a topic heavily studied by security researchers, finding software vulnerabilities is becoming increasingly challenging because the software widely used in day-to-day life is growing larger and more complicated. This project addresses this challenge by rethinking a classic technique called fuzzing for finding vulnerabilities from large software. The high-level idea of fuzzing is to create a large number of random inputs to run software and in turn trigger vulnerabilities. The novelties of this project are the new approaches, techniques, and tools that revolutionize fuzzing and make the nearly random testing process more intelligent and targeted. This way, this project will enhance security of various types of widely used software, ranging from web browsers to server-side programs.To that end, this project is investigating vulnerability-coverage-driven fuzzing. Existing fuzzing techniques primarily followed an approach called code-coverage-driven fuzzing, motivated by the belief that code coverage and vulnerability finding are strongly correlated. Challenging this widely held belief, this project shows that code coverage has weaker-than-expected ties with vulnerabilities and code-coverage-driven fuzzing is not well suited for vulnerability finding. Pioneering vulnerability-coverage-driven fuzzing, this project invents a series of novel techniques to (1) obtain feedback on vulnerability coverage (2) prioritize test inputs that can reach more vulnerabilities and (3) maximize the chance to trigger vulnerabilities reached by the test inputs. This project also produces new metrics, new benchmarks, and new frameworks for comprehensively evaluating the use of fuzzing for vulnerability finding. With the investigators' experience in research of software security and system security, this project provides a group of education, training, and research opportunities for both undergraduate and graduate students. Through industry outreach, the investigators pursue technology transfers and raise the awareness of software security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.48550/arxiv.2203.06834
发表时间:
2022-03
期刊:
ArXiv
影响因子:
--
作者:
[Ruotong Yu;Francesca Del Nin;Yuchen Zhang;Shan Huang;Pallavi Kaliyar;Sarah Zakto;M. Conti;G. Portokalidis;Jun Xu]
通讯作者:
Ruotong Yu;Francesca Del Nin;Yuchen Zhang;Shan Huang;Pallavi Kaliyar;Sarah Zakto;M. Conti;G. Portokalidis;Jun Xu
Towards Understanding the Runtime Performance of Rust
理解 Rust 的运行时性能
DOI:
10.1145/3551349.3559494
发表时间:
2023
期刊:
Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering
影响因子:
--
作者:
[Zhang, Yuchen, Zhang, Yunhang, Portokalidis, Georgios, Xu, Jun]
通讯作者:
Xu, Jun
CAREER: Fuzzing Large Software: Principles, Methods, and Tools
-
批准号:2340198
-
项目类别:Continuing Grant
-
资助金额:$55.55万
-
财政年份:2024
-
负责人:Jun Xu
-
依托单位:
Travel: NSF Student Travel Grant for 2023 ACM Conference on Computer and Communications Security (CCS)
-
批准号:2341773
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2023
-
负责人:Jun Xu
-
依托单位:
CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure
-
批准号:2319880
-
项目类别:Standard Grant
-
资助金额:$119.81万
-
财政年份:2023
-
负责人:Jun Xu
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
-
批准号:2031377
-
项目类别:Standard Grant
-
资助金额:$59.6万
-
财政年份:2020
-
负责人:Jun Xu
-
依托单位:
CNS Core: Small: Towards Hybrid Data Center Switching Using Partially Reconfigurable Circuit Switch
-
批准号:2007006
-
项目类别:Standard Grant
-
资助金额:$41.73万
-
财政年份:2020
-
负责人:Jun Xu
-
依托单位:
CNS Core: Small: Ultra-Low-Complexity Switching Algorithms for Scalable High Network Performance
-
批准号:1909048
-
项目类别:Standard Grant
-
资助金额:$43.27万
-
财政年份:2019
-
负责人:Jun Xu
-
依托单位:
NeTS: Small: Collaborative Research: Research into Worst-Case Large Deviation Theory for Network Algorithmics
-
批准号:1423182
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2014
-
负责人:Jun Xu
-
依托单位:
NeTS: Medium: Collaborative Research: Towards Building Time Capsule for Online Social Activities
-
批准号:1302197
-
项目类别:Standard Grant
-
资助金额:$30.4万
-
财政年份:2013
-
负责人:Jun Xu
-
依托单位:
NeTS: Small: Collaborative Research: Towards Principled Network Troubleshooting via Efficient Packet Stream Processing
-
批准号:1218092
-
项目类别:Standard Grant
-
资助金额:$30.6万
-
财政年份:2012
-
负责人:Jun Xu
-
依托单位:
SBIR Phase I: Nanocomposites for Electronic Packaging
-
批准号:0912544
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2009
-
负责人:Jun Xu
-
依托单位:
NeTS: Medium:Collaborative Research: Towards Versatile and Programmable Measurement Architecture for Future Networks
-
批准号:0905169
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2009
-
负责人:Jun Xu
-
依托单位:
NetSE: Large: Collaborative Research: FieldStream: Network Data Services for Exposure Biology Studies in Natural Environments
-
批准号:0910592
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2009
-
负责人:Jun Xu
-
依托单位:
DHB: Collaborative Research: Cultural and Genetic Basis of Social Support Use
-
批准号:0734230
-
项目类别:Standard Grant
-
资助金额:$16.29万
-
财政年份:2008
-
负责人:Jun Xu
-
依托单位:
Collaborative Research: CT-ISG: Accurate Sampling of the Internet for Effective Anomaly Detection
-
批准号:0716423
-
项目类别:Continuing Grant
-
资助金额:$17.5万
-
财政年份:2007
-
负责人:Jun Xu
-
依托单位:
NeTS-NBD: Accurate Estimation of Network Measurement Matrices Using Multiple Data Sources
-
批准号:0626979
-
项目类别:Continuing Grant
-
资助金额:$24.0万
-
财政年份:2006
-
负责人:Jun Xu
-
依托单位:
NeTS-NBD: Network Data Streaming for Measurement and Monitoring of Future High-Speed Networks
-
批准号:0519745
-
项目类别:Continuing Grant
-
资助金额:$28.6万
-
财政年份:2005
-
负责人:Jun Xu
-
依托单位:
CAREER: Fundamental Lower Bound and Tradeoff Problems in Networking
-
批准号:0238315
-
项目类别:Standard Grant
-
资助金额:$42.07万
-
财政年份:2003
-
负责人:Jun Xu
-
依托单位:
ITR/SY: Mandatory Human Participation: A New Paradigm for Building Secure Systems
-
批准号:0113933
-
项目类别:Standard Grant
-
资助金额:$28.8万
-
财政年份:2001
-
负责人:Jun Xu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: