课题基金 / 基金详情

I-Corps: Data-Driven Risk Assessments for Software Vulnerabilities

I-Corps: Data-Driven Risk Assessments for Software Vulnerabilities
I-Corps:数据驱动的软件漏洞风险评估
批准号:
2244900
负责人:
Tudor Dumitras
金额:
$5.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
已结题
起止时间:
2023-01-01 至 2023-06-30

项目摘要

项目成果

Tudor Dumitras的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The broader impact/commercial potential of this I-Corps project is the development of technology that addresses inefficiencies in the software update processes by complementing existing vulnerability assessment tools and allowing practitioners to update critical vulnerabilities faster in order to reduce the risk of attacks. The World Economic Forum ranks cyberattacks among the top 10 global risks of the decade. One of the main causes for these incidents are exploits against software vulnerabilities. A recent survey revealed that 27% of participating organizations were breached due to unpatched vulnerabilities. The impact of vulnerability exploits can often be seen through infamous ransomware campaigns which have affected several critical infrastructure sectors. Vulnerability exploits have shifted from being primarily a financial concern, to being a societal issue threatening the environment, national security, and even human life. As a result, removing software vulnerabilities as a target of cyber attackers is an urgent necessity. The government and industrial organizations can mitigate the risk of attacks by remediating vulnerabilities within their enterprise networks through software updates.This I-Corps project is based on the development of a technology that focuses on mitigating the impact of vulnerability exploits, which are one of the principal enablers of cyberattacks, and can be prevented through software updates. This project will provide novel tools to address the operational challenges involved in managing software updates by offering automatic, data-driven risk assessments for vulnerabilities. These tools use machine learning to learn historical associations between vulnerabilities and attacks. During deployment, the technology identifies newly disclosed vulnerabilities, collects publicly available information, and uses the machine learning models to compute various components related to the risk of exploits and attacks against these vulnerabilities.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CRII: SaTC: Empirical and Analytical Models for the Deployment of Software Updates in Large Vulnerable Populations
  • 批准号:
    1464163
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.03万
  • 财政年份:
    2015
  • 负责人:
    Tudor Dumitras
  • 依托单位:
国内基金
海外基金
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
Data-driven Recommendation System Construction of an Online Medical Platform Based on the Fusion of Information
Development of a Linear Stochastic Model for Wind Field Reconstruction from Limited Measurement Data
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    40万元
  • 批准年份:
    2020
  • 负责人:
    Vikrant Gupta
  • 依托单位:
基于Linked Open Data的Web服务语义互操作关键技术
  • 批准号:
    61373035
  • 项目类别:
    面上项目
  • 资助金额:
    77.0万元
  • 批准年份:
    2013
  • 负责人:
    冯志勇
  • 依托单位: