课题基金 / 基金详情

Collaborative Research: SaTC: TTP: Small: eSLIC: Enhanced Security Static Analysis for Detecting Insecure Configuration Scripts

Collaborative Research: SaTC: TTP: Small: eSLIC: Enhanced Security Static Analysis for Detecting Insecure Configuration Scripts
协作研究:SaTC:TTP:小型:eSLIC:用于检测不安全配置脚本的增强安全静态分析
批准号:
2247141
负责人:
Akond Ashfaque Rahman
金额:
$24.47万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-10-01 至 2024-09-30

项目摘要

项目成果

Akond Ashfaque Rahman的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Information technology (IT) organizations manage infrastructure using configuration scripts. Configuration scripts help practitioners to accomplish a wide range of jobs, including cloud computing, scientific research, and large-scale data analytics. Even though configuration scripts enable scalable and rapid delivery of software, security weaknesses in configuration scripts, such as hard-coded passwords, can result in security and privacy problems such as data breaches. Current research of configuration script security is limited in finding types of problems that can be detected, preventing false positives, and enabling actionability—all of which prohibits practitioners to take actions on the identified security weaknesses, potentially leaving computing systems open to security attacks. The project aims to address these limitations. The project’s novelties are development of techniques and tools that will automatically detect security weaknesses in configuration scripts developed using a wide range of languages, heavily used in industry. The project's impacts are related to securing the national cyber infrastructure, educating the next generation IT workforce on cybersecurity, and broadening of participation through recruitment of underrepresented communities. The project will focus on the development of techniques and tools that will automatically detect security weaknesses in configuration scripts developed using a wide range of languages heavily used in industry. Three main tasks will be investigated for this project. First, qualitative analysis is applied in order to determine a comprehensive list of security weaknesses for multiple configuration script languages, and devise static analysis techniques for automatically identifying each category of security weakness. Next, grammar-based parsing and machine learning techniques are applied, evaluated, and integrated into the derived static analysis so that false positives are reduced. Finally, the development context of practitioners from the open source and proprietary domain will be systematically mined to generate actionable alerts and suggestions, which will enable practitioners to fix security weaknesses. Along with the three technical tasks, industry panels will be organized, where practitioners from industry will give feedback on the developed techniques and tools. Findings from the project will be disseminated to government, industry and open source practitioners, as well as to students who are learning about configuration management in graduate and undergraduate level courses related to cybersecurity. The project is expected to generate best practices for security code review, automated tools, and education materials essential to secure configuration script development. As a transition to practice (TTP) project, it will facilitate collaboration with industry practitioners, so that a comprehensive, holistic, practitioner-friendly security static analysis is achieved to secure configuration script development and management.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1007/s10664-023-10328-5
发表时间: 2023-06
期刊: Empirical Software Engineering
影响因子: 4.1
作者: [A. Rahman;Dibyendu Brinto Bose;Raunak Shakya;Rahul Pandita]
通讯作者: A. Rahman;Dibyendu Brinto Bose;Raunak Shakya;Rahul Pandita
Detecting and Characterizing Propagation of Security Weaknesses in Puppet-based infrastructure Management
检测和表征基于 Puppet 的基础设施管理中安全漏洞的传播
DOI: 10.1109/tse.2023.3265962
发表时间: 2023
期刊: IEEE Transactions on Software Engineering
影响因子: 7.4
作者: [Rahman, Akond, Parnin, Chris]
通讯作者: Parnin, Chris
Survey - Ansible Test Smell
调查 - Ansible 测试气味
DOI: 10.6084/m9.figshare.21699269.v1
发表时间: 2023
期刊: figshare
影响因子: --
作者: [Rahman, Akond]
通讯作者: Rahman, Akond
Dataset - Defects in Ansible Infrastructure Orchestrator
数据集 - Ansible Infrastructure Orchestrator 中的缺陷
DOI: 10.6084/m9.figshare.21638090.v1
发表时间: 2023
期刊: figshare
影响因子: --
作者: [Rahman, Akond]
通讯作者: Rahman, Akond
10
    SHF: Small: Resilient Operations for Deployment Units Used in Container Orchestration
    • 批准号:
      2312321
    • 项目类别:
      Standard Grant
    • 资助金额:
      $55.33万
    • 财政年份:
      2023
    • 负责人:
      Akond Ashfaque Rahman
    • 依托单位:
    Authentic Learning Modules for DevOps Security Education
    • 批准号:
      2310179
    • 项目类别:
      Standard Grant
    • 资助金额:
      $15.4万
    • 财政年份:
      2023
    • 负责人:
      Akond Ashfaque Rahman
    • 依托单位:
    Authentic Learning Modules for DevOps Security Education
    • 批准号:
      2209636
    • 项目类别:
      Standard Grant
    • 资助金额:
      $15.4万
    • 财政年份:
      2022
    • 负责人:
      Akond Ashfaque Rahman
    • 依托单位:
    Collaborative Research: SaTC: TTP: Small: eSLIC: Enhanced Security Static Analysis for Detecting Insecure Configuration Scripts
    • 批准号:
      2026869
    • 项目类别:
      Standard Grant
    • 资助金额:
      $24.47万
    • 财政年份:
      2020
    • 负责人:
      Akond Ashfaque Rahman
    • 依托单位:
    国内基金
    海外基金
    Research on Quantum Field Theory without a Lagrangian Description
    • 批准号:
      24ZR1403900
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
      SATOSHI NAWATA
    • 依托单位:
    Cell Research
    Cell Research
    Cell Research (细胞研究)