课题基金 / 基金详情

CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure

CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure
CICI:TCR:网络基础设施的及时、可靠和安全的安全更新
批准号:
2319880
负责人:
Jun Xu
金额:
$119.81万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-09-01 至 2026-08-31

项目摘要

项目成果

Jun Xu的其他基金

相似基金

相关文献

中文摘要
翻译
网络基础设施在国家关键基础设施中发挥着至关重要的作用,推动着科学、工程、教育和协作的进步。然而,网络基础设施也因其高价值的数据(如核试验结果)和庞大的计算资源(如超级计算机)而成为网络攻击者的完美目标。数据显示,网络攻击对网络基础设施的影响日益频繁,对经济、环境、公共卫生乃至国家安全造成的损害显著。该项目旨在将最新的网络安全进展和技术转化为增强网络基础设施在网络威胁下的弹性。根据US-CERT的说法,该项目特别确保在网络基础设施上运行的软件系统及时、可靠和安全地采用安全更新或补丁,这可以帮助消除高达85%的目标攻击。研究成果推动了在资金有限、管理专业知识不足和高度多样化的环境等具有挑战性的条件下对软件补丁的科学研究。研究成果还预计将部署到大型网络基础设施平台,包括犹他州CHPC(5600用户平台)和许多类似平台(例如,PNNL, ORNL和罗格斯大学高级研究计算办公室)。从技术上讲,该项目开发了三种创新,以提供网络基础设施所需的安全更新。首先,它采用了最新的开源框架,为网络基础设施提供负担得起的补丁管理,并探索了补丁存在检测和自动漏洞生成方面的研究进展,以检测未采用的补丁并评估其紧迫性。其次,引入定向模糊测试和回归模糊测试作为评估网络基础设施补丁质量的方法,并定制差异程序分析来分析测试结果并衡量可用补丁的可靠性。第三,它开发了一个系统范围的依赖分析,以了解受目标补丁影响的组件,并根据分析结果提供信息,在飞行中组装一个低成本的测试平台,以评估补丁对整个系统的安全性。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cyberinfrastructure plays a crucial role in the nation's critical infrastructures, driving advancements in science, engineering, education, and collaboration. However, cyberinfrastructure also becomes a perfect target for cyber attackers, due to its high-value data (e.g., nuclear test results) and massive computing resources (e.g., supercomputers). As shown by data, cyber attacks are happening to cyberinfrastructure more frequently, causing remarkable damage to the economy, environment, public health, and even national security. This project aims to transition recent cybersecurity advancements and techniques for enhancing cyberinfrastructure resilience under cyber threats. In particular, this project ensures that security updates, or patches, for software systems running on cyberinfrastructure are adopted in a timely, reliable, and safe way, which can help eliminate up to 85 percent of targeted attacks, according to US-CERT. The research outcomes advance the scientific study of software patching under challenging conditions such as limited monetary resources, insufficient admin expertise, and highly diverse environments. The research outcomes are also projected to deploy to large-scale cyberinfrastructure platforms, including Utah CHPC (a 5,600-user platform) and many similar platforms (e.g., PNNL, ORNL, and the Rutgers Office of Advanced Research Computing).Technically, this project develops three innovations to offer security updates desired by cyberinfrastructure. First, it adapts recent open-source frameworks to provide affordable patch management for cyberinfrastructure and explores research advancements in patch presence detection and automated exploit generation to detect unadopted patches and assess their urgency. Second, it introduces directed fuzz testing and regression fuzz testing as methods to evaluate patch quality for cyberinfrastructure and tailors differential program analysis to analyze the testing outcomes and measure the reliability of available patches. Third, it develops a system-wide dependency analysis to understand the components impacted by a target patch and informed by the analysis result, assembles a low-cost testbed on the fly to assess the safety of the patch to the entire system.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Fuzzing Large Software: Principles, Methods, and Tools
  • 批准号:
    2340198
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $55.55万
  • 财政年份:
    2024
  • 负责人:
    Jun Xu
  • 依托单位:
Travel: NSF Student Travel Grant for 2023 ACM Conference on Computer and Communications Security (CCS)
  • 批准号:
    2341773
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.5万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2213727
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2022
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2031377
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2020
  • 负责人:
    Jun Xu
  • 依托单位:
国内基金
海外基金
高效Mage转座系统赋能KRAS G12D突变结直肠癌新型TCR-T疗法开发临床前研究
双靶向CAR-TCR-T疗法克服小细胞肺癌肿瘤异质性的机制探索
  • 批准号:
    JCZRLH202601115
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
  • 依托单位:
Piezo1驱动的人工合成TCR-T精准靶向肝癌的治疗研究
  • 批准号:
    2026JJ60274
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
    肖潺潺
  • 依托单位:
靶向PIK3CA突变的TCR-TCE NV制备及其在妊娠乳腺癌治疗中的研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李罗
  • 依托单位: