课题基金 / 基金详情

CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure

CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure
CICI:TCR:网络基础设施的及时、可靠和安全的安全更新
批准号:
2319880
负责人:
Jun Xu
金额:
$119.81万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-09-01 至 2026-08-31

项目摘要

项目成果

Jun Xu的其他基金

相似基金

相关文献

中文摘要
翻译
网络基础设施在国家的关键基础设施中发挥着至关重要的作用,推动了科学、工程、教育和合作的进步。然而,网络基础设施也因其高价值的数据(如核试验结果)和海量的计算资源(如超级计算机)而成为网络攻击者的完美目标。数据显示,网络基础设施受到网络攻击的频率越来越高,对经济、环境、公共卫生乃至国家安全造成了显著破坏。该项目旨在转变最新的网络安全进步和技术,以增强网络基础设施在网络威胁下的应变能力。根据US-CERT的说法,该项目尤其确保以及时、可靠和安全的方式采用在网络基础设施上运行的软件系统的安全更新或补丁,这可以帮助消除高达85%的定向攻击。这些研究成果推动了在具有挑战性的条件下进行软件修补的科学研究,这些条件包括有限的资金、不足的管理专业知识和高度多样化的环境。研究成果还预计将部署到大型网络基础设施平台,包括犹他州CHPC(一个5600用户的平台)和许多类似的平台(例如,PNNL、ORNL和罗格斯高级研究计算办公室)。在技术上,该项目开发了三项创新,以提供网络基础设施所需的安全更新。首先,它采用最近的开源框架,为网络基础设施提供负担得起的补丁管理,并探索补丁存在检测和自动漏洞利用生成方面的研究进展,以检测未采用的补丁并评估其紧迫性。其次,引入直接模糊测试和回归模糊测试作为评估网络基础设施补丁质量的方法,并定制了差分程序分析方法来分析测试结果和衡量可用补丁的可靠性。第三,它开发了系统范围的相关性分析,以了解受目标补丁程序影响并受分析结果影响的组件,动态组装低成本试验台,以评估整个系统的补丁程序的安全性。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cyberinfrastructure plays a crucial role in the nation's critical infrastructures, driving advancements in science, engineering, education, and collaboration. However, cyberinfrastructure also becomes a perfect target for cyber attackers, due to its high-value data (e.g., nuclear test results) and massive computing resources (e.g., supercomputers). As shown by data, cyber attacks are happening to cyberinfrastructure more frequently, causing remarkable damage to the economy, environment, public health, and even national security. This project aims to transition recent cybersecurity advancements and techniques for enhancing cyberinfrastructure resilience under cyber threats. In particular, this project ensures that security updates, or patches, for software systems running on cyberinfrastructure are adopted in a timely, reliable, and safe way, which can help eliminate up to 85 percent of targeted attacks, according to US-CERT. The research outcomes advance the scientific study of software patching under challenging conditions such as limited monetary resources, insufficient admin expertise, and highly diverse environments. The research outcomes are also projected to deploy to large-scale cyberinfrastructure platforms, including Utah CHPC (a 5,600-user platform) and many similar platforms (e.g., PNNL, ORNL, and the Rutgers Office of Advanced Research Computing).Technically, this project develops three innovations to offer security updates desired by cyberinfrastructure. First, it adapts recent open-source frameworks to provide affordable patch management for cyberinfrastructure and explores research advancements in patch presence detection and automated exploit generation to detect unadopted patches and assess their urgency. Second, it introduces directed fuzz testing and regression fuzz testing as methods to evaluate patch quality for cyberinfrastructure and tailors differential program analysis to analyze the testing outcomes and measure the reliability of available patches. Third, it develops a system-wide dependency analysis to understand the components impacted by a target patch and informed by the analysis result, assembles a low-cost testbed on the fly to assess the safety of the patch to the entire system.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Fuzzing Large Software: Principles, Methods, and Tools
  • 批准号:
    2340198
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $55.55万
  • 财政年份:
    2024
  • 负责人:
    Jun Xu
  • 依托单位:
Travel: NSF Student Travel Grant for 2023 ACM Conference on Computer and Communications Security (CCS)
  • 批准号:
    2341773
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.5万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2213727
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2022
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2031377
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2020
  • 负责人:
    Jun Xu
  • 依托单位:
国内基金
海外基金
高效Mage转座系统赋能KRAS G12D突变结直肠癌新型TCR-T疗法开发临床前研究
双靶向CAR-TCR-T疗法克服小细胞肺癌肿瘤异质性的机制探索
  • 批准号:
    JCZRLH202601115
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
  • 依托单位:
Piezo1驱动的人工合成TCR-T精准靶向肝癌的治疗研究
  • 批准号:
    2026JJ60274
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
    肖潺潺
  • 依托单位:
靶向PIK3CA突变的TCR-TCE NV制备及其在妊娠乳腺癌治疗中的研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李罗
  • 依托单位: