CAREER: Cross-Boundary Program Analyses for Web Applications
CAREER: Cross-Boundary Program Analyses for Web Applications
批准号:
2321444
负责人:
Weihang Wang
金额:
$50.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-03-01 至 2026-08-31
中文摘要
现代Web应用程序建立在以不同编程语言编写并由多方分发的程序集成的基础上。虽然这样的开发模型提供了最大的模块化和灵活性,但它对传统的软件工程原则提出了独特的挑战。当Web应用程序无法按预期运行时,由于缺乏跨语言分析支持,开发人员经常需要独立地分析用各种语言编写的代码组件。动态地包含来自多方的源代码使得识别错误的根本原因变得具有挑战性,因为开发人员无法访问第三方内部。不同的语言和第三方的使用形成了技术界限,使Web开发人员无法全面了解客户端的异类代码。该项目解决了复杂Web应用程序中存在的技术边界的挑战,并为理解、分析和调试涉及多种语言和多方的Web应用程序创建了科学基础。该项目将支持网络应用程序的可靠性,提高网络开发生产率,并通过保护网络用户免受常见网络问题的影响,为他们提供关键保证。该项目计划构建一种策略规范语言,使Web开发人员能够编写规范策略来规范其代码执行的许多方面,例如强制执行关键事件的控制流,在存在未知第三方服务的情况下保护网页,以及确保用户体验。基于这些策略,将开发新的程序分析和运行时技术,以分别暴露可能的违规(用于识别问题)和自动策略实施(用于修复问题)。策略规范和执行将为Web开发人员提供保证,并使他们能够控制在其网站上执行的代码,这是当前技术所缺乏的。将开发支持跨语言分析的方法,以处理不同编程语言之间的交互,包括WebAssembly和JavaScript。总之,这些活动将加深对复杂网络应用程序中技术边界的科学理解,并创建新的程序分析技术来支持更高效的网络开发。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Modern web applications are built atop the integration of programs written in diverse programming languages and distributed by multiple parties. While such a development model provides maximum modularity and flexibility, it raises unique challenges to traditional software-engineering principles. When web applications fail to behave as intended, developers often need to analyze code components written in various languages independently due to the lack of cross-language analysis support. Dynamically including source code from multiple parties makes it challenging to identify the root causes of errors because developers do not have access to third-party internals. Diverse languages and the use of third parties create technical boundaries that prevent web developers from obtaining a comprehensive understanding of the heterogeneous code on the client side. This project addresses the challenges of the technical boundaries existing in complex web applications and the creation of a scientific foundation for understanding, analyzing, and debugging web applications involving diverse languages and multiple parties. The project will support web-application reliability, increase web development productivity, and provide critical assurance for web users by shielding them from common web issues. The project plans to build a policy-specification language that enables web developers to compose specification policies to regulate many aspects of their code execution, such as enforcing control flow of critical events, securing web pages in the presence of unknown third-party services, and ensuring user experience. Based on these policies, novel program analyses and runtime techniques will be developed to expose possible violations (for problem identification) and automatic policy enforcement (for problem fixing), respectively. The policy specification and enforcement will provide assurance for web developers and enable them to control the code executed on their websites, which is lacking with current technologies. Approaches that support a cross-language analysis will be developed to handle interactions between diverse programming languages, including WebAssembly and JavaScript. Together, these activities will deepen the scientific understanding of the technical boundaries in complex web applications and create new program-analysis techniques to support more efficient web development.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Travel: NSF Student Travel Grant for 2023 IEEE Secure Development Conference (SecDev)
-
批准号:2329578
-
项目类别:Standard Grant
-
资助金额:$1.8万
-
财政年份:2023
-
负责人:Weihang Wang
-
依托单位:
NSF Student Travel Grant for 2022 IEEE Security Development (SecDev) Conference
-
批准号:2227930
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2022
-
负责人:Weihang Wang
-
依托单位:
CAREER: Cross-Boundary Program Analyses for Web Applications
-
批准号:2047980
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Weihang Wang
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胰岛素样生长信号介导的肺巨噬细胞和上皮细胞cross-tolk通过核自噬参与慢性气道炎症形成的机制研究
-
批准号:JCZRYB202500229
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:
-
依托单位:
基于NLRP3炎性小体与自噬Cross-talk探讨心康冲剂干预心肌纤维化的机制研究
-
批准号:2025JJ80174
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:邹菊英
-
依托单位:
PKM2琥珀酰化修饰介导癌细胞与血小板间Cross-talk调控胆管癌侵袭转移的研究
-
批准号:JCZRYB202500379
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:
-
依托单位:
基于破骨-成骨细胞Cross-Talk探讨内固定物存留对关节软骨退变的影响及补肾强骨治法的科学内涵
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
三痹汤激活线粒体自噬影响免疫细胞Cross talk延缓椎间盘退变的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:王楠
-
依托单位:
多环芳烃(PAHs )介导的癌细胞和Th17细胞“cross-talk”所
致免疫抑制反应在胶质瘤增殖侵袭中的作用及毒理学机制研
究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
PGK1乙酰化修饰介导癌细胞与TAMs间Cross-talk调控胆囊癌EMT的研究
-
批准号:82373032
-
项目类别:面上项目
-
资助金额:49万元
-
批准年份:2023
-
负责人:王剑明
-
依托单位:
线粒体ClpP激动剂通过铁死亡-免疫调控cross-talk治疗急性髓细胞白血病的机制研究
-
批准号:82370171
-
项目类别:面上项目
-
资助金额:49万元
-
批准年份:2023
-
负责人:吴俣
-
依托单位:
生长激素受体通过脂肪酸介导的肝脏-脂肪Cross-talk影响脂质内稳态的研究
-
批准号:82370866
-
项目类别:面上项目
-
资助金额:49万元
-
批准年份:2023
-
负责人:吴英杰
-
依托单位:
基于“cross-β折叠”结构形成理论解析面筋蛋白淀粉样纤维的形成机制
-
批准号:32372365
-
项目类别:面上项目
-
资助金额:50.00万元
-
批准年份:2023
-
负责人:张慧娟
-
依托单位: