CAREER: Context-Sensitive Fuzzing for Networked Systems
CAREER: Context-Sensitive Fuzzing for Networked Systems
批准号:
2339350
负责人:
Endadul Hoque
金额:
$53.87万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-07-01 至 2029-06-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Internet-facing security-critical network protocols are susceptible to exploitation by remote adversaries seeking to compromise overall security. These adversaries employ crafted inputs to exploit undisclosed or unpatched security flaws (bugs) in protocol implementations. Despite the common strategy of bug identification and patching, unearthing elusive bugs in protocol implementations remains challenging as it requires navigating stringent input validation to discover bugs that lurk deep in the code. Fuzzing, endorsed by the National Institute of Standards and Technology (NIST), automates security testing by passing abnormal inputs to programs in order to discover bugs. While fuzzing has effectively uncovered bugs in many real-world systems, it still struggles to generate semantically correct inputs essential for testing beyond initial input validation. This project bridges this gap in traditional fuzzing by developing an innovative automated solution that effectively enhances the testing of protocol implementations. The core objective of this project is to develop an automated, context-sensitive fuzzing approach that effectively uncovers bugs in security-critical protocol implementations. This project realizes its objective through activities across three complementary research thrusts. The first thrust designs a domain specific language to encode context-sensitive hierarchical structures of inputs and develops algorithms to efficiently generate semantically correct inputs. The second thrust devises several mutation techniques, essential for fuzzing, that will maintain the context-sensitivity of the input. The third thrust develops mechanisms to faithfully maintain the internal state of a stateful protocol so that each fuzz input can be tested in a suitable state of the protocol.This project has the potential to significantly enhance the robustness of protocol implementations, benefiting society. This project's education component includes organizing capture-the-flag (CTF) competitions, improving cybersecurity courses, and conducting K-12 workshops to raise cybersecurity awareness. Undergraduate and graduate students from historically marginalized communities will be recruited to increase their participation in research and educational activities.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CNS Core: Small: Retrofitting IoT Ecosystems with a Software-defined Overlay to Enforce Safety, Security, and Privacy Policies
-
批准号:2007512
-
项目类别:Standard Grant
-
资助金额:$25.01万
-
财政年份:2020
-
负责人:Endadul Hoque
-
依托单位:
国内基金
海外基金
基于Context建模的基因组数据压缩研究
-
批准号:61861045
-
项目类别:地区科学基金项目
-
资助金额:35.0万元
-
批准年份:2018
-
负责人:陈建华
-
依托单位:
Focus+Context支持的群集三维对象变形可视化
-
批准号:41671381
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2016
-
负责人:应申
-
依托单位:
基于Context建模的熵编码及其应用研究
-
批准号:61062005
-
项目类别:地区科学基金项目
-
资助金额:22.0万元
-
批准年份:2010
-
负责人:陈建华
-
依托单位: