CAREER: Context-Sensitive Fuzzing for Networked Systems

职业:网络系统的上下文敏感模糊测试

基本信息

  • 批准号:
    2339350
  • 负责人:
  • 金额:
    $ 53.87万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2024
  • 资助国家:
    美国
  • 起止时间:
    2024-07-01 至 2029-06-30
  • 项目状态:
    未结题

项目摘要

Internet-facing security-critical network protocols are susceptible to exploitation by remote adversaries seeking to compromise overall security. These adversaries employ crafted inputs to exploit undisclosed or unpatched security flaws (bugs) in protocol implementations. Despite the common strategy of bug identification and patching, unearthing elusive bugs in protocol implementations remains challenging as it requires navigating stringent input validation to discover bugs that lurk deep in the code. Fuzzing, endorsed by the National Institute of Standards and Technology (NIST), automates security testing by passing abnormal inputs to programs in order to discover bugs. While fuzzing has effectively uncovered bugs in many real-world systems, it still struggles to generate semantically correct inputs essential for testing beyond initial input validation. This project bridges this gap in traditional fuzzing by developing an innovative automated solution that effectively enhances the testing of protocol implementations. The core objective of this project is to develop an automated, context-sensitive fuzzing approach that effectively uncovers bugs in security-critical protocol implementations. This project realizes its objective through activities across three complementary research thrusts. The first thrust designs a domain specific language to encode context-sensitive hierarchical structures of inputs and develops algorithms to efficiently generate semantically correct inputs. The second thrust devises several mutation techniques, essential for fuzzing, that will maintain the context-sensitivity of the input. The third thrust develops mechanisms to faithfully maintain the internal state of a stateful protocol so that each fuzz input can be tested in a suitable state of the protocol.This project has the potential to significantly enhance the robustness of protocol implementations, benefiting society. This project's education component includes organizing capture-the-flag (CTF) competitions, improving cybersecurity courses, and conducting K-12 workshops to raise cybersecurity awareness. Undergraduate and graduate students from historically marginalized communities will be recruited to increase their participation in research and educational activities.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
面向互联网的安全关键网络协议很容易受到远程攻击者的攻击,从而危及整体安全。这些攻击者使用精心制作的输入来利用协议实现中未公开或未修补的安全缺陷(错误)。尽管有常见的bug识别和修补策略,但在协议实现中发现难以捉摸的bug仍然具有挑战性,因为它需要导航严格的输入验证来发现潜伏在代码深处的bug。Fuzzing由美国国家标准与技术研究所(NIST)认可,通过将异常输入传递给程序以发现错误来自动进行安全测试。虽然模糊化已经有效地发现了许多现实系统中的错误,但它仍然很难生成对于初始输入验证之外的测试至关重要的语义正确的输入。该项目通过开发一种创新的自动化解决方案,有效地增强了协议实现的测试,从而弥补了传统模糊测试的不足。该项目的核心目标是开发一种自动化的,上下文敏感的模糊方法,有效地发现安全关键协议实现中的错误。该项目通过三个互补研究方向的活动实现其目标。第一个推力设计了一个领域特定的语言来编码上下文敏感的层次结构的输入和开发算法,有效地生成语义正确的输入。第二个推力设计了几个突变技术,基本的模糊,这将保持输入的上下文敏感性。第三个目标是开发机制来忠实地维护有状态协议的内部状态,以便每个模糊输入都可以在协议的适当状态下进行测试。该项目有可能显著增强协议实现的健壮性,造福社会。该项目的教育部分包括组织“夺旗”(CTF)竞赛,改进网络安全课程,并举办K-12讲习班,以提高网络安全意识。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Endadul Hoque其他文献

Preserving privacy in wireless sensor networks using reliable data aggregation
使用可靠的数据聚合保护无线传感器网络中的隐私
  • DOI:
    10.1145/2034594.2034599
  • 发表时间:
    2011
  • 期刊:
  • 影响因子:
    0
  • 作者:
    F. Rahman;Endadul Hoque;S. Ahamed
  • 通讯作者:
    S. Ahamed
Ensuring specification compliance, robustness, and security of wireless network protocols
  • DOI:
  • 发表时间:
    2015
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Endadul Hoque
  • 通讯作者:
    Endadul Hoque

Endadul Hoque的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Endadul Hoque', 18)}}的其他基金

Collaborative Research: CNS Core: Small: Retrofitting IoT Ecosystems with a Software-defined Overlay to Enforce Safety, Security, and Privacy Policies
合作研究:CNS 核心:小型:使用软件定义的覆盖层改造物联网生态系统,以执行安全、安保和隐私政策
  • 批准号:
    2007512
  • 财政年份:
    2020
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Standard Grant

相似国自然基金

基于Context建模的基因组数据压缩研究
  • 批准号:
    61861045
  • 批准年份:
    2018
  • 资助金额:
    35.0 万元
  • 项目类别:
    地区科学基金项目
Focus+Context支持的群集三维对象变形可视化
  • 批准号:
    41671381
  • 批准年份:
    2016
  • 资助金额:
    65.0 万元
  • 项目类别:
    面上项目
基于Context建模的熵编码及其应用研究
  • 批准号:
    61062005
  • 批准年份:
    2010
  • 资助金额:
    22.0 万元
  • 项目类别:
    地区科学基金项目

相似海外基金

Context-sensitive Interpretation of Ambiguous English Phrases
歧义英语短语的上下文相关解释
  • 批准号:
    574149-2022
  • 财政年份:
    2022
  • 资助金额:
    $ 53.87万
  • 项目类别:
    University Undergraduate Student Research Awards
Searching and Analyzing Big Data: Context-sensitive and Task-aware Approaches
搜索和分析大数据:上下文敏感和任务感知的方法
  • 批准号:
    RGPIN-2020-07157
  • 财政年份:
    2022
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Discovery Grants Program - Individual
Searching and Analyzing Big Data: Context-sensitive and Task-aware Approaches
搜索和分析大数据:上下文敏感和任务感知的方法
  • 批准号:
    RGPIN-2020-07157
  • 财政年份:
    2021
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Discovery Grants Program - Individual
SCC-CIVIC-PG Track A: Co-Creating Context-Sensitive Mobility Strategies for Advancing the Social and Economic Goals of Low-Income Communities
SCC-CIVIC-PG 轨道 A:共同制定情境敏感的出行策略,以推进低收入社区的社会和经济目标
  • 批准号:
    2044995
  • 财政年份:
    2021
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Standard Grant
Searching and Analyzing Big Data: Context-sensitive and Task-aware Approaches
搜索和分析大数据:上下文敏感和任务感知的方法
  • 批准号:
    RGPIN-2020-07157
  • 财政年份:
    2020
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Discovery Grants Program - Individual
Multi-Modal Reinforcement Learning Algorithms for Improving Context-Sensitive Closed-Loop Blood Glucose Control for Type 1 Diabetics
用于改善 1 型糖尿病患者上下文敏感闭环血糖控制的多模态强化学习算法
  • 批准号:
    2452234
  • 财政年份:
    2020
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Studentship
Me, we, and them. A context-sensitive model of social and vicarious consumer animosity
我、我们、还有他们。
  • 批准号:
    411039907
  • 财政年份:
    2019
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Research Grants
Searching and Analyzing Big Data: Context-sensitive and Task-aware Approaches
搜索和分析大数据:上下文敏感和任务感知的方法
  • 批准号:
    RGPIN-2015-03807
  • 财政年份:
    2019
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Discovery Grants Program - Individual
Context- and Community- sensitive transport solutions in Charlotteville Tobago: Impacts on the spatial governance
夏洛特维尔多巴哥的环境和社区敏感型交通解决方案:对空间治理的影响
  • 批准号:
    425915783
  • 财政年份:
    2019
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Research Fellowships
Evaluating gender-sensitive interventions for people who use drugs in the context of British Columbia's opioid overdose crisis
评估在不列颠哥伦比亚省阿片类药物过量危机背景下对吸毒者采取的性别敏感干预措施
  • 批准号:
    396881
  • 财政年份:
    2018
  • 资助金额:
    $ 53.87万
  • 项目类别:
    Fellowship Programs
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了