课题基金 / 基金详情

CAREER: Fuzzing Large Software: Principles, Methods, and Tools

CAREER: Fuzzing Large Software: Principles, Methods, and Tools
职业:模糊大型软件:原理、方法和工具
批准号:
2340198
负责人:
Jun Xu
金额:
$55.55万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-03-01 至 2029-02-28

项目摘要

项目成果

Jun Xu的其他基金

相似基金

相关文献

中文摘要
翻译
今天的软件正在达到前所未有的规模,导致各种各样的大型软件系统,如web浏览器、电子邮件客户端和数据库系统,在社会中占据着中心地位。然而,这种规模的激增带来了无数的漏洞,威胁到每个人的数字安全。统计数据显示,超过一百万行代码的软件平均每1000行有0.66个缺陷,其中36%被归类为漏洞。这个项目通过探索专为发现大型软件中的漏洞而量身定制的安全测试来解决这个关键问题。它专注于扩展模糊测试——一种被软件供应商和开源社区所接受的主要测试策略——以保持大型软件的高有效性和效率。研究成果为大型软件的独特特性给安全测试带来的新挑战提供了科学依据。预期的结果还提高了在日常生活中发挥关键作用的各种大型软件的安全性,例如Chromium, Firefox, Thunderbird, MySQL, LibreOffice, PDFium, TensorFlow和OpenCV。研究成果将导致技术向工业转移。这项研究将通过新课程和犹他州青年教育项目以及CTF竞赛整合到教育和培训中。从技术上讲,该项目引入了三个关键创新,以实现大型软件的可扩展模糊测试。首先,它采用面向对象的分解来处理大型软件的极端复杂性,根据它所操作的数据对象将其分解为自包含的代码单元。这种方法允许测试单个代码单元,克服与模糊整个软件系统相关的挑战,并支持更深的代码覆盖。其次,该项目将以模糊测试为中心的优化集成到编译器和操作系统中,以提高测试速度。这些优化最大限度地减少了与模糊测试无关的操作,并动态地适应了模糊测试的进展,释放了隐藏的速度潜力。第三,该项目开发了基于历史的崩溃分析,通过过滤和分类测试过程中遇到的崩溃,加快了从模糊到修补的周期。利用模糊测试产生的历史数据,这种分析全面地理解和处理崩溃,为解决大型软件系统提供了必要的保真度和效率。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Today's software is reaching unprecedented sizes, resulting in a variety of large software systems, such as web browsers, email clients, and database systems, occupying a central role in society. However, this surge in size brings forth a myriad of vulnerabilities that threaten everyone's digital security. Statistics reveal that software exceeding one million lines of code harbors an average of 0.66 defects per 1,000 lines, with 36% classified as vulnerabilities. This project addresses this critical issue by exploring security testing tailored explicitly for discovering vulnerabilities in large software. It focuses on scaling fuzzing---a predominant testing strategy embraced by software vendors and open-source communities---to maintain high effectiveness and efficiency for large software. The research outcomes advance the scientific study of security testing under new challenges posed by large software's unique properties. The anticipated results also improve the security of various types of large software that play a crucial role in daily lives, such as Chromium, Firefox, Thunderbird, MySQL, LibreOffice, PDFium, TensorFlow, and OpenCV. The outcomes of the research will lead to technology transfer to industry. The research will be integrated into education and training through new curriculum and outreach to Utah's Youth Education program as well as capture the flag (CTF) competitions.Technically, this project introduces three key innovations to enable scalable fuzzing for large software. First, it employs object-oriented decomposition to address the extreme complexity of large software, breaking it down into self-contained code units based on the data objects it manipulates. This approach allows for testing individual code units, overcoming the challenges associated with fuzzing entire software systems and enabling deeper code coverage. Second, the project integrates fuzzing-centric optimizations into compilers and operating systems to enhance testing speed. These optimizations minimize fuzzing-irrelevant operations and dynamically adapt to the progress of fuzzing, unlocking hidden speed potential. Third, the project develops history-informed crash analysis to expedite the fuzzing-to-patching cycle by filtering and triaging crashes encountered during testing. Leveraging historical data produced by fuzzing, this analysis comprehensively understands and processes crashes, offering the fidelity and efficiency necessary for addressing large software systems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Travel: NSF Student Travel Grant for 2023 ACM Conference on Computer and Communications Security (CCS)
  • 批准号:
    2341773
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.5万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure
  • 批准号:
    2319880
  • 项目类别:
    Standard Grant
  • 资助金额:
    $119.81万
  • 财政年份:
    2023
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2213727
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2022
  • 负责人:
    Jun Xu
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2031377
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.6万
  • 财政年份:
    2020
  • 负责人:
    Jun Xu
  • 依托单位:
国内基金
海外基金
面向软件漏洞挖掘的智能化Fuzzing测试方法研究
  • 批准号:
    --
  • 项目类别:
    面上项目
  • 资助金额:
    59万元
  • 批准年份:
    2021
  • 负责人:
    陈锦富
  • 依托单位: