课题基金 / 基金详情

Supporting software security by measuring, coordinating, and enforcing software trustworthiness

Supporting software security by measuring, coordinating, and enforcing software trustworthiness
通过测量、协调和加强软件可信度来支持软件安全
批准号:
402445-2011
负责人:
Locasto, Michael
金额:
$2.48万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31

项目摘要

项目成果

Locasto, Michael的其他基金

相似基金

相关文献

中文摘要
翻译
公众在选择安全软件来保护他们的计算机时,往往几乎没有什么指导。这个问题之所以如此困难,是因为缺乏关于计算机系统(及其软件)的哪些特定部分(各种防病毒、反间谍软件和防火墙软件)实际监控和防御的信息。信息安全专家通常建议多层防御(即“深度防御”),但几乎没有具体证据来判断应该选择哪个软件或确定这些层的组成。 这里的关键科学问题集中在如何在这些系统中构建信任--软件将按预期运行的概念。因此,这项工作试图衡量现有软件保护机制的组成,以确定它们“覆盖”了多少计算机。这项工作还提出了如何设计安全软件以合作(而不是竞争)的模型,因为它们的竞争通常会导致计算机不稳定或由于冲突的修改而崩溃。以“深度防御”的名义将两个或多个安全机制粘贴在一起,并让它们以意想不到的、适得其反的或最终不安全的方式交互,似乎不是很可取的。 尽管这项研究从根本上考察了棘手的科学问题,如如何在软件中建立信任关系,但该提案中的工作将产生非常实际的结果:使最终用户和组织能够更清楚地了解他们选择的保护机制集合提供了什么。
英文摘要
The public often has little guidance when selecting security software to defend their computers. What makes this problem so difficult is the lack of information on what specific parts of a computer system (and its software) various anti-virus, anti-spyware, and firewall software actually monitor and defend. Information security experts typically recommend multiple layers of defense (i.e., "defense-in-depth"), but there is little concrete evidence for judging what software to pick or determining the makeup of those layers. The key scientific issue here focuses on how to compose trust -- the notion that software will behave as expected -- in these systems. This work thus seeks to measure the composition of existing software protection mechanisms for how much of a computer they "cover." This work also proposes models for how to design security software to cooperate (rather than compete) because their competition typically results in unstable or crashing computers due to conflicting modifications. Pasting two or more security mechanisms together in the name of "defense-in-depth" and having them interact in unanticipated, counterproductive, or ultimately insecure ways does not seem very desirable. Although this research examines fundamentally hard scientific problems like how to compose trust relationships in software, the work in this proposal will have a very practical outcome: enabling end-users and organizations to more clearly understand what their chosen collection of protection mechanisms provides.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
  • 批准号:
    402445-2011
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.48万
  • 财政年份:
    2014
  • 负责人:
    Locasto, Michael
  • 依托单位:
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
  • 批准号:
    402445-2011
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.48万
  • 财政年份:
    2013
  • 负责人:
    Locasto, Michael
  • 依托单位:
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
  • 批准号:
    402445-2011
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.48万
  • 财政年份:
    2012
  • 负责人:
    Locasto, Michael
  • 依托单位:
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
  • 批准号:
    402445-2011
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.48万
  • 财政年份:
    2011
  • 负责人:
    Locasto, Michael
  • 依托单位:
国内基金
海外基金
低辐射空间环境下商用多核处理器层次化软件容错技术研究
  • 批准号:
    90818016
  • 项目类别:
    重大研究计划
  • 资助金额:
    50.0万元
  • 批准年份:
    2008
  • 负责人:
    傅忠传
  • 依托单位: