Supporting software security by measuring, coordinating, and enforcing software trustworthiness
通过测量、协调和加强软件可信度来支持软件安全
基本信息
- 批准号:402445-2011
- 负责人:
- 金额:$ 2.48万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2015
- 资助国家:加拿大
- 起止时间:2015-01-01 至 2016-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The public often has little guidance when selecting security software to defend their computers. What makes this problem so difficult is the lack of information on what specific parts of a computer system (and its software) various anti-virus, anti-spyware, and firewall software actually monitor and defend. Information security experts typically recommend multiple layers of defense (i.e., "defense-in-depth"), but there is little concrete evidence for judging what software to pick or determining the makeup of those layers.
The key scientific issue here focuses on how to compose trust -- the notion that software will behave as expected -- in these systems. This work thus seeks to measure the composition of existing software protection mechanisms for how much of a computer they "cover." This work also proposes models for how to design security software to cooperate (rather than compete) because their competition typically results in unstable or crashing computers due to conflicting modifications. Pasting two or more security mechanisms together in the name of "defense-in-depth" and having them interact in unanticipated, counterproductive, or ultimately insecure ways does not seem very desirable.
Although this research examines fundamentally hard scientific problems like how to compose trust relationships in software, the work in this proposal will have a very practical outcome: enabling end-users and organizations to more clearly understand what their chosen collection of protection mechanisms provides.
公众在选择安全软件来保护他们的计算机时往往没有什么指导。 使这个问题如此困难的是缺乏关于计算机系统(及其软件)的哪些特定部分的信息,各种反病毒,反间谍软件和防火墙软件实际上监视和防御。 信息安全专家通常建议多层防御(即,“纵深防御”),但几乎没有具体的证据来判断选择什么软件或确定这些层的组成。
这里的关键科学问题集中在如何在这些系统中构建信任--软件将按预期运行的概念。因此,这项工作旨在衡量现有的软件保护机制的组成,以确定它们“覆盖”计算机的多少。“这项工作还提出了如何设计安全软件进行合作(而不是竞争)的模型,因为它们的竞争通常会导致由于相互冲突的修改而导致计算机不稳定或崩溃。 以“深度防御”的名义将两个或多个安全机制粘贴在一起,并让它们以不可预见的、适得其反的或最终不安全的方式进行交互,这似乎不是很理想。
虽然这项研究从根本上探讨了如何在软件中构建信任关系等困难的科学问题,但这项提案中的工作将产生非常实际的结果:使最终用户和组织能够更清楚地了解他们选择的保护机制集合提供了什么。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Locasto, Michael其他文献
Locasto, Michael的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Locasto, Michael', 18)}}的其他基金
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
通过测量、协调和加强软件可信度来支持软件安全
- 批准号:
402445-2011 - 财政年份:2014
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
通过测量、协调和加强软件可信度来支持软件安全
- 批准号:
402445-2011 - 财政年份:2013
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
通过测量、协调和加强软件可信度来支持软件安全
- 批准号:
402445-2011 - 财政年份:2012
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
Supporting software security by measuring, coordinating, and enforcing software trustworthiness
通过测量、协调和加强软件可信度来支持软件安全
- 批准号:
402445-2011 - 财政年份:2011
- 资助金额:
$ 2.48万 - 项目类别:
Discovery Grants Program - Individual
相似国自然基金
低辐射空间环境下商用多核处理器层次化软件容错技术研究
- 批准号:90818016
- 批准年份:2008
- 资助金额:50.0 万元
- 项目类别:重大研究计划
相似海外基金
TELEMETRY - Trustworthy mEthodologies, open knowLedgE & autoMated tools for sEcurity Testing of IoT software, haRdware & ecosYstems
遥测 - 值得信赖的方法,开放的知识
- 批准号:
10087006 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
EU-Funded
TRUSTED: SecuriTy SummaRies for SecUre SofTwarE Development
值得信赖:安全软件开发的安全摘要
- 批准号:
EP/X03688X/1 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
Research Grant
CAREER: Enabling Robust and Adaptive Architectures through a Decoupled Security-Centric Hardware/Software Stack
职业:通过解耦的以安全为中心的硬件/软件堆栈实现鲁棒性和自适应架构
- 批准号:
2238548 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
Continuing Grant
Elements: An Infrastructure for Software Quality and Security Issues Detection and Correction
要素:软件质量和安全问题检测和纠正的基础设施
- 批准号:
2416756 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
Standard Grant
Brain Digital Slide Archive: An Open Source Platform for data sharing and analysis of digital neuropathology
Brain Digital Slide Archive:数字神经病理学数据共享和分析的开源平台
- 批准号:
10735564 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
Implementation of an impact assessment tool to optimize responsible stewardship of genomic data in the cloud
实施影响评估工具以优化云中基因组数据的负责任管理
- 批准号:
10721762 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
A Multi-Modal Wearable Sensor for Early Detection of Cognitive Decline and Remote Monitoring of Cognitive-Motor Decline Over Time
一种多模态可穿戴传感器,用于早期检测认知衰退并远程监控认知运动随时间的衰退
- 批准号:
10765991 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别:
Administrative Core: An Integrated Multi PI And Multi Site Management Plan For Enhanced Echinobase
管理核心:增强型 Echinobase 的集成多 PI 和多站点管理计划
- 批准号:
10715579 - 财政年份:2023
- 资助金额:
$ 2.48万 - 项目类别: