Automated Security Testing of an Electronic Asset Transfer Platform

电子资产转移平台的自动化安全测试

基本信息

  • 批准号:
    516011-2017
  • 负责人:
  • 金额:
    $ 1.82万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Engage Grants Program
  • 财政年份:
    2017
  • 资助国家:
    加拿大
  • 起止时间:
    2017-01-01 至 2018-12-31
  • 项目状态:
    已结题

项目摘要

Ensuring that software is bug-free is a significant technical challenge, recognized as such in both industry and academic research. Exacerbating this challenge is the very real possibility that malicious parties can tease out and trigger bugs for personal and institutional gain. The technology of the company-partner for this proposal, nanopay, relates to the transfer of assets, for example, money. Their technology is a particularly attractive target for such malicious exploitation. Like most enterprises, nanopay invests considerably in technology and processes to ensure software quality. Of importance in this context is automation --- integration of automated testing in the process of developing and delivering software and related services. Existing solutions are severely lacking in this regard when it comes to security properties. In particular, as nanopay's solution is for asset-transfer, security in their context includes properties for that domain, for example, questions such as: `Can a malicious user acquire an asset, yet not have paid for it?,' and, `Can a malicious merchant somehow cheat a user out of payments, yet not deliver corresponding goods and services?' While there is broad research in frameworks for articulating security properties, and reasoning about them, automation of the nature we discuss above remains a long-term goal in research. There is no existing technology, of which were are aware, that nanopay can leverage in the near-term. The proposed work will train Highly Qualified Personnel (HQP) and be of short- and long-term value to industry in Ontario, Canada.
确保软件没有bug是一个重大的技术挑战,在工业和学术研究中都是如此。加剧这一挑战的是,恶意方有真实的可能为了个人和机构的利益而梳理和触发漏洞。该公司合作伙伴的技术,纳米支付,涉及资产的转移,例如,钱。他们的技术是这种恶意利用的特别有吸引力的目标。像大多数企业一样,Nanopay在技术和流程上投入了大量资金,以确保软件质量。在这种情况下,重要的是自动化--在开发和交付软件及相关服务的过程中集成自动化测试。在安全属性方面,现有解决方案严重缺乏这方面的解决方案。特别是,由于nanopay的解决方案是针对资产转移的,因此其上下文中的安全性包括该域的属性,例如,诸如“恶意用户是否可以获得资产,但尚未支付?”“以及”恶意商家是否可以以某种方式欺骗用户付款,但不提供相应的商品和服务?“虽然在阐明安全属性的框架方面有广泛的研究,并对它们进行推理,但我们上面讨论的自动化仍然是研究的长期目标。我们知道,目前还没有任何现有的技术可以让纳米支付在短期内发挥作用。拟议的工作将培训高素质的人员(HQP),并在加拿大安大略的行业具有短期和长期的价值。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Tripunitara, Mahesh其他文献

Tripunitara, Mahesh的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Tripunitara, Mahesh', 18)}}的其他基金

Trust, in an Internet of Things
物联网中的信任
  • 批准号:
    RGPIN-2019-05634
  • 财政年份:
    2022
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Trust, in an Internet of Things
物联网中的信任
  • 批准号:
    RGPIN-2019-05634
  • 财政年份:
    2021
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Software Dependability for 5G Systems
5G 系统的软件可靠性
  • 批准号:
    532264-2018
  • 财政年份:
    2021
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Collaborative Research and Development Grants
Software Dependability for 5G Systems
5G 系统的软件可靠性
  • 批准号:
    532264-2018
  • 财政年份:
    2020
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Collaborative Research and Development Grants
Trust, in an Internet of Things
物联网中的信任
  • 批准号:
    RGPIN-2019-05634
  • 财政年份:
    2020
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Software Dependability for 5G Systems
5G 系统的软件可靠性
  • 批准号:
    532264-2018
  • 财政年份:
    2019
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Collaborative Research and Development Grants
Trust, in an Internet of Things
物联网中的信任
  • 批准号:
    RGPIN-2019-05634
  • 财政年份:
    2019
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Strengthening the Foundations of Access Control
加强访问控制的基础
  • 批准号:
    RGPIN-2014-06716
  • 财政年份:
    2018
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual
Software Dependability for 5G Systems**********
5G 系统的软件可靠性************
  • 批准号:
    532264-2018
  • 财政年份:
    2018
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Collaborative Research and Development Grants
Strengthening the Foundations of Access Control
加强访问控制的基础
  • 批准号:
    RGPIN-2014-06716
  • 财政年份:
    2017
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Grants Program - Individual

相似海外基金

TELEMETRY - Trustworthy mEthodologies, open knowLedgE & autoMated tools for sEcurity Testing of IoT software, haRdware & ecosYstems
遥测 - 值得信赖的方法,开放的知识
  • 批准号:
    10087006
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
    EU-Funded
Effective integration of human and automated analyses for security testing
安全测试中人工分析和自动分析的有效集成
  • 批准号:
    DE230100473
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Discovery Early Career Researcher Award
An innovative platform to reduce the risk of cyber attacks on smart contracts for all blockchains by minimising human effort and improving the efficacy of security testing.
一个创新平台,通过最大限度地减少人力并提高安全测试的效率,降低所有区块链智能合约遭受网络攻击的风险。
  • 批准号:
    10047308
  • 财政年份:
    2023
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Collaborative R&D
CAREER: Systematic Approach for Extensively (SAfEly) Testing and Verifying the Security of Connected and Autonomous Vehicle
职业:广泛(安全)测试和验证联网自动驾驶汽车安全性的系统方法
  • 批准号:
    2241718
  • 财政年份:
    2022
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Continuing Grant
FAUST: fault and security testing for vehicle systems
FAUST:车辆系统的故障和安全测试
  • 批准号:
    565305-2021
  • 财政年份:
    2022
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Alliance Grants
CAREER: Systematic Approach for Extensively (SAfEly) Testing and Verifying the Security of Connected and Autonomous Vehicle
职业:广泛(安全)测试和验证联网自动驾驶汽车安全性的系统方法
  • 批准号:
    2144801
  • 财政年份:
    2022
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Continuing Grant
Investigation and Development of a Cyber Security Sandbox for IIoT Information Technology and Operational Technology Threat Vector Testing and Mitigation
用于 IIoT 信息技术和运营技术威胁向量测试和缓解的网络安全沙箱的调查和开发
  • 批准号:
    561351-2020
  • 财政年份:
    2021
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Applied Research and Development Grants - Level 1
FAUST: fault and security testing for vehicle systems
FAUST:车辆系统的故障和安全测试
  • 批准号:
    565305-2021
  • 财政年份:
    2021
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Alliance Grants
Linguistic Security Testing
语言安全测试
  • 批准号:
    563357-2021
  • 财政年份:
    2021
  • 资助金额:
    $ 1.82万
  • 项目类别:
    University Undergraduate Student Research Awards
Development of rapid testing technology to increase food security
开发快速检测技术以提高食品安全
  • 批准号:
    77477
  • 财政年份:
    2020
  • 资助金额:
    $ 1.82万
  • 项目类别:
    Collaborative R&D
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了