Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
批准号:
RGPIN-2017-05700
负责人:
Merlo, Ettore
金额:
$1.46万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2019
资助国家:
加拿大
项目状态:
已结题
起止时间:
2019-01-01 至 2020-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The proposed research aims at improving the quality and the security integrity of software, while reducing its development cost in the perspective of application security.******Today's large deployment of Web and mobile applications, cloud services, and cyber-physical systems demand frequent and short release cycles or continuous releases. This puts even more stress and time constraints on quality assurance in general and on application security.******I propose to design, implement, and evaluate automated and scalable methods for the early fault localization and automated repair of security inconsistencies and vulnerabilties in access controls in software applications.******I propose to localize faulty security code by investigating counter-examples from violated policies in security models and to synthesize human-usable explanations.******In this proposal, I want to address and investigate the automated repair of detected security inconsistencies by reasoning on the localized faults that correspond to executions that violate some role-privilege policies.******For example, missing checks could be repaired by automatically inserting proper authorization checks to restore the desired security reachability and accesses to security sensitive resources.******Two problems appear when path based security repair is sought:***(a) selection of code fragments implementing appropriate security checks to be inserted, deleted, or modified to repair the detected inconsistencies.***(b) where to insert the checks along the possibly many paths that violate the security reachability constraints.******In this proposal, I want to address first the problem of automated security repairs and second the problem of optimal placement of required new security checks.******I want to determine the categories of security problems that can be automatically repaired, thus relieving the developers from this burden.***I want to investigate their significance in large industrial or open source systems.******When automation cannot be completely achieved for some inconsistency category, I want to investigate an interactive and recommendation-based strategy to support the developers during their manual repair of inconsistencies by supplying explanations and suggestions.******The proposed research on automated repairs will prevent detected and repaired inconsistencies from being released. Software systems will be more secure and less vulnerable to attacks. The overall process from detection to repaired release will be shorter. Therefore, the window of opportunity for attacks will be dramatically reduced.******Results from this research will be methods and tools available to researchers for automatically analyzing and repairing large applications in the perspective of security. Findings about the effectiveness of automated detection and repair of inconsistencies in large and popular open source applications will also be produced.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
-
批准号:RGPIN-2017-05700
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2021
-
负责人:Merlo, Ettore
-
依托单位:
Automated AI-supported methane plume detection from satellite and aircraft images
-
批准号:568677-2021
-
项目类别:Alliance Grants
-
资助金额:$7.04万
-
财政年份:2021
-
负责人:Merlo, Ettore
-
依托单位:
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
-
批准号:RGPIN-2017-05700
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2020
-
负责人:Merlo, Ettore
-
依托单位:
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
-
批准号:RGPIN-2017-05700
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2018
-
负责人:Merlo, Ettore
-
依托单位:
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
-
批准号:RGPIN-2017-05700
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.46万
-
财政年份:2017
-
负责人:Merlo, Ettore
-
依托单位:
Analysis, testing and evolution of security vulnerabilities in web applications
-
批准号:165343-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2014
-
负责人:Merlo, Ettore
-
依托单位:
Analysis, testing and evolution of security vulnerabilities in web applications
-
批准号:165343-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2013
-
负责人:Merlo, Ettore
-
依托单位:
Analysis, testing and evolution of security vulnerabilities in web applications
-
批准号:165343-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2012
-
负责人:Merlo, Ettore
-
依托单位:
Analysis, testing and evolution of security vulnerabilities in web applications
-
批准号:165343-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2011
-
负责人:Merlo, Ettore
-
依托单位:
Model-driven engineering support for certified avionics software development
-
批准号:386870-2009
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$4.88万
-
财政年份:2010
-
负责人:Merlo, Ettore
-
依托单位:
Analysis, testing and evolution of security vulnerabilities in web applications
-
批准号:165343-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2010
-
负责人:Merlo, Ettore
-
依托单位:
Evolution and risk analysis of large software systems
-
批准号:165343-2003
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2009
-
负责人:Merlo, Ettore
-
依托单位:
Evolution and risk analysis of large software systems
-
批准号:165343-2003
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2008
-
负责人:Merlo, Ettore
-
依托单位:
Evolution and risk analysis of large software systems
-
批准号:165343-2003
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2006
-
负责人:Merlo, Ettore
-
依托单位:
Evolution and risk analysis of large software systems
-
批准号:165343-2003
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2005
-
负责人:Merlo, Ettore
-
依托单位:
Evolution and risk analysis of large software systems
-
批准号:165343-2003
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2004
-
负责人:Merlo, Ettore
-
依托单位:
Evolution and risk analysis of large software systems
-
批准号:165343-2003
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2003
-
负责人:Merlo, Ettore
-
依托单位:
Definition and investigation of unconstrained def-use analysis for structural software testinU
-
批准号:165343-1999
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.84万
-
财政年份:2002
-
负责人:Merlo, Ettore
-
依托单位:
CSER: Software quality evaluation (Phase2)
-
批准号:227075-1999
-
项目类别:Cooperative Activities
-
资助金额:$0.27万
-
财政年份:2001
-
负责人:Merlo, Ettore
-
依托单位:
Definition and investigation of unconstrained def-use analysis for structural software testinU
-
批准号:165343-1999
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.84万
-
财政年份:2001
-
负责人:Merlo, Ettore
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Graphon mean field games with partial observation and application to failure detection in distributed systems
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:MATHIEULOUROCHLAURIERE
-
依托单位:
基于深穿透拉曼光谱的安全光照剂量的深层病灶无创检测与深度预测
-
批准号:82372016
-
项目类别:面上项目
-
资助金额:48.00万元
-
批准年份:2023
-
负责人:林俐
-
依托单位:
膀胱癌高表达基因UPK3A的筛选、鉴定和相关研究
-
批准号:81101922
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2011
-
负责人:来永庆
-
依托单位:
图像分类方法研究及其在色情监测中的应用
-
批准号:61172103
-
项目类别:面上项目
-
资助金额:62.0万元
-
批准年份:2011
-
负责人:王春恒
-
依托单位:
基于隐半马尔科夫模型的无线传感器网络入侵检测系统研究
-
批准号:61101083
-
项目类别:青年科学基金项目
-
资助金额:25.0万元
-
批准年份:2011
-
负责人:史景伦
-
依托单位:
基于指令层次的网页木马渗透攻击机理分析与检测方法研究
-
批准号:61003217
-
项目类别:青年科学基金项目
-
资助金额:18.0万元
-
批准年份:2010
-
负责人:诸葛建伟
-
依托单位:
超高速正则表达式匹配技术研究
-
批准号:61073184
-
项目类别:面上项目
-
资助金额:12.0万元
-
批准年份:2010
-
负责人:董群峰
-
依托单位:
低辐射空间环境下商用多核处理器层次化软件容错技术研究
-
批准号:90818016
-
项目类别:重大研究计划
-
资助金额:50.0万元
-
批准年份:2008
-
负责人:傅忠传
-
依托单位:
制冷系统故障诊断关键问题的定量研究
-
批准号:50876059
-
项目类别:面上项目
-
资助金额:30.0万元
-
批准年份:2008
-
负责人:谷波
-
依托单位: