Comprehensive Security Assurance Solutions for Software-Dependent Systems
Comprehensive Security Assurance Solutions for Software-Dependent Systems
批准号:
RGPIN-2019-06306
负责人:
Jaskolka, Jason
金额:
$1.68万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2019
资助国家:
加拿大
项目状态:
已结题
起止时间:
2019-01-01 至 2020-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
There is an ever-growing need to assure the security of critical software-dependent systems, and the information that they use, store, and communicate, in the face of cyber-attacks and failures. As systems grow larger and more complex they become more susceptible to a variety of unforeseen security vulnerabilities. Security should therefore be considered at all stages of their development. The current approach of having security “bolted-on” to the systems that we build is not sufficient. Instead, we need to consider the increasingly critical security requirements for these systems and design them with security “baked-in” so that sufficient evidence to support security assurance claims can be generated and reasoned about alongside the system being developed. ******The overall aim of this research program is to establish comprehensive security assurance solutions by enhancing security-by-design approaches for engineering secure software-dependent systems. More specifically, it aims to develop more incremental, modular, and compositional solutions for securing systems from the outset and for generating sufficient evidence of their built-in resilience to a range of cyber-attacks and failures. This requires the integration of formal (mathematically rigorous) methods and security-by-design approaches to provide verifiable evidence to support security assurance claims from early stages of system development. We will achieve this by: (1) Developing formal modeling and analysis frameworks with which we can provide mathematical proofs of assurance of security properties of software-dependent systems at early stages of development; (2) Establishing system-level security evaluation methods and techniques for understanding and mitigating the risks to system assets posed by identified security vulnerabilities; and (3) Advancing techniques to support the management, evaluation, and presentation of sufficient evidence for developing incremental security assurance cases.******Governments, businesses, and users want to be assured that the cyber systems they use offer adequate protections to mitigate the potential risks and associated losses if they experience an attack or failure. The anticipated outcomes will help in establishingat all stages of system developmentsufficient evidence to provide this assurance. This will contribute to alleviating some of the challenges of reasoning about the security of large and complex software-dependent systems and the high-costs associated with security assurance and certification. This research supports Canada's strategic investment to position itself as a global leader in cybersecurity. The obtained results have the potential to impact and influence the development of standards, regulations, and guidelines pertaining to development, evaluation, and certification practices for high-assurance secure software-dependent systems enabling Canadians to have higher confidence in the cyber systems that underpin their daily lives.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Comprehensive Security Assurance Solutions for Software-Dependent Systems
-
批准号:RGPIN-2019-06306
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2022
-
负责人:Jaskolka, Jason
-
依托单位:
Comprehensive Security Assurance Solutions for Software-Dependent Systems
-
批准号:RGPIN-2019-06306
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2021
-
负责人:Jaskolka, Jason
-
依托单位:
Comprehensive Security Assurance Solutions for Software-Dependent Systems
-
批准号:RGPIN-2019-06306
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.68万
-
财政年份:2020
-
负责人:Jaskolka, Jason
-
依托单位:
Comprehensive Security Assurance Solutions for Software-Dependent Systems
-
批准号:DGECR-2019-00176
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2019
-
负责人:Jaskolka, Jason
-
依托单位:
A Mathematical Model for Covert Channels in Closed Systems of Communicating Agents
-
批准号:425996-2012
-
项目类别:Postgraduate Scholarships - Doctoral
-
资助金额:$1.53万
-
财政年份:2013
-
负责人:Jaskolka, Jason
-
依托单位:
A Mathematical Model for Covert Channels in Closed Systems of Communicating Agents
-
批准号:425996-2012
-
项目类别:Postgraduate Scholarships - Doctoral
-
资助金额:$1.53万
-
财政年份:2012
-
负责人:Jaskolka, Jason
-
依托单位:
Detecting security-vulnerable members of a software family through view reconciliation
-
批准号:377385-2009
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Master's
-
资助金额:$1.27万
-
财政年份:2009
-
负责人:Jaskolka, Jason
-
依托单位:
Design and implementation of a tool for the analysis of cryptographic protocols
-
批准号:368557-2008
-
项目类别:University Undergraduate Student Research Awards
-
资助金额:$0.33万
-
财政年份:2008
-
负责人:Jaskolka, Jason
-
依托单位:
海外基金