课题基金 / 基金详情

Vulnerabilities Analysis

Vulnerabilities Analysis
漏洞分析
批准号:
0311723
负责人:
Matt Bishop
金额:
$24.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-08-01 至 2006-07-31

项目摘要

项目成果

Matt Bishop的其他基金

相似基金

相关文献

中文摘要
翻译
CCR-0311723漏洞分析Matt Bishop该项目将开发和测试现有计算机系统和软件中安全漏洞的新分类方案。当系统满足某些条件时,漏洞就存在了,这些条件决定了漏洞的性质。分类方案将以这些条件为基础。本研究的目标是:(1)确定是否每个漏洞都有一个独特的,最小规模的一组这样的条件;(2)确定是否漏洞共享这些条件;(3)确定是否,对于一个足够大的漏洞集,条件的数量小于漏洞的数量。该方法将检查开放源代码系统和程序中的漏洞,并确定可以利用漏洞的确切条件。随着对利用漏洞所需条件的了解越来越多,这些条件的表达也将越来越精细。这项工作的意义在于,它将导致对系统中为什么会出现漏洞、如何检测漏洞以及如何预防漏洞的更深入的理解。其更广泛的影响是,如果假设是真的,否定系统上的条件可以界定当时未知的漏洞。供应商和安全分析师将能够使用我们将开发的方法来测试系统的漏洞,比目前的命中和失误的方法更容易。最后,这项工作将为开发和教授编写比现在更少漏洞的程序的方法提供更严格的基础。
英文摘要
CCR-0311723Vulnerabilities AnalysisMatt BishopThis project will develop and test a new classification schemefor security vulnerabilities in existing computer systems andsoftware. A vulnerability exists when a system meets certainconditions, the precise conditions dictating the nature of thevulnerability. The classification scheme will be based upon theseconditions. The goal of this research is to: (1) determinewhether every vulnerability has a unique, minimally-sized setof such conditions; (2) determine whether vulnerabilities sharethese conditions; and (3) determine whether, for a large enoughset of vulnerabilities, the number of conditions is less thanthe number of vulnerabilities. The methodology will be toexamine vulnerabilities in open source systems and programs, anddetermine the exact conditions under which a vulnerabilitycan be exploited. The expression of the conditions will be refinediteratively, as more is learned about the conditions needed toexploit vulnerabilities.The significance of this work is that it will lead to a deeperunderstanding of why vulnerabilities occur in systems, how todetect them, and how to prevent them. Its broader impact is that,if the hypotheses are true, negating conditions on a system couldeliminate vulnerabilities not known at the time. Vendors andsecurity analysts would be able to use the approach we will developto test systems for vulnerabilities more readily than the current,hit-and-miss methods. Finally, this work would provide amore rigorous basis for developing and teaching methods ofwriting programs with fewer vulnerabilities than occur now.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: EDU: Building an Electronic Voting Technology Inspired Interactive Teaching and Learning Framework for Cybersecurity Education
  • 批准号:
    2011175
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.0万
  • 财政年份:
    2020
  • 负责人:
    Matt Bishop
  • 依托单位:
SaTc: EDU: Collaborative: An Assessment Driven Approach to Self-Directed Learning in Secure Programming (SecTutor)
  • 批准号:
    1934279
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.1万
  • 财政年份:
    2019
  • 负责人:
    Matt Bishop
  • 依托单位:
CICI: CE: Improving the Security of a Science DMZ
  • 批准号:
    1739025
  • 项目类别:
    Standard Grant
  • 资助金额:
    $73.81万
  • 财政年份:
    2017
  • 负责人:
    Matt Bishop
  • 依托单位:
Travel Support for Participants in the 2016 New Security Paradigms Workshop
  • 批准号:
    1644900
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.0万
  • 财政年份:
    2016
  • 负责人:
    Matt Bishop
  • 依托单位:
国内基金
海外基金
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
Intelligent Patent Analysis for Optimized Technology Stack Selection:Blockchain BusinessRegistry Case Demonstration
  • 批准号:
    --
  • 项目类别:
    外国学者研究基金项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    USHARANI HAREESH GOVINDARA JAN
  • 依托单位:
基于Meta-analysis的新疆棉花灌水增产模型研究
  • 批准号:
    41601604
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    22.0万元
  • 批准年份:
    2016
  • 负责人:
    赵爱琴
  • 依托单位:
大规模微阵列数据组的meta-analysis方法研究
  • 批准号:
    31100958
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2011
  • 负责人:
    赵洪雅
  • 依托单位: