CAREER: Reliability and Security of Database and Web Applications
CAREER: Reliability and Security of Database and Web Applications
批准号:
0546844
负责人:
Zhendong Su
金额:
$45.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-02-15 至 2012-01-31
中文摘要
CCF-0546844苏振东加州大学戴维斯分校:数据库和Web应用程序的可靠性和安全性数据库和Web应用程序存在许多严重故障,严重破坏了我国信息系统基础设施的安全性和可靠性。许多这样的错误是由于这些应用程序与外部环境的动态和复杂交互而引入的,例如动态构造查询以访问数据库。因此,自动强制这些交互的正确性很重要,但不存在这样的技术或工具。因此,这些应用程序容易受到严重故障和安全威胁的影响。这个项目提出了一个新颖的、系统的分析框架来解决这个问题。以静态分析和运行时检查为基础,该框架将提供一种严格而全面的方法来验证和实施特定于数据库和Web应用程序的大类高级属性。增加的教育部分包括开发一门跨学科课程,综合数据库、程序设计语言、软件工程和计算机安全的概念,以满足设计强大的数据库密集型应用程序的教育需要。该项目预计将对工业界和学术界产生影响。在该项目中开发的分析工具将在其他机构和行业分发用于教学、研究和实验评估。该项目还将制作公开可用的教学材料,包括网站和课件,帮助人们编写更可靠、更安全的数据库和网络应用程序,并作为开发工具的信息中心,例如该项目的开发工具。
英文摘要
CCF-0546844Zhendong SuUniversity of California -DavisCAREER: Reliability and Security of Database and Web ApplicationsDatabase and web applications contain many critical faults, seriously undermining the security and reliability of our national information system infrastructures. Many such errors are introduced because ofthese applications' dynamic and complex interactions with outside environments such as dynamically constructing queries to access a database. Thus, it is important to automatically enforce the correctness of these interactions, but no such technique or tool exists. Consequently, these applications are susceptible to serious failures and security threats. This project proposes a novel, systematic analysis framework to address this problem. With static analysis and runtime checking as its foundation, this framework willoffer a rigorous and comprehensive approach to validate and enforce large classes of high-level properties specific to database and web applications. The additional educational component includes the development of an interdisciplinary course integrating concepts from databases, programming languages, software engineering, and computer security to address the educational need of engineering robust database-intensive applications. This project is expected to impact both industry and academia. Analysis tools developed in the projectwill be distributed for teaching, research, and experimental evaluation at other institutions and by industry. This project will also produce publicly available instructional materials including web sites and courseware that help people write more reliable and secure database and web applications, and serve as a clearing house for development tools such as the ones from this project.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SHF: Small: Testing and Analysis for Reliable Numerical Software
-
批准号:1618158
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Zhendong Su
-
依托单位:
SHF: Small: Compiler Validation via Equivalence Modulo Inputs
-
批准号:1528133
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2015
-
负责人:Zhendong Su
-
依托单位:
EAGER: Toward Numerically Robust Software
-
批准号:1349528
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2013
-
负责人:Zhendong Su
-
依托单位:
TWC: Small: Collaborative: Similary-Based Program Analyses for Eliminating Vulnerabilities
-
批准号:1319187
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2013
-
负责人:Zhendong Su
-
依托单位:
SHF: Small: Reusing Debugging Knowledge
-
批准号:1117603
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2011
-
负责人:Zhendong Su
-
依托单位:
TC: Small: Runtime and Static Analysis for Web Application Security
-
批准号:0917392
-
项目类别:Standard Grant
-
资助金额:$42.4万
-
财政年份:2009
-
负责人:Zhendong Su
-
依托单位:
Program Analysis for Reliable Numerical Software
-
批准号:0702622
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2007
-
负责人:Zhendong Su
-
依托单位:
Collaborative Research: CT-T: A Vertical Systems Framework for Effective Defense against Memory-Based Attacks
-
批准号:0627749
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2006
-
负责人:Zhendong Su
-
依托单位:
海外基金