课题基金 / 基金详情

CAREER: A Framework for Preventing Web-based Attacks

CAREER: A Framework for Preventing Web-based Attacks
职业:防止基于 Web 的攻击的框架
批准号:
0845894
负责人:
Venkat Venkatakrishnan
金额:
$40.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2014-08-31

项目摘要

项目成果

Venkat Venkatakrishnan的其他基金

相似基金

相关文献

中文摘要
翻译
该奖项是根据2009年《美国复苏和再投资法案》(公法111-5)资助的。万维网是一项关键的基础设施,通过促进信息交换、商业和教育为我们的社会服务。随着它的不断发展,针对无辜网络用户的基于网络的数据标签的数量也在不断增加。此类攻击的例子包括跨站点脚本、SQL注入和跨站点请求伪造。最近通过这些恶性攻击对终端用户和在线企业的攻击造成了广泛的破坏。因此,防御这些攻击对互联网经济和整个社会都是非常重要的关注。该项目制定了一个全面的计划来保护Web应用程序免受这些攻击。该项目的技术贡献在于开发了诱导Web应用程序的预期行为并通过强制实施这些预期行为来防止攻击的技术。我们构建了一个框架,其中使用模型来表示Web应用程序的意图,然后执行这些模型以确保强大的攻击防御。该框架使用了基于静态和动态分析、符号求值、运行时检查和隔离执行的新技术作为基础。该项目还开发了使Web应用程序和浏览器能够协作的技术,以防止攻击,并对Web内容施加细粒度的限制。该项目中开发的工具将对保护易受这些攻击的遗留Web应用程序产生立竿见影的效果。该职业研究项目通过在本科生和研究生计算机安全课堂中整合网络安全主题,与教育工作密切相关。最后,与芝加哥市中心的一所小学合作也是该项目教育使命的一部分。
英文摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).The World Wide Web is a critical infrastructure that serves our societyby facilitating information exchange, business andeducation. As it continues to evolve, the number of web-basedattacks that target innocent web users keeps increasing. Examples of such attacks include Cross-site Scripting, SQL Injectionand Cross-site Request Forgery. Recent attacks on end-users andonline enterprises through these virulent attacks have resulted inwidespread damage. Defending these attacks is therefore of very important concern to Internet economy and to society-at-large. This project develops a comprehensive plan for defending web applications from these attacks. The technical contributions of this project are in the development of thetechnologies that elicit the intended behavior of a web applicationand prevent attacks by enforcing these intended behaviors. We builda framework in which the intentions of a web application are represented using models, which are then enforced to ensure robust prevention of attacks. This framework uses novel techniques based on static and dynamicanalysis, symbolic evaluation, runtime checking and isolated execution as foundations. This project also developstechniques that enable a web application and a browser tocollaborate in order to prevent attacks, and apply fine-grainedrestrictions on Web content. The tools being developed in this project will have immediate impact on defending legacy web applications that are vulnerable to these attacks. The CAREER research project is closely tied with educationalefforts by integrating topics on web security in the undergraduate and graduate computer security classrooms. Finally, a collaborative effort with a Chicago inner-city elementary school is also part of this project's educational mission.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Collaborative: RADAR: Real-time Advanced Detection and Attack Reconstruction
  • 批准号:
    1918542
  • 项目类别:
    Standard Grant
  • 资助金额:
    $61.2万
  • 财政年份:
    2019
  • 负责人:
    Venkat Venkatakrishnan
  • 依托单位:
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
  • 批准号:
    1514472
  • 项目类别:
    Standard Grant
  • 资助金额:
    $55.0万
  • 财政年份:
    2015
  • 负责人:
    Venkat Venkatakrishnan
  • 依托单位:
I-Corps: Automated Web Application Analysis
  • 批准号:
    1248717
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2012
  • 负责人:
    Venkat Venkatakrishnan
  • 依托单位:
SFS Scholarships in Cybersecurity and Information Assurance
  • 批准号:
    1241685
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $150.53万
  • 财政年份:
    2012
  • 负责人:
    Venkat Venkatakrishnan
  • 依托单位:
海外基金