课题基金 / 基金详情

TTP: Securing Python Package Management with The Update Framework (TUF)

TTP: Securing Python Package Management with The Update Framework (TUF)
TTP:使用更新框架 (TUF) 保护 Python 包管理
批准号:
1345049
负责人:
Justin Cappos
金额:
$18.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-08-01 至 2015-07-31

项目摘要

项目成果

Justin Cappos的其他基金

相似基金

相关文献

中文摘要
翻译
大多数软件更新系统的不安全性构成了重大的安全风险。因此,一个具有最少技术知识的攻击者可以对大量计算机造成巨大的破坏。这给全球安全带来了潜在的危机,科学界尤其可能成为受害者。科学界拥有对黑客特别有吸引力的计算资源。科学家们可以使用的高速网络和计算能力将成为发送垃圾邮件的绝佳平台,让大量流量淹没主要网站,使其退出互联网(DDOS),甚至对美国目标发动网络战攻击。TUF(更新框架)是PI在之前的研究中开发的一个工具,用于保护他们新的或现有的软件更新系统。软件更新系统容易受到许多已知攻击的攻击,包括可能导致客户端受到损害或崩溃的攻击。TUF通过提供一个可以添加到软件更新程序中的灵活的安全框架,帮助解决了这个问题。这个项目将把我们的TUF工具转化为安全包管理的实际应用。增加的安全性将对用户完全不可见,除非正在进行攻击,无声地阻止恶意包管理器攻击。TUF为安全密钥撤销、私有安全更新检索和离线/在线混合角色保护提供了独特的功能。这项工作将保护数以百万计的政府系统、军事服务器、科学家和普通互联网用户免受攻击。
英文摘要
The insecurity of most software update systems poses a major security risk. As a result, an attacker with a minimal amount of technical knowledge can cause a huge amount of damage to a huge number of computers. This poses a potential crisis for global security, with the scientific community a particularly likely victim. The scientific community possesses computational resources that are particularly attractive to hackers. The high speed networks and computation available to scientists would make an excellent platform for sending SPAM, flooding major sites with traffic to knock them off the Internet (DDOS), or even launching cyber-warfare attacks against US targets.TUF (The Update Framework) is a tool, developed in prior research by the PI, to secure their new or existing software update systems. Software update systems are vulnerable to many known attacks, including those that can result in clients being compromised or crashed. TUF helps solve this problem by providing a flexible security framework that can be added to software updaters. This project will transition our TUF tool into practical use for secure package management. The added security will be completely invisible to users unless an attack is underway, silently preventing malicious package manager attacks from being effective. TUF provides unique capabilities for secure key revocation, private security update retrieval, and offline/online hybrid role protections. This work will protect millions of government systems, military servers, scientists, and average internet users from attack.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: TTP: Medium: Defending the Supply Chain of Democracy: Towards a Cryptographically Verified and Authenticated Network of Laws
  • 批准号:
    2247829
  • 项目类别:
    Standard Grant
  • 资助金额:
    $68.76万
  • 财政年份:
    2023
  • 负责人:
    Justin Cappos
  • 依托单位:
SaTC: TTP: Medium: Securing Python's Software Supply Chain
  • 批准号:
    2054692
  • 项目类别:
    Standard Grant
  • 资助金额:
    $80.0万
  • 财政年份:
    2021
  • 负责人:
    Justin Cappos
  • 依托单位:
ASPIRE: An SFS Program for Interdisciplinary Research and Education (Renewal)
  • 批准号:
    1922291
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $483.05万
  • 财政年份:
    2019
  • 负责人:
    Justin Cappos
  • 依托单位:
SaTC: TTP: Medium: Collaborative: Securing the Software Supply Chain
  • 批准号:
    1801376
  • 项目类别:
    Standard Grant
  • 资助金额:
    $76.6万
  • 财政年份:
    2018
  • 负责人:
    Justin Cappos
  • 依托单位:
海外基金