课题基金 / 基金详情

EAGER: Collaborative: Using Cognitive Techniques To Detect and Prevent Security Flaws

EAGER: Collaborative: Using Cognitive Techniques To Detect and Prevent Security Flaws
EAGER:协作:使用认知技术检测和预防安全缺陷
批准号:
1444827
负责人:
Justin Cappos
金额:
$13.43万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-01-01 至 2017-12-31

项目摘要

项目成果

Justin Cappos的其他基金

相似基金

相关文献

中文摘要
翻译
软件漏洞是一个严重的问题,部分原因是程序员的错误。一个常见的原因是,程序员对代码将执行的操作的理解与代码执行的实际操作之间存在认知差距。这项工作向严格理解人类如何思考代码迈出了第一步,(最终)通过构建更多人类可理解的编程语言和程序来帮助显著减少bug。该项目将执行一项试点研究,以确定如何理解此类安全漏洞,梳理出它们的关键方面,并将这种理解集成到专家辅导系统中,以帮助程序员检测它们。认知科学技术将通过将漏洞分割成其组成部分并评估所产生的错误,来推导出现有安全漏洞中的核心贡献问题。这将创建对安全问题的一般理解,从而使类似源代码的再现和复制变得容易,这是专家辅导工具的理想输入。由此产生的专家辅导工具将用于评估辅导在帮助程序员减少对类似错误的敏感性方面的有效性。
英文摘要
Software vulnerabilities are a substantial problem that exists in part due to programmer errors. A common cause is that programmers have a cognitive gap between their understanding of what actions code will perform and the actual actions the code performs. This work takes a first step toward rigorously understanding how humans think about code to (eventually) help to dramatically reduce bugs by building more human understandable programming languages and programs. This project will perform a pilot study to determine how to understand such security bugs, tease out the key aspects of them, and integrate this understanding into expert tutoring systems to help programmers detect them.Cognitive science techniques will be used to derive the core contributing issues in existing security vulnerabilities by slicing vulnerabilities into their component parts and evaluating the resulting bugs. This will create a generalized understanding of security issues which will enable easy reproduction and replication of similar source code, which is ideal input for an expert tutoring tool. The resulting expert tutoring tool will be used to evaluate the effectiveness of tutoring in helping programmers reduce reduce their susceptibility to similar bugs.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: TTP: Medium: Defending the Supply Chain of Democracy: Towards a Cryptographically Verified and Authenticated Network of Laws
  • 批准号:
    2247829
  • 项目类别:
    Standard Grant
  • 资助金额:
    $68.76万
  • 财政年份:
    2023
  • 负责人:
    Justin Cappos
  • 依托单位:
SaTC: TTP: Medium: Securing Python's Software Supply Chain
  • 批准号:
    2054692
  • 项目类别:
    Standard Grant
  • 资助金额:
    $80.0万
  • 财政年份:
    2021
  • 负责人:
    Justin Cappos
  • 依托单位:
ASPIRE: An SFS Program for Interdisciplinary Research and Education (Renewal)
  • 批准号:
    1922291
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $483.05万
  • 财政年份:
    2019
  • 负责人:
    Justin Cappos
  • 依托单位:
SaTC: TTP: Medium: Collaborative: Securing the Software Supply Chain
  • 批准号:
    1801376
  • 项目类别:
    Standard Grant
  • 资助金额:
    $76.6万
  • 财政年份:
    2018
  • 负责人:
    Justin Cappos
  • 依托单位:
海外基金