EAGER: Effective Detection of Vulnerabilities and Linguistic Stratification in Open Source Software
EAGER: Effective Detection of Vulnerabilities and Linguistic Stratification in Open Source Software
批准号:
1445079
负责人:
Raul Aranovich
金额:
$30.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-10-01 至 2017-09-30
中文摘要
软件漏洞是代码中的弱点,可能被网络罪犯利用来破坏系统。它们通常不会妨碍程序的功能,因此很难检测到。这个项目的重点是开发方法来识别程序中的“弱点”,在这些地方更容易出现漏洞。用于检测弱点的方法是基于检查开源软件(OSS)在线社区中代码开发人员使用的语言模式的新思想。通过结合自然语言处理方法和社会语言学分析,pi研究了程序员在信任和影响力的社会等级中的角色与他或她编写避免漏洞并遵守公共网络安全标准的代码的技能之间的联系。研究结果以一种更快的方式识别漏洞,因此有助于使程序更安全。它还有助于理解代码的自然属性和在线群体中交流的社会动态,为进一步研究软件工程的语言方面奠定基础。
英文摘要
Software vulnerabilities are weaknesses in the code that may be exploited by cybercriminals to harm a system. They often do not hinder a program's functionality, and are thus difficult to detect. This project focuses on developing methods to identify such "weak spots" in a program, where vulnerabilities are more likely to occur. The approach used for detecting weak spots is based on the novel idea of examining linguistic patterns employed by code developers in Open-Source Software (OSS) online communities. Using a combination of natural language processing methods and sociolinguistic analyses, the PIs research the links between a programmer's role within a social hierarchy of trust and influence and his or her skills in producing code that avoids vulnerabilities and adheres to the communal cybersecurity standards. The research results in a faster way to identify vulnerabilities, therefore contributing to make programs safer. It also contributes to understanding of the natural properties of code and the social dynamics of communication in online groups, laying the foundation for further research into linguistic aspects of software engineering.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: SSC: TrOnto - A Community-Based Ontology for a Trustworthy and ResiliCent Scientific Cyberspace
-
批准号:1840191
-
项目类别:Standard Grant
-
资助金额:$64.0万
-
财政年份:2018
-
负责人:Raul Aranovich
-
依托单位:
海外基金