CRII: SaTC: Empirical and Analytical Models for the Deployment of Software Updates in Large Vulnerable Populations
CRII: SaTC: Empirical and Analytical Models for the Deployment of Software Updates in Large Vulnerable Populations
批准号:
1464163
负责人:
Tudor Dumitras
金额:
$17.03万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-05-15 至 2018-04-30
中文摘要
软件漏洞是恶意软件传播的重要载体。负责部署漏洞补丁的软件更新机制正在与寻求利用漏洞的网络攻击者竞争。此外,这些更新机制具有多个潜在冲突的设计目标,因为它们必须在全球数百万台主机上快速部署补丁,不能使用户负担过重,并且必须避免破坏部署环境中的依赖关系。本项目旨在模拟脆弱宿主群体的动态,以评估当前软件更新机制的实际障碍及其安全性和可靠性目标之间的冲突。使用更新部署事件的真实数据集,该研究通过经验研究了脆弱宿主种群的衰减,以确定延迟更新的部署特定因素。在这些见解的基础上,项目开发用于更新部署的参数化分析模型,并使用这些模型在更新软件时量化可靠性和安全性之间的权衡。这些模型为在存在多个设计目标的情况下推理软件更新的属性提供了有原则的方法,并通过探索更大的设计空间来改进软件更新机制。研究人员通过组织数据驱动的安全研讨会、发布带有软件漏洞增强信息的数据集,以及与行业合作伙伴合作,在现实环境中评估所提出的技术,来传播该项目的成果。
英文摘要
Software vulnerabilities are an important vector for malware delivery. The software updating mechanisms, responsible for deploying the vulnerability patches, are in a race with the cyber attackers seeking to exploit the vulnerabilities. Moreover, these updating mechanisms have multiple, potentially conflicting, design goals, as they must quickly deploy patches on millions of hosts worldwide, must not overburden the users, and must avoid breaking dependencies in the deployment environment. This project aims to model the dynamics of vulnerable host populations, in order to assess the practical barriers for current software updating mechanisms and the conflicts among their security and reliability goals. Using real-world data sets of update deployment events, the research studies the decay of vulnerable host populations empirically to identify deployment-specific factors that delay updates. Building on these insights, the project develops parameterized analytical models for update deployment, and uses these models to quantify the trade-offs between reliability and security when updating software. The models provide principled methods for reasoning about the properties of software updates in the presence of multiple design goals and enable improvements in software updating mechanisms by exploring a large design space. The researchers are disseminating the results from this project by organizing workshops on data-driven security, by releasing data sets with augmented information about software vulnerabilities, and by collaborating with industry partners to evaluate the proposed techniques in real-world settings.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
I-Corps: Data-Driven Risk Assessments for Software Vulnerabilities
-
批准号:2244900
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2023
-
负责人:Tudor Dumitras
-
依托单位:
海外基金