课题基金 / 基金详情

CAREER: At-scale Analysis of Issues in Cyber-Security and Software Engineering

CAREER: At-scale Analysis of Issues in Cyber-Security and Software Engineering
职业:网络安全和软件工程问题的大规模分析
批准号:
1552836
负责人:
Christopher White
金额:
$48.72万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-05-15 至 2022-04-30

项目摘要

项目成果

Christopher White的其他基金

相似基金

相关文献

中文摘要
翻译
网络安全中最重大的挑战之一是,人类参与软件工程,在实现规范时不可避免地会犯安全错误,导致软件漏洞。消除这些错误的一个挑战是相对缺乏关于什么是安全编码实践的经验证据(例如,安全默认值、验证客户端数据等),威胁建模和教育解决方案可以有效减少软件工程师产生的应用程序级漏洞的数量。本研究的目的是进行实验,分析编程作业提交到大规模开放式在线课程(MOOC)之前和之后的安全编码和威胁建模技术被教导,以经验性地衡量其对安全漏洞的分配实施率的影响。这项研究的一个关键组成部分将是使用MOOC分配规范和可能受到常见网络安全漏洞影响的变体,例如Web应用程序的输入验证或移动的平台上的权限升级问题。由于这些关键的安全实施问题将提前知道,MOOC作业将允许自动评估每个作业实施如何成功地管理这些安全问题。本研究调查的关键问题包括分析不同的安全编码和威胁建模技术对软件中漏洞产生的影响,这些技术需要在什么抽象级别上进行教学才能有效,威胁建模与自动化漏洞评估工作的相对投资回报,以及使开发人员意识到安全问题与需要主动应用安全编码和威胁建模技术的相对有效性。这项研究的广泛影响是巨大的。很少有经验数据可供组织使用,以正确评估已开发的安全编码和威胁建模技术。通过创建大量严格的证据来说明不同技术的有效性(或可能无效),该研究将允许组织评估其投资回报并改进这些技术在软件工程过程中的使用。
英文摘要
One of the most significant challenges in cybersecurity is that humans are involved in software engineering and inevitably make security mistakes in their implementation of specifications, leading to software vulnerabilities. A challenge to eliminating these mistakes is the relative lack of empirical evidence regarding what secure coding practices (e.g., secure defaults, validating client data, etc.), threat modeling, and educational solutions are effective in reducing the number of application-level vulnerabilities that software engineers produce. This research aims to perform experiments analyzing programming assignment submissions to Massively Open Online Courses (MOOCs) before and after secure coding and threat modeling techniques are taught to empirically measure their impact on the rate of security vulnerabilities in assignment implementations. A key component of this research will be the use of MOOC assignment specifications and variations that have the potential to be affected by common cybersecurity vulnerabilities, such as problems with input validation to web applications or privilege escalation on mobile platforms. Because these critical security implementation issues will be known ahead of time, the MOOC assignments will allow automated assessment of how successfully each assignment implementation manages these security issues.Key questions investigated by this research include analyzing the impact of varying secure coding and threat modeling techniques on vulnerability production in software, what level of abstraction these techniques need to be taught at to be effective, the relative return on investment of threat modeling vs. automated vulnerability assessment effort, and the comparative effectiveness of making developers aware of security issues versus requiring active application of secure coding and threat modeling techniques. The broader impact of this research is substantial. Very little empirical data is available for organizations to use to properly value the secure coding and threat modeling techniques that have been developed. By creating a large body of rigorous evidence to illustrate how effective (or possibly not effective) different techniques are, the research will allow organizations to evaluate their return on investment and improve the use of these techniques in the software engineering process.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Strathclyde Discipline Hopping for Discovery Science 2022-23
  • 批准号:
    NE/X017206/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $12.85万
  • 财政年份:
    2022
  • 负责人:
    Christopher White
  • 依托单位:
EMERGE: Multi-hazards and emergent risks in Northern Europe's remote and vulnerable regions
  • 批准号:
    NE/W003775/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $7.05万
  • 财政年份:
    2021
  • 负责人:
    Christopher White
  • 依托单位:
CPS: TTP Option: Medium: Collaborative Research: Cyber-Physical System Integrity and Security with Impedance Signatures
  • 批准号:
    1931931
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $48.72万
  • 财政年份:
    2019
  • 负责人:
    Christopher White
  • 依托单位:
I-Corps Teams: Leaf Global Fintech: Virtual Banking Beyond Borders
  • 批准号:
    1906995
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2018
  • 负责人:
    Christopher White
  • 依托单位:
国内基金
海外基金
基于热量传递的传统固态发酵过程缩小(Scale-down)机理及调控
  • 批准号:
    22108101
  • 项目类别:
    青年科学基金项目(C类)
  • 资助金额:
    30.0万元
  • 批准年份:
    2021
  • 负责人:
    靳光远
  • 依托单位:
基于Multi-Scale模型的轴流血泵瞬变流及空化机理研究
  • 批准号:
    31600794
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    22.0万元
  • 批准年份:
    2016
  • 负责人:
    荆腾
  • 依托单位:
基于异构医学影像数据的深度挖掘技术及中枢神经系统重大疾病的精准预测
  • 批准号:
    61672236
  • 项目类别:
    面上项目
  • 资助金额:
    64.0万元
  • 批准年份:
    2016
  • 负责人:
    王骏
  • 依托单位:
城镇居民亚健康状态的评价方法学及健康管理模式研究
  • 批准号:
    81172775
  • 项目类别:
    面上项目
  • 资助金额:
    14.0万元
  • 批准年份:
    2011
  • 负责人:
    许军
  • 依托单位: