SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
批准号:
1704253
负责人:
Giovanni Vigna
金额:
$110.16万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-01 至 2023-07-31
中文摘要
传统上,人类分析师在检查软件程序的漏洞时执行核心分析任务,同时使用自动化技术作为辅助。在这种情况下,人类是分析过程的协调者,他们将特定的任务委托给特定的工具(如反汇编程序或符号执行系统),负责组合和合成多个工具的结果。 由于二进制程序的自动化分析已经发展到可以扩展到大量真实世界二进制程序的复杂技术,因此现在建议我们转向一种新的范式,其中自动化工具编排过程,并在适当的时候将任务委托给人类。该研究调查了这种新方法,在这种方法中,当自动化技术无法处理应用程序的语义丰富的特定于应用程序的方面时,会利用人类的行为,这些方面是人类可以毫不费力地执行的任务。总体目标是提高自动化漏洞分析和修补的能力。 该研究将开发一个定义良好的框架,其中子任务建模并以原则性的方式分配给演员。例如,模糊是自动漏洞分析中常用的技术。这种方法需要一组测试用例或种子作为输入,这些测试用例或种子执行目标二进制文件的功能。然后这些种子会发生变异,以探索越来越多的代码库,并增加触发bug的机会。 种子质量,就它们如何很好地执行目标程序而言,对模糊器的有效性具有缩放效应:这些测试用例提供的覆盖范围越大,通过变异它们来探索的代码就越多。不幸的是,创建高质量的测试用例种子是一个复杂的问题,这通常被视为人类提供给系统的输入,因为人类对软件的语义有很好的理解,他们在创建高质量的测试用例方面非常有效。 所提出的框架开始分析,然后生成定义良好的“播种小任务”,以系统的方式整合人类的努力,不需要专家级别的人类分析师。这些简单的任务表示与应用程序的阶段性交互,不熟练的人可以执行(例如,因此,这些任务可以通过各种渠道进行众包(如亚马逊的土耳其机器人),他们的结果自动合并到整个漏洞分析过程中。定义良好的框架支持发现自动化和由具有不同技能水平的人执行的动作的意外组合。通过改善二进制分析技术可以更全面地分析大量的二进制文件。因此,在部署之前可以识别更多的漏洞,从而有助于软件应用程序的整体安全性,包括那些关键基础设施的一部分。
英文摘要
Traditionally, human analysts have carried out the core analysis tasks when checking software programs for vulnerabilities, while using automated techniques as an aid. In this case, the humans are the orchestrators of the analysis process, and they delegate specific tasks to specific tools (such as a disassembler or a symbolic execution system), taking care of combining and composing the results of multiple tools. Because the automated analysis of binary programs has advanced to sophisticated techniques that scale to large sets of real-world binary programs, it is now proposed that we move to a new paradigm in which automated tools orchestrate the process, with tasks being delegated to humans when appropriate. The research investigates this new approach, in which human actions are leveraged when automated techniques are unable to deal with the semantically rich, application-specific aspects of applications, which are tasks that humans can carry out with little effort. The overall goal is to improve the capabilities of automated vulnerability analysis and patching. The research will develop a well-defined framework in which subtasks are modeled and assigned to actors in a principled way. For example, fuzzing is a technique commonly used in automated vulnerability analysis. This approach requires, as input, a set of test cases, or seeds, that exercise the functionality of the target binary. These seeds are then mutated to explore more and more of the code base and increase the chance of triggering bugs. The seed quality, in terms of how well they exercise the target program, has a scaling effect on the effectiveness of a fuzzer: the more coverage these test cases provide, the more code will be explored by mutating them. Unfortunately, the creation of high-quality test case seeds is a complicated problem, and this is generally seen as a human-provided input into a system.Because humans have an excellent understanding of the semantics of software, they are very effective at creating high-quality test cases. The proposed framework starts the analysis and then generates well-defined "seeding tasklet" to integrate human efforts in a systematic way that does not require expert-level human analysts.These simple tasks represent staged interactions with an application that an unskilled human can carry out (e.g., by executing a transaction or filling a form).Therefore, these tasks can be crowdsourced through various channels (such as Amazon's Mechanical Turk), and their results automatically merged into the overall vulnerability analysis process.The reliance on a formal, well-defined framework supports the discovery of unanticipated combinations of automation and actions performed by humans with different skill levels.By improving the state-of-the-art in binary analysis it is possible to analyze a larger number of binaries in a more complete way.As a result, more vulnerabilities are identified before deployment, contributing to the overall security of software applications, including those that are part of the critical infrastructure.
期刊论文(22)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna]
通讯作者:
Kevin Burk;Fabio Pagani;Christopher Krügel;Giovanni Vigna
Sleak: automating address space layout derandomization
Sleak:自动化地址空间布局去随机化
DOI:
10.1145/3359789.3359820
发表时间:
2019
期刊:
Proceedings of the 35th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Hauser, Christophe, Menon, Jayakrishna, Shoshitaishvili, Yan, Wang, Ruoyu, Vigna, Giovanni, Kruegel, Christopher]
通讯作者:
Kruegel, Christopher
DOI:
--
发表时间:
2023
期刊:
影响因子:
--
作者:
[Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna]
通讯作者:
Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna
DOI:
10.1145/3133956.3134105
发表时间:
2017-08
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Yan Shoshitaishvili;Michael Weissbacher;Lukas Dresel;Christopher Salls;Ruoyu Wang;Christopher Krügel;Giovanni Vigna]
通讯作者:
Yan Shoshitaishvili;Michael Weissbacher;Lukas Dresel;Christopher Salls;Ruoyu Wang;Christopher Krügel;Giovanni Vigna
Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates
Cloud Strife:降低域验证证书的安全风险
DOI:
10.14722/ndss.2018.23327
发表时间:
2018
期刊:
Internet Society Symposium on Network and Distributed System Security (NDSS
影响因子:
--
作者:
[Borgolte, Kevin, Fiebig, Tobias, Hao, Shuang, Kruegel, Christopher, Vigna, Giovanni]
通讯作者:
Vigna, Giovanni
共 18 条
AI Institute for Agent-based Cyber Threat Intelligence and Operation
-
批准号:2229876
-
项目类别:Cooperative Agreement
-
资助金额:$1999.42万
-
财政年份:2023
-
负责人:Giovanni Vigna
-
依托单位:
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
-
批准号:1623246
-
项目类别:Standard Grant
-
资助金额:$14.54万
-
财政年份:2016
-
负责人:Giovanni Vigna
-
依托单位:
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
-
批准号:1408632
-
项目类别:Standard Grant
-
资助金额:$106.61万
-
财政年份:2014
-
负责人:Giovanni Vigna
-
依托单位:
Organization of Grand Challenges in Cyber Security
-
批准号:0939188
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2009
-
负责人:Giovanni Vigna
-
依托单位:
SGER: Grand Challenges in Cyber Security
-
批准号:0820907
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2008
-
负责人:Giovanni Vigna
-
依托单位:
CT-ER: A Framework for Live Security Exercises and Challenges
-
批准号:0716753
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Modeling and Analyzing Trust in Service-Oriented Architectures
-
批准号:0716095
-
项目类别:Standard Grant
-
资助金额:$85.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Using Structural and Behavioral Models to Detect Malware
-
批准号:0627783
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2006
-
负责人:Giovanni Vigna
-
依托单位:
CT-ISG: Multi-Model Anomaly Detection for Web-Based Applications
-
批准号:0524853
-
项目类别:Continuing grant
-
资助金额:$45.0万
-
财政年份:2005
-
负责人:Giovanni Vigna
-
依托单位:
CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
-
批准号:0238492
-
项目类别:Continuing grant
-
资助金额:$39.99万
-
财政年份:2003
-
负责人:Giovanni Vigna
-
依托单位:
Collaborative Research: MASSA: Mobile Agent System Security Through Analysis
-
批准号:0209065
-
项目类别:Continuing grant
-
资助金额:$23.01万
-
财政年份:2002
-
负责人:Giovanni Vigna
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: