SHF: Small: Detecting the 1%: Growing the Science of Vulnerability Detection
SHF: Small: Detecting the 1%: Growing the Science of Vulnerability Detection
批准号:
1909516
负责人:
Laurie Williams
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2023-09-30
中文摘要
每天,新闻报道都会披露最新的日益复杂的安全攻击,这些攻击威胁到我们的国家安全、我们的网络基础设施、我们的健康、我们的财务、我们的孩子和民主本身。然而,研究表明,发现的漏洞可能具有非常大的破坏性,但很少见,出现在大约1%-4%的软件文件中。寻找漏洞被描述为“大海捞针”。但是,保护美国人民、美国国土和美国人的生活方式意味着软件组织需要检测漏洞,以便在客户使用产品之前修复这些漏洞,从而使攻击者可以使用这些漏洞。该项目将进行研究,以了解风险最大的漏洞的特征和位置,以便花费特别的努力并开发自动化工具来检测这些漏洞。这项工作将提高软件组织生产安全软件产品的能力,使人们能够依赖计算机系统执行关键功能,并安全地处理、存储和交流敏感信息。该研究项目还涉及对博士生的指导,以及面向本科生和研究生的软件安全教学创新。对要审查和测试的代码做出明智的决定,可以提高团队发现和消除更多漏洞的能力。因此,基于漏洞的检测技术和工具以及有效的漏洞预测可能会更好地为寻求优先处理安全检查和测试工作的安全工程师提供服务。该项目的目标是通过对漏洞特征的实证研究,以及通过开发和评估预测模型,并结合人工智能的最新研究,帮助软件从业者检测可利用的漏洞。该项目将探索漏洞的特征,重点放在构成最高安全风险的漏洞上。有关漏洞基本特征的知识可用于开发以漏洞为重点的工具,以帮助团队有效和高效地检测漏洞。基本的脆弱性特征还可以用来开发新的指标和方法,以建立脆弱性预测模型,并通过人工智能的最新研究得到加强。该项目团队还将提供试验台和测试数据,以帮助其他安全研究人员。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Daily, news reports reveal the latest increasingly sophisticated security attacks that threaten our national security, our cyber infrastructure, our health, our finances, our children, and democracy itself. Yet, studies indicate that discovered vulnerabilities can be very damaging but are rare, appearing in about 1-4% of software files. Finding vulnerabilities has been described as "searching for a needing in a haystack." But, protecting the American people, the American homeland, and the American way of life means that software organizations need to detect vulnerabilities so that they can be fixed before the product is used by customers, which makes the vulnerabilities available to attackers. This project will perform studies to understand the characteristics and location of the most risky vulnerabilities so that special effort can be spent and automated tools can be developed to detect the vulnerabilities. The work will improve the ability of software organizations to produce secure software products so that people can rely upon computer systems to perform critical functions and to process, store, and communicate sensitive information securely. The research project also involves the mentoring of PhD students and innovation in software-security teaching for undergraduate and graduate students.Making informed decisions on what code to review and test can improve a team's ability to find and remove more vulnerabilities. Therefore, security engineers looking to prioritize security inspection and testing efforts may be better served by vulnerability-based detection techniques and tools and effective vulnerability prediction. The goal of this project is to aid software practitioners in detecting exploitable vulnerabilities through empirical study of the characteristics of vulnerabilities and through the development and evaluation of prediction models enhanced with recent research from artificial intelligence. The project will explore characteristics of vulnerabilities with a focus on those that pose the highest security risk. Knowledge about the fundamental characteristics of vulnerabilities can be used in the development of vulnerability-focused tools to aid teams in effectively and efficiently detecting vulnerabilities. The fundamental vulnerability characteristics can also be used to develop novel metrics and methods for building vulnerability prediction models enhanced with recent research from artificial intelligence. The project team will also provide a testbed and test data to help other security researchers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3524842.3528437
发表时间:
2022-03
期刊:
2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR)
影响因子:
--
作者:
[Rui Shu;Tianpei Xia;Laurie A. Williams;T. Menzies]
通讯作者:
Rui Shu;Tianpei Xia;Laurie A. Williams;T. Menzies
DOI:
10.1007/s10664-020-09906-8
发表时间:
2019-11
期刊:
Empirical Software Engineering
影响因子:
4.1
作者:
[Rui Shu;Tianpei Xia;Jianfeng Chen;L. Williams;T. Menzies]
通讯作者:
Rui Shu;Tianpei Xia;Jianfeng Chen;L. Williams;T. Menzies
DOI:
10.1109/tse.2019.2949275
发表时间:
2019
期刊:
IEEE Transactions on Software Engineering
影响因子:
7.4
作者:
[Yu, Zhe, Theisen, Christopher, Williams, Laurie, Menzies, Tim]
通讯作者:
Menzies, Tim
Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard
围绕 OWASP 应用程序安全验证标准构建全面的软件安全课程
DOI:
--
发表时间:
2021
期刊:
Proceedings of the International Conference on Software Engineering
影响因子:
--
作者:
[Elder, Sarah, Zahan, Nusrat, Kozarev, Val, Shu, Rui, Menzies, Tim, Williams, Laurie]
通讯作者:
Williams, Laurie
DOI:
10.1007/s10664-021-10064-8
发表时间:
2020-11
期刊:
Empirical Software Engineering
影响因子:
4.1
作者:
[Rui Shu;Tianpei Xia;L. Williams;T. Menzies]
通讯作者:
Rui Shu;Tianpei Xia;L. Williams;T. Menzies
Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain
-
批准号:2207008
-
项目类别:Continuing Grant
-
资助金额:$634.45万
-
财政年份:2022
-
负责人:Laurie Williams
-
依托单位:
SaTC: CORE: Small: Risk-based Secure Checked-in Credential Reduction for Software Development
-
批准号:2055554
-
项目类别:Standard Grant
-
资助金额:$39.97万
-
财政年份:2021
-
负责人:Laurie Williams
-
依托单位:
Collaborative Research: DarkSide-20k: A Global Program for the Direct Detection of Dark Matter Using Low-Radioactivity Argon
-
批准号:1812480
-
项目类别:Continuing Grant
-
资助金额:$5.0万
-
财政年份:2018
-
负责人:Laurie Williams
-
依托单位:
EAGER: Cognitive modeling of strategies for dealing with errors in mobile touch interfaces
-
批准号:1451172
-
项目类别:Standard Grant
-
资助金额:$28.11万
-
财政年份:2014
-
负责人:Laurie Williams
-
依托单位:
EDU: Motivating and Reaching University Students and Professionals with Software Security Education
-
批准号:1318428
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2013
-
负责人:Laurie Williams
-
依托单位:
Differential Analysis on Changes in Medical Device Software
-
批准号:1160603
-
项目类别:Standard Grant
-
资助金额:$6.0万
-
财政年份:2012
-
负责人:Laurie Williams
-
依托单位:
CT-ER: On the Use of Security Metrics to Identify and Rank the Risk of Vulnerability- and Exploit-Prone Components
-
批准号:0716176
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Laurie Williams
-
依托单位:
Academy for Software Engineering Educators and Trainers
-
批准号:0542681
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2005
-
负责人:Laurie Williams
-
依托单位:
CAREER: Test-Driven Development of Secure and Reliable Software Applications
-
批准号:0346903
-
项目类别:Continuing Grant
-
资助金额:$39.99万
-
财政年份:2004
-
负责人:Laurie Williams
-
依托单位:
ITWF: Collaboration through Agile Software Development Practices: A Means for Improvement in Quality and Retention of IT Workers
-
批准号:0305917
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2003
-
负责人:Laurie Williams
-
依托单位:
Pair-Learning in Undergraduate Computer Science Education
-
批准号:0088178
-
项目类别:Standard Grant
-
资助金额:$22.71万
-
财政年份:2001
-
负责人:Laurie Williams
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: