课题基金 / 基金详情

CAREER: Black-Box Learning of Web Application Authorization Policies

CAREER: Black-Box Learning of Web Application Authorization Policies
职业:Web 应用程序授权策略的黑盒学习
批准号:
2047623
负责人:
Amirreza Masoumzadeh
金额:
$57.47万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-10-01 至 2026-09-30

项目摘要

项目成果

Amirreza Masoumzadeh的其他基金

相似基金

相关文献

中文摘要
翻译
Web应用程序已成为访问服务和功能的事实上的方式。确保Web应用程序的不同用户只被允许访问他们应该访问的内容,即实现正确的授权,这一点至关重要。但是,不幸的是,访问控制和授权中断一直被列为最大的Web应用漏洞之一。事实上,由于代码复杂性和快速开发等挑战,许多Web应用程序无法提供其强制授权策略的准确规范。无论是最终用户,还是应用程序的开发人员,都无法对此环境中的数据保护进行推理。为了解决这一问题,本研究项目设计了一个新的框架,用于从Web应用程序中学习细粒度的授权策略,而不依赖于访问其源代码或了解其他内部复杂性。该项目开发了一个综合研究和教育计划,以培训安全/隐私、机器学习和网络技术交叉领域的下一代网络安全工作人员。由于基于网络的系统在我们的社会中普遍存在,所开发的框架和相关解决方案将大大有助于系统安全和用户隐私。此外,由于其黑盒设计,开发的技术将是调查应用程序采用者(例如,部署外包应用程序的公司)和第三方(例如,调查隐私法和期望遵守情况的安全/隐私研究人员和监管机构)在其开发环境之外的应用程序数据授权做法的关键资产。该项目吸引了不同的学生群体,特别是来自代表不足的群体的学生参与安全和隐私研究,并通过外展活动让广大社区接触到安全和隐私主题。该研究项目开发了一种自动学习Web应用程序授权策略的新范例,显著改善了确保Web应用程序的安全和隐私。这项研究的一个关键特征是将Web应用程序视为黑匣子,即通过与常规最终用户进行交互和观察来学习授权。黑盒方法允许抽象出Web应用程序的内部复杂性,转而专注于重要的事情:了解在用户访问应用程序数据时对其实施了哪些策略。研究分三个阶段进行。首先,设计了一个理论策略学习框架,用于有效地探测应用程序作为黑盒的授权空间,并构造其策略的形式化规范。其次,将开发一种方法和相关技术,用于从黑盒Web应用程序中学习数据对象、关系和操作的表示,以便实现理论框架在Web领域的实际部署。第三,该项目将开发分析和集成学习到的授权策略的技术,以提高Web应用程序的安全性和隐私。通过为研究人员、开发人员和分析人员提供一种自动学习授权策略规范的方法,此范例将对网络安全/隐私研究和实践产生革命性影响。除了使他们能够了解Web应用程序的授权行为外,它还将重振依赖于具体策略规范的正式策略测试和验证技术的研究。此外,通用框架将适用于网络应用程序以外的其他领域,如移动应用程序生态系统。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Web applications have become the de facto way to access services and functionalities. It is vital to ensure that different users of web applications are only allowed to access what they are supposed to, i.e., implementing correct authorization. But, unfortunately, broken access control and authorization has been constantly ranked as one of the top web application vulnerabilities. In fact, many web applications cannot provide an accurate specification of their enforced authorization policies due to challenges such as code complexity and fast-paced development. Neither end users nor even developers of the applications could reason about data protection in this environment. To address this problem, this research project devises a novel framework for learning fine-grained authorization policies from web applications without relying on access to their source codes or understanding other internal complexities. The project develops an integrated research and education program to train the next generation of cybersecurity workforce at the intersection of security/privacy, machine learning, and web technologies. Since web-based systems are pervasive in our society, the developed framework and associated solutions will significantly contribute to system safety and user privacy. Furthermore, due to their black-box design, the developed techniques will be critical assets to investigate data authorization practices of applications outside their development environments by application adopters (e.g., companies deploying outsourced applications) and third parties acting in the interest of end users (e.g., security/privacy researchers and regulators investigating compliance with privacy laws and expectations). The project engages a diverse body of students especially from underrepresented groups in security and privacy research and exposes the broad community to security and privacy topics through outreach activities.This research project develops a novel paradigm for automated learning of web application authorization policies that significantly improves ensuring the security and privacy of web applications. A key characteristic of this research is to treat web applications as black boxes, i.e., learning authorizations by interacting with and observing them as would regular end users. The black-box approach allows abstracting away internal complexities of web applications and focusing instead on what matters: learning what policies are enforced on users as they access application data. The research is carried out in three thrusts. First, a theoretical policy learning framework will be devised for efficiently probing the authorization space of applications as black boxes and constructing formal specifications of their policies. Second, a methodology and associated techniques for learning representation of data objects, relationships, and operations from black-box web applications will be developed in order to realize practical deployment of the theoretical framework in the web domain. Third, the project will develop techniques for analysis and integration of the learned authorization policies to improve the security and privacy of web applications. This paradigm will be transformative for web security/privacy research and practice by providing researchers, developers, and analysts an automated approach to learn the specifications of authorization policies. In addition to enabling them to understand the authorization behavior of web applications, it will revitalize research in formal policy testing and verification techniques that rely on concrete policy specifications. Furthermore, the general framework will be applicable beyond web applications to other domains such as mobile app ecosystems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
Towards Automated Learning of Access Control Policies Enforced by Web Applications
实现 Web 应用程序执行的访问控制策略的自动学习
DOI: 10.1145/3589608.3594743
发表时间: 2023
期刊: Proceedings of the 28th ACM Symposium on Access Control Models and Technologies
影响因子: --
作者: [Iyer, Padmavathi, Masoumzadeh, Amir]
通讯作者: Masoumzadeh, Amir
Effective Evaluation of Relationship-Based Access Control Policy Mining
基于关系的访问控制策略挖掘的有效评估
DOI: 10.1145/3532105.3535022
发表时间: 2022
期刊: Proceedings of the 27th ACM Symposium on Access Control Models and Technologies
影响因子: --
作者: [Iyer, Padmavathi, Masoumzadeh, Amirreza]
通讯作者: Masoumzadeh, Amirreza
DOI: 10.1145/3517121
发表时间: 2022-08-01
期刊: ACM TRANSACTIONS ON PRIVACY AND SECURITY
影响因子: 2.3
作者: [Iyer,Padmavathi, Masoumzadeh,Amirreza]
通讯作者: Masoumzadeh,Amirreza
Travel: NSF Student Travel Grant for 5th IEEE International Conference on Trust, Privacy, and Security in Intelligent Systems and Applications (IEEE TPS 2023)
  • 批准号:
    2333916
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2023
  • 负责人:
    Amirreza Masoumzadeh
  • 依托单位:
NSF Student Travel Grant for 2019 IEEE International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (IEEE TPS)
  • 批准号:
    2002916
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2019
  • 负责人:
    Amirreza Masoumzadeh
  • 依托单位:
国内基金
海外基金
空间分数阶 Black-Scholes 方程的波动率反演 问题
  • 批准号:
    Q24A010012
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    蒋晓颖
  • 依托单位:
Black-Scholes期权定价模型的时间自适应算法与分析
  • 批准号:
    12271142
  • 项目类别:
    面上项目
  • 资助金额:
    45万元
  • 批准年份:
    2022
  • 负责人:
    任金城
  • 依托单位:
Shining light on the black hole mass distribution
  • 批准号:
    12073029
  • 项目类别:
    面上项目
  • 资助金额:
    61.0万元
  • 批准年份:
    2020
  • 负责人:
    Roberto Soria
  • 依托单位:
新老岛弧斑岩铜(金)矿中间岩浆房过程对比研究:以菲律宾 Black Mountain和我国多宝山为例