课题基金 / 基金详情

SaTC: CORE: Small: Defense by Deception of Smartphone Software Applications For Users With Disabilities

SaTC: CORE: Small: Defense by Deception of Smartphone Software Applications For Users With Disabilities
SaTC:核心:小型:针对残障用户的智能手机软件应用程序的欺骗防御
批准号:
2129739
负责人:
Mark Grechanik
金额:
$48.36万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-01-01 至 2024-12-31

项目摘要

项目成果

Mark Grechanik的其他基金

相似基金

相关文献

中文摘要
翻译
基于图形用户界面(GUI)的应用程序(gap)在商业和个人使用中都无处不在,并且部署在各种软件和硬件智能手机平台上。不幸的是,许多使用这种gap的用户都有残疾——仅在美国就有大约5000万,全球超过6亿——这些用户很难在智能手机上使用gap。由于有数百种残疾可能损害人们的视力、运动、记忆、口头交流和听力,残疾用户需要对基于无障碍技术的gap进行专门增强,这些技术从根本上来说是不安全的,从而使残疾用户面临各种网络攻击。这些恶意应用程序可以利用无障碍技术来掠夺残疾用户以获取经济利益,从而在经济上损害用户。尽管有数百种辅助方法,但几乎没有研究可以确保残疾用户使用GAPs,特别是在他们被欺骗在智能手机上安装并允许运行恶意辅助应用程序之后。这个项目通过开发软件来解决这些问题,自动欺骗这些恶意应用程序,使其暴露其意图,从而有效地检测它们,并保护残疾互联网用户。此外,该项目还包括许多活动,以扩大代表性不足的群体对计算机的参与。该项目基于有史以来第一次自动欺骗防御(DbD)方法的新想法,通过结合博弈论,武器化网络钓鱼和现实登录生成,保护目标金融漏洞免受恶意辅助应用程序的攻击,即使在部署了具有完全访问权限的复杂恶意应用程序之后,智能手机也将得到保护。本项目的一个关键部分是重建生成仿冒GAP的gui,其用户界面结构与目标金融GAP非常相似,无法通过算法区分仿冒的gui。有了研究者在这项研究工作中产生的自动化使用欺骗来保护残疾用户的博弈论基础,其他研究人员可以通过建立以自动化方式应用欺骗的统一抽象来更密切地合作,以确保gap。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Graphical User Interface (GUI)-based APplications (GAPs) are ubiquitous, both in business and personal use, and are deployed on diverse software and hardware smartphone platforms. Unfortunately, many users of such GAPs have disabilities - approximately 50 million in the USA alone and over 600 million worldwide - and it is difficult for these users to work with GAPs on their smartphones. Since there are hundreds of types of disabilities that may impair people in vision, movement, memory, oral communication and hearing, users with disabilities need specialized enhancements to GAPs that are based on accessibility technologies, which are fundamentally insecure, thus exposing users with disabilities to a variety of cyber-attacks. These malicious apps can use the accessibility technologies to prey on users with disabilities for financial gain, harming the users financially. Although there are hundreds of assistive approaches, there is almost no research to secure users with disabilities in using GAPs, especially after they are tricked to install and give permissions to run malicious assistive apps on their smartphones. This project addresses these issues by developing software to automatically deceive these malicious applications into revealing their intent, thus effectively detecting them, and protecting Internet users with disabilities. Furthermore, the project includes many activities to broaden the participation of underrepresented groups in computing.This project is based on a novel idea of the first-ever automated Defense by Deception (DbD) approach that protects targeted financial GAPs from malicious assistive apps by using game theory combined with weaponized phishing and realistic login generation, whereby smartphones will be secured even after complex malicious apps are deployed with full accessibility privileges. A key part of this project is to reconstructively generate fake GUIs of the doppelganger GAPs, whose user interface structures closely resemble the target financial GAP, from which the fake GUIs cannot be distinguished algorithmically. With the game-theoretical foundation of automating the use of deception to protect users with disabilities that the investigator produces in this research work, other researchers can collaborate more closely in securing GAPs by building on the proposed unifying abstraction of applying deception in an automated way.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SHF:Small:Proving User Interface Testing Programs Correct
  • 批准号:
    2120142
  • 项目类别:
    Standard Grant
  • 资助金额:
    $47.65万
  • 财政年份:
    2021
  • 负责人:
    Mark Grechanik
  • 依托单位:
SHF: Small:Automatically Synthesizing System and Integration Tests
  • 批准号:
    1908094
  • 项目类别:
    Standard Grant
  • 资助金额:
    $37.89万
  • 财政年份:
    2019
  • 负责人:
    Mark Grechanik
  • 依托单位:
EAGER: Securing Smartphone Applications Against Rapidly Expanding Accessibility-Based Attacks
  • 批准号:
    1650000
  • 项目类别:
    Standard Grant
  • 资助金额:
    $9.71万
  • 财政年份:
    2016
  • 负责人:
    Mark Grechanik
  • 依托单位:
SHF: Small: Automatically Localizing Functional Faults In Deployed Software Applications
  • 批准号:
    1615563
  • 项目类别:
    Standard Grant
  • 资助金额:
    $35.09万
  • 财政年份:
    2016
  • 负责人:
    Mark Grechanik
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: