课题基金 / 基金详情

POSE: Phase I: Scoping An Open-Source Ecosystem Around Proactive Software Supply Chain Monitoring

POSE: Phase I: Scoping An Open-Source Ecosystem Around Proactive Software Supply Chain Monitoring
POSE:第一阶段:围绕主动软件供应链监控确定开源生态系统的范围
批准号:
2229703
负责人:
Santiago Torres-Arias
金额:
$30.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
已结题
起止时间:
2022-09-15 至 2024-08-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
该项目由开放源代码生态系统之路(POSE)资助,旨在利用开放源代码开发的力量,为国家和社会重要问题创造新技术解决方案。工业、政府和学术界都依赖于开源软件组件的供应链。最近,黑客们发现,为了攻击他们的目标,他们可以“毒化水流”,从而一次有效地影响所有的软件用户。这类攻击的问题已经造成了站点和整个互联网的中断,估计造成了数十亿美元的损失。从像XCodeGhost这样的大型攻击到Solarwinds,软件供应链攻击的破坏程度、复杂性和频率都呈上升趋势。现有的开源开发方法在实现广泛采用方面面临挑战,主要是由于确保开源供应链的复杂性——一个由具有不同社会技术动机的参与者组成的高度互联的网络。该项目解决了开发和维护社区以提供可用安全性的挑战。该项目的新颖之处在于发现并构建了一个更广泛的解决方案,不仅可以保护云系统,还可以保护人工智能和物联网(IoT)等新兴应用,以及电网等关键任务应用。如果成功,项目的影响将保护数百万软件用户。该项目旨在开发一个可持续增长的开源生态系统,以包括更多的用户,并实现对软件供应链攻击的有意义的保护,尽可能多地防御向量。这个项目分为两个任务。首先,它与新兴应用程序的涉众和最终用户接触。其次,它建立了一个可持续发展计划,以吸引和维持社区的新成员。这个生态系统有潜力改变美国和世界各地的软件的健壮性和安全性。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project is funded by Pathways to Enable Open-Source Ecosystems (POSE) which seeks to harness the power of open-source development for the creation of new technology solutions to problems of national and societal importance. Industry, government, and academia rely on a supply chain of open-source software components. Recently, hackers have identified that, in order to hack their targets, they can "poison the water stream" to effectively affect all consumers of software at once. Problems with these sorts of attacks have caused site- and Internet-wide disruption at an estimated cost of billions of dollars. From major attacks like XCodeGhost to Solarwinds, software supply chain attacks have seen increasing trends in damage, sophistication, and frequency. Existing approaches to open-source development face challenges in achieving widespread adoption, mostly due to the complicated nature of securing the open source supply chain --- a highly interconnected network of actors with different socio-technical motivations. This project tackles the challenge of developing and sustaining a community to provide usable security. The project's novelties are in recognizing and building a broader solution that can secure not only cloud systems, but emerging applications such as as Artificial Intelligence and Internet of Things (IoT) as well as mission critical applications such as the powergrid. If successful, the project's impacts will protect millions of software users.This project aims to develop an open source ecosystem that sustainably grows to include further users and achieves meaningful protection against software supply chain attacks, protecting against as many vectors as possible. This project is divided in two tasks. First, it engages with stakeholders and end-users of emerging applications. Second, it builds a sustainability plan to attract and maintain new members in the community. This ecosystem has the potential to transform the robustness and security of software built in the United States and worldwide.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/icse48619.2023.00206
发表时间: 2023-03
期刊: 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE)
影响因子: --
作者: [Wenxin Jiang;Nicholas Synovic;Matt Hyatt;Taylor R. Schorlemmer;R. Sethi;Yung-Hsiang Lu;G. Thiruvathukal;James C. Davis]
通讯作者: Wenxin Jiang;Nicholas Synovic;Matt Hyatt;Taylor R. Schorlemmer;R. Sethi;Yung-Hsiang Lu;G. Thiruvathukal;James C. Davis
DOI: 10.1145/3560835.3564547
发表时间: 2022-11
期刊: Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses
影响因子: --
作者: [Wenxin Jiang;Nicholas Synovic;R. Sethi;Aryan Indarapu;Matt Hyatt;Taylor R. Schorlemmer;G. Thiruvathukal]
通讯作者: Wenxin Jiang;Nicholas Synovic;R. Sethi;Aryan Indarapu;Matt Hyatt;Taylor R. Schorlemmer;G. Thiruvathukal
Sigstore: Software Signing for Everybody
Sigstore:适合所有人的软件签名
DOI: 10.1145/3548606.3560596
发表时间: 2022
期刊: ACM
影响因子: --
作者: [Newman, Zachary, Meyers, John Speed, Torres-Arias, Santiago]
通讯作者: Torres-Arias, Santiago
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
SoK:通过建立安全设计属性来分析软件供应链安全
DOI: 10.1145/3560835.3564556
发表时间: 2022
期刊: Proceedings of the 1st ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED
影响因子: --
作者: [Okafor, Chinenye, Schorlemmer, Taylor R., Torres-Arias, Santiago, Davis, James C.]
通讯作者: Davis, James C.
共 7 条
    国内基金
    海外基金
    Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark Supercooled Phase Transition
    • 批准号:
      24ZR1429700
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
      YUICHIRO NAKAI
    • 依托单位:
    ATLAS实验探测器Phase 2升级
    • 批准号:
      11961141014
    • 项目类别:
      国际(地区)合作与交流项目
    • 资助金额:
      3350万元
    • 批准年份:
      2019
    • 负责人:
      刘衍文
    • 依托单位:
    地幔含水相Phase E的温度压力稳定区域与晶体结构研究
    • 批准号:
      41802035
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      12.0万元
    • 批准年份:
      2018
    • 负责人:
      张里
    • 依托单位:
    基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究