CAREER: Integrating Trust and Accountability into Compliance Enforcement for a Secure Internet of Things
CAREER: Integrating Trust and Accountability into Compliance Enforcement for a Secure Internet of Things
批准号:
2237012
负责人:
Adwait Nadkarni
金额:
$53.77万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-03-15 至 2028-02-29
中文摘要
监管机构直到最近才开始应对数十亿易受攻击的物联网(IoT)产品的现实,并出台了有针对性的安全和隐私法规。这些政策举措的有用性取决于它们在实践中的执行。此类法规中概述的执行策略类似于用于软件安全遵从性的策略,其中监管机构将执行委托给评估供应商产品的商业许可评估设施(clef)。虽然这种授权有助于将执法范围扩大到数百万种产品,但它是有代价的:受影响的一方,即作为安全合规的主要受益者的监管机构和消费者,在其中发挥的作用有限,从而形成不利于有效执法的激励结构。详细地说,产品供应商没有什么动力去选择一个能彻底评估他们产品的理想CLEF,而不是一个能提供最快认证途径的CLEF。即使供应商真诚地寻找理想的CLEF,除了小册子、有限的演示和CLEF的声誉之外,他们也没有什么手段来衡量CLEF的有效性。此外,clef不是根据其在检测漏洞方面的表现,而是根据程序能力(例如,适当的设施、人员)颁发许可证的。因此,如果将传统模型应用于物联网领域,将会培养出缺乏改进动力的未经验证的clef,以及仅仅将认证视为责任盾牌的供应商。本项目旨在通过为受影响的一方提供实用工具来客观地衡量clef的绩效,并影响安全合规执行中的问责制,从而避免这样的未来。本研究中开发的系统的、数据驱动的评估技术将使监管机构和标准机构能够通过直接评估clef的声称性能来改革合规基础设施,作为许可授予过程或定期审计的一部分。此外,本研究还将通过自我评价帮助clef和供应商提高,帮助供应商寻求有效的clef,帮助clef在绩效的基础上竞争。通过改善物联网的合规执行基础设施,该项目将以安全的物联网产品的形式为消费者带来切实的利益,并有可能增加消费者对物联网技术的信心和采用。该研究将通过体验式学习活动纳入威廉玛丽大学的研究生和本科生安全课程,并传播给决策者和开发人员等关键利益相关者,以及更广泛的研究社区。该项目将突变测试方法与静态和动态分析、机器学习和定性研究协同结合,为经验和系统地评估clef奠定基础,并沿着三个核心研究重点和研究可扩展性的第四个重点。第一个要点通过调查一个关键的潜在问题来检查clef所承担的工作范围是否足够:clef应该寻找什么?为此,本研究在市场规模上获取和分析物联网产品,以便对哪些漏洞与检测相关(即在物联网环境中构成风险)有一个概括的理解,从而形成一个全面的、基于风险的物联网漏洞分类。第二个要点严格评估CLEF从分类法中检测漏洞的重要变体(即突变)的能力。它开发了一个威胁感知突变框架,该框架由一个威胁模型指导,用于封装clef必须考虑的条件的遵从性执行,从而确保对clef进行非任意评估。第三个重点是通过突变驱动的漏洞预测方法重新想象合规执行的安全分析,该方法结合了机器学习和以安全为中心的突变的优势,以实现有效的检测。第四个要点探讨了研究对物联网产品类型、应用领域(如智慧城市)和使用范例的可扩展性。该研究项目利用了来自安全、软件工程和机器学习的良好基础技术,在安全和软件工程的交叉领域做出了新的贡献。最后,将移动物联网应用程序作为目标产品类型的初步关注将推动移动和物联网安全关键交叉点的安全研究。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Regulators have only recently begun to grapple with the reality of billions of vulnerable Internet of Things (IoT) products and have responded with targeted security and privacy regulations. The usefulness of such policy initiatives relies on their enforcement in practice. The enforcement strategy outlined in such regulations is similar to that used for software security compliance, wherein regulators delegate enforcement to Commercially Licensed Evaluation Facilities (CLEFs), which evaluate vendor products. While such delegation is useful in scaling the enforcement to millions of products, it comes at a price: the affected party, i.e., the regulators and consumers who are the primary beneficiaries of security compliance, play a limited role in it, enabling an incentive structure skewed against effective enforcement. To elaborate, product vendors have little incentive to select an ideal CLEF that would thoroughly evaluate their product, instead of one that offers the fastest route to certification. Even if a vendor searched for an ideal CLEF in good faith, they have few means to gauge the CLEF’s effectiveness aside from brochures, limited demonstrations, and the CLEF’s reputation. Moreover, CLEFs are not licensed on the basis of their performance at detecting vulnerabilities, but instead on procedural competence (e.g., adequate facilities, personnel). Hence, traditional model, if applied as is to the IoT sector, would foster unvalidated CLEFs who have little incentive to improve, and vendors who simply view certifications as liability shields. This project seeks to avert such a future by empowering the affected party with practical tools to objectively measure the performance of CLEFs, and influence accountability in security compliance enforcement. The systematic, data-driven, evaluation techniques developed in this research will enable regulators and standards bodies to reform the compliance infrastructure by directly evaluating the claimed performance of CLEFs as a part of the license-granting process or periodic audits. Moreover, this research will also help CLEFs and vendors improve through self-evaluation, help vendors seek effective CLEFs, and help CLEFs compete on the basis of performance. By improving the compliance enforcement infrastructure for IoT, this project will generate tangible benefits for consumers in the form of secure IoT products, and has the potential to increase consumer confidence in and adoption of IoT technology. The research will be incorporated into graduate and undergraduate security classes at William & Mary through experiential learning activities, and disseminated to key stakeholders such as policymakers and developers, as well as the broader research community. This project synergistically blends the approach of mutation testing with static and dynamic analysis, machine learning, and qualitative studies, to lay the foundation for empirically and systematically evaluating CLEFs, along three core research thrusts and a fourth thrust that investigates extensibility. The first thrust examines if the scope of work assumed by CLEFs is sufficient, by investigating a key underlying question: what should CLEFs look for? To this end, the research acquires and analyzes IoT products at market-scale, in order to develop a generalizable understanding of what vulnerabilities are relevant to detect, i.e., pose risk in the IoT context, resulting in a comprehensive, risk-based IoT vulnerability taxonomy. The second thrust rigorously evaluates a CLEF’s ability to detect non-trivial variants of vulnerabilities from the taxonomy, i.e., mutants. It develops a threat-aware mutation framework that generates mutants guided by a threat model for compliance enforcement that encapsulates the conditions CLEFs must account for, thus ensuring a non-arbitrary evaluation of CLEFs. The third thrust re-imagines security analysis for compliance enforcement with the approach of mutation-driven vulnerability prediction, which combines the strengths of machine learning and security-focused mutation for effective detection. The fourth thrust explores the extensibility of the research to IoT product-types, application domains (e.g., smart cities), and usage paradigms. This research project leverages well-founded techniques from security, software engineering, and machine learning to make novel contributions at the intersection of security and software engineering. Finally, the initial focus on mobile-IoT apps as a target product-type will advance security research at the key intersection of mobile and IoT security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CPS: Medium: Enabling Data-Driven Security and Safety Analyses for Cyber-Physical Systems
-
批准号:2132281
-
项目类别:Standard Grant
-
资助金额:$79.98万
-
财政年份:2022
-
负责人:Adwait Nadkarni
-
依托单位:
SaTC: CORE: Small: Enabling Systematic Evaluation of the Soundness of Android Security Analysis Techniques
-
批准号:1815336
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Adwait Nadkarni
-
依托单位:
海外基金