Collaborative Research: SaTC: CORE: Medium: Securing Continuous Integration Workflows
Collaborative Research: SaTC: CORE: Medium: Securing Continuous Integration Workflows
批准号:
2247687
负责人:
Nikos Vasilakis
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-07-01 至 2027-06-30
中文摘要
持续集成(CI)已经成为现代软件开发周期的关键。开发人员设计CI脚本(通常称为工作流或管道)来自动化大多数软件维护任务,例如测试和部署。开发人员经常错误配置工作流,导致严重的安全问题,这可能会导致供应链攻击的破坏性影响。CI平台和支持的特性的极端多样性进一步加剧了这个问题,并使跨不同CI平台统一指定和验证安全属性变得具有挑战性。该项目通过定义工作流所需的安全属性和开发与平台无关的技术来验证和执行安全属性,从而解决了这个问题。此外,这项研究将支持跨学科发展的博士和本科生,研究生水平的课程,以及工作流安全分析的游戏化培训环境。该项目定义了CI工作流所需的安全属性,并开发了验证和指定这些属性的方法。这需要能够以与平台无关的方式工作的技术来处理CI平台的多样性。该项目通过设计工作流中间表示(WIR)和工作流规范语言(WSL)来间接处理这些问题。WIR和WSL分别支持与平台无关的工作流安全属性验证和规范。安全属性的验证将通过工作流分析框架(Workflow Analysis Framework, WAF)执行,该框架支持静态和动态分析,传递在与平台无关的WIR中编码的工作流。WSL是一种特定于领域的语言,它允许开发人员以与平台无关的方式指定工作流及其安全属性。设计一个有效的WSL需要理解开发人员在工程工作流中的观点和挑战,并指定安全属性。在此背景下,本项目进行了必要的开发人员研究,以获得对上述方面的见解。该项目还开发了一个双向编译基础设施,用于将工作流从WSL转换为特定于平台的版本,从而实现与现有平台的兼容性。此外,该项目还旨在创建、收集和编目跨不同平台的代表性工作流的大型语料库。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Continuous Integration (CI) has become essential to the modern software development cycle. Developers engineer CI scripts, commonly called workflows or pipelines, to automate most software maintenance tasks, such as testing and deployment. Developers frequently misconfigure workflows resulting in severe security issues, which can have devastating effects resulting in supply-chain attacks. The extreme diversity of CI platforms and the supported features further exacerbate the problem and make it challenging to specify and verify security properties across different CI platforms uniformly. This project addresses the problem by defining the desired security properties of a workflow and developing platform-independent techniques to verify and enforce the security properties. Furthermore, this research will support the cross-disciplinary development of a diverse cohort of Ph.D. and undergraduate students, graduate-level courses, and a gamified training environment for workflow security analysis.This project defines the required security properties of CI workflows and develops methods to verify and specify these properties. This requires techniques that can work in a platform-independent manner to handle the diversity of CI platforms. The project handles this through indirection by designing Workflow Intermediate Representation (WIR) and Workflow Specification Language (WSL). WIR and WSL enable platform-agnostic verification and specification of workflow security properties, respectively. The verification of security properties will be performed through Workflow Analysis Framework (WAF) that supports both static and dynamic analysis passes over workflows encoded in a platform-agnostic WIR. WSL, a domain-specific language, allows developers to specify workflows and their security properties in a platform-independent manner. Designing an effective WSL requires understanding developers' perspectives and challenges in engineering workflows and specifying security properties. In this context, this project performs necessary developer studies to gain insights about the above aspects. The project also develops a bidirectional compilation infrastructure for translating workflows from WSL to platform-specific versions, enabling compatibility with existing platforms. Furthermore, the project also aims to create, collect, and catalog a large corpus of representative workflows across different platforms.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CSR: Core: Medium: Scaling Unix/Linux Shell Programs
-
批准号:2312346
-
项目类别:Continuing Grant
-
资助金额:$59.96万
-
财政年份:2023
-
负责人:Nikos Vasilakis
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: