CAREER: Context-Sensitive Fuzzing for Networked Systems
CAREER: Context-Sensitive Fuzzing for Networked Systems
批准号:
2339350
负责人:
Endadul Hoque
金额:
$53.87万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-07-01 至 2029-06-30
中文摘要
面向互联网的安全关键型网络协议容易受到远程攻击者的攻击,这些远程攻击者试图破坏整体安全。这些攻击者利用精心编制的输入来利用协议实现中未披露或未打补丁的安全缺陷(Bug)。尽管有常见的错误识别和修补策略,但在协议实现中找出难以捉摸的错误仍然具有挑战性,因为它需要导航严格的输入验证来发现隐藏在代码深处的错误。FUZZING得到了美国国家标准与技术研究所(NIST)的认可,它通过将异常输入传递给程序来发现漏洞,从而实现安全测试的自动化。虽然Fuzing已经有效地发现了许多真实系统中的错误,但它仍然很难生成语义上正确的输入,这对于超出初始输入验证的测试是必不可少的。该项目通过开发一种创新的自动化解决方案来有效地增强协议实现的测试,从而弥合了传统模糊的这一差距。该项目的核心目标是开发一种自动化的、上下文敏感的模糊方法,有效地发现安全关键协议实现中的错误。该项目通过三个相辅相成的研究项目的活动实现其目标。第一个推力是设计一种特定于领域的语言来编码输入的上下文敏感的层次结构,并开发算法来高效地生成语义正确的输入。第二个推力设计了几种突变技术,这些技术对于模糊化至关重要,将保持输入的上下文敏感性。第三个推力开发了一种机制来忠实地维护有状态协议的内部状态,以便每个模糊输入都可以在协议的合适状态下进行测试。该项目具有显著增强协议实现的健壮性的潜力,从而造福社会。该项目的教育部分包括组织捕获旗帜(CTF)比赛,改进网络安全课程,以及举办K-12讲习班以提高网络安全意识。来自历史边缘社区的本科生和研究生将被招募,以增加他们在研究和教育活动中的参与。这一奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Internet-facing security-critical network protocols are susceptible to exploitation by remote adversaries seeking to compromise overall security. These adversaries employ crafted inputs to exploit undisclosed or unpatched security flaws (bugs) in protocol implementations. Despite the common strategy of bug identification and patching, unearthing elusive bugs in protocol implementations remains challenging as it requires navigating stringent input validation to discover bugs that lurk deep in the code. Fuzzing, endorsed by the National Institute of Standards and Technology (NIST), automates security testing by passing abnormal inputs to programs in order to discover bugs. While fuzzing has effectively uncovered bugs in many real-world systems, it still struggles to generate semantically correct inputs essential for testing beyond initial input validation. This project bridges this gap in traditional fuzzing by developing an innovative automated solution that effectively enhances the testing of protocol implementations. The core objective of this project is to develop an automated, context-sensitive fuzzing approach that effectively uncovers bugs in security-critical protocol implementations. This project realizes its objective through activities across three complementary research thrusts. The first thrust designs a domain specific language to encode context-sensitive hierarchical structures of inputs and develops algorithms to efficiently generate semantically correct inputs. The second thrust devises several mutation techniques, essential for fuzzing, that will maintain the context-sensitivity of the input. The third thrust develops mechanisms to faithfully maintain the internal state of a stateful protocol so that each fuzz input can be tested in a suitable state of the protocol.This project has the potential to significantly enhance the robustness of protocol implementations, benefiting society. This project's education component includes organizing capture-the-flag (CTF) competitions, improving cybersecurity courses, and conducting K-12 workshops to raise cybersecurity awareness. Undergraduate and graduate students from historically marginalized communities will be recruited to increase their participation in research and educational activities.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CNS Core: Small: Retrofitting IoT Ecosystems with a Software-defined Overlay to Enforce Safety, Security, and Privacy Policies
-
批准号:2007512
-
项目类别:Standard Grant
-
资助金额:$25.01万
-
财政年份:2020
-
负责人:Endadul Hoque
-
依托单位:
国内基金
海外基金
基于Context建模的基因组数据压缩研究
-
批准号:61861045
-
项目类别:地区科学基金项目
-
资助金额:35.0万元
-
批准年份:2018
-
负责人:陈建华
-
依托单位:
Focus+Context支持的群集三维对象变形可视化
-
批准号:41671381
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2016
-
负责人:应申
-
依托单位:
基于Context建模的熵编码及其应用研究
-
批准号:61062005
-
项目类别:地区科学基金项目
-
资助金额:22.0万元
-
批准年份:2010
-
负责人:陈建华
-
依托单位: