Build and Watch: Towards Intrusion-Aware Software Systems
Build and Watch: Towards Intrusion-Aware Software Systems
批准号:
RGPIN-2014-04294
负责人:
Zulkernine, Mohammad
金额:
$1.89万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2014
资助国家:
加拿大
项目状态:
已结题
起止时间:
2014-01-01 至 2015-12-31
中文摘要
在软件系统的设计和实现中,安全性是最重要的。然而,在大多数软件开发过程中,安全性问题并没有从软件开发生命周期的开始就得到解决,有时甚至是在软件部署之后才被关注。因此,这些软件系统仍然容易受到各种攻击。软件系统的日益复杂要求软件工程师和安全分析人员更加认真地关注软件系统的安全性。然而,大多数安全软件开发方法的主要关注点并不是在开发阶段集成或监视安全方面。这个研究项目将专注于构建入侵感知软件系统,然后在运行时观察或监控这些系统。本研究计划的最终目标是开发方法,使其能够在现代分布式环境中自动监控入侵,从而生成更安全的软件系统。拟议的计划将通过两种互补的开发和监控方法来实现这一目标:i)基于安全需求规范;ii)基于安全模式的。提出了一种规范方法,可以用来规范系统在正常情况下和受到已知攻击时的操作行为。在运行时将使用相同的规范来识别与规范的偏差。构建入侵场景描述工具,并根据入侵场景自动生成签名。最后,将开发软件监控系统,通过分析与生成的签名相关的系统运行时行为来检测对软件系统的任何入侵。安全模式将用于实现软件设计中的安全需求,这些模式的违反(缺失或存在)将通过使用观察到的运行时信息对模式进行自动分析来检测。由于安全模式是设计的组成部分,并且与安全需求相对应,任何违反这些模式的行为都表明违反了相应的需求。从这个研究项目中得到的方法和工具将在现实世界安全关键应用的案例研究中进行评估。这项研究的结果将在弥合现代、复杂和分布式软件系统的软件工程和安全工程实践之间的差距方面发挥至关重要的作用。软件系统的安全性现在变得更加重要,因为它是云计算和移动等新计算范式和环境安全的基础。该研究项目的一个独特之处在于为五名研究生提供软件工程和安全工程原理的平衡培训设施,为他们构建安全的软件产品做好准备。
英文摘要
Security is of prime importance in the design and implementation of software systems. Nevertheless, in most software development processes, security issues are not addressed from the beginning of a software development life cycle and sometimes even are looked at after the deployment of the software. As a result, these software systems remain vulnerable to various attacks. The growing complexity of software systems requires more serious attention of software engineers and security analysts to monitor software systems for their security. However, the main focus in most secure software development methodologies is not specifically on integrating or monitoring security aspects along the development phases. This research program will focus on building intrusion-aware software systems and then watching or monitoring those at runtime. The ultimate goal of this research program is to develop methodologies allowing the generation of more secure software systems by enabling them to monitor intrusions automatically in the modern distributed environments. The proposed program will be carried out to achieve this goal using two complementary approaches of development and monitoring: i) Security requirements specification-based; ii) Security pattern-based. A specification method will be proposed which can be used to specify operational behavior of the system both under normal condition and when it is under known attacks. The same specification will be utilized at runtime for identifying the deviation from the specification. Tools will be built for intrusion scenario description and automatic signature generation from the scenarios. Finally, software monitoring systems will be developed to detect any intrusions into the software systems by analyzing the run-time behavior of the systems with respect to the generated signatures. Security patterns will be used to realize security requirements in software design and the violation (absence or presence) of these patterns will be detected by automatic analysis of the patterns employing the observed runtime information. As security patterns are the components of design and correspond to security requirements, any violation of these patterns indicates the violation of the corresponding requirements. The methods and tools derived from this research program will be assessed on case studies from real world security-critical applications. The outcomes of this research will play a vital role in bridging the gap between software engineering and security engineering practices for modern, complex, and distributed software systems. Security of software systems is more crucial now as it is the basis for the security of new computing paradigms and environments such as Cloud and mobile. One of the unique aspects of this research program is to provide a balanced training facility for five graduate students in both software engineering and security engineering principles preparing them to build secure software products.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Building and Monitoring Security in Emerging Softwarized Systems
-
批准号:RGPIN-2020-03980
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$4.01万
-
财政年份:2022
-
负责人:Zulkernine, Mohammad
-
依托单位:
Building and Monitoring Security in Emerging Softwarized Systems
-
批准号:RGPIN-2020-03980
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$4.01万
-
财政年份:2021
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Reliability And Security
-
批准号:CRC-2016-00203
-
项目类别:Canada Research Chairs
-
资助金额:$3.64万
-
财政年份:2021
-
负责人:Zulkernine, Mohammad
-
依托单位:
Building and Monitoring Security in Emerging Softwarized Systems
-
批准号:RGPIN-2020-03980
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$4.01万
-
财政年份:2020
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Reliability and Security
-
批准号:CRC-2016-00203
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2020
-
负责人:Zulkernine, Mohammad
-
依托单位:
Secure cloud computing for connected vehicles
-
批准号:506546-2017
-
项目类别:Strategic Projects - Group
-
资助金额:$13.0万
-
财政年份:2019
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Reliability and Security
-
批准号:CRC-2016-00203
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2019
-
负责人:Zulkernine, Mohammad
-
依托单位:
Integrating and Monitoring Security in Software Applications
-
批准号:RGPIN-2019-04651
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.48万
-
财政年份:2019
-
负责人:Zulkernine, Mohammad
-
依托单位:
Secure cloud computing for connected vehicles
-
批准号:506546-2017
-
项目类别:Strategic Projects - Group
-
资助金额:$13.08万
-
财政年份:2018
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Reliability and Security
-
批准号:CRC-2016-00203
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2018
-
负责人:Zulkernine, Mohammad
-
依托单位:
Build and Watch: Towards Intrusion-Aware Software Systems
-
批准号:RGPIN-2014-04294
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2018
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Reliability and Security
-
批准号:CRC-2016-00203
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2017
-
负责人:Zulkernine, Mohammad
-
依托单位:
Secure cloud computing for connected vehicles
-
批准号:506546-2017
-
项目类别:Strategic Projects - Group
-
资助金额:$12.93万
-
财政年份:2017
-
负责人:Zulkernine, Mohammad
-
依托单位:
Build and Watch: Towards Intrusion-Aware Software Systems
-
批准号:RGPIN-2014-04294
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2017
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Dependability
-
批准号:1000226985-2011
-
项目类别:Canada Research Chairs
-
资助金额:$3.64万
-
财政年份:2016
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Reliability and Security
-
批准号:CRC-2016-00203
-
项目类别:Canada Research Chairs
-
资助金额:$3.64万
-
财政年份:2016
-
负责人:Zulkernine, Mohammad
-
依托单位:
Build and Watch: Towards Intrusion-Aware Software Systems
-
批准号:RGPIN-2014-04294
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2016
-
负责人:Zulkernine, Mohammad
-
依托单位:
Build and Watch: Towards Intrusion-Aware Software Systems
-
批准号:RGPIN-2014-04294
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.89万
-
财政年份:2015
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Dependability
-
批准号:1226985-2011
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2015
-
负责人:Zulkernine, Mohammad
-
依托单位:
Software Dependability
-
批准号:1000226985-2011
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2014
-
负责人:Zulkernine, Mohammad
-
依托单位:
海外基金