课题基金 / 基金详情

Integrating and Monitoring Security in Software Applications

Integrating and Monitoring Security in Software Applications
集成和监控软件应用程序中的安全性
批准号:
RGPIN-2019-04651
负责人:
Zulkernine, Mohammad
金额:
$2.48万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2019
资助国家:
加拿大
项目状态:
已结题
起止时间:
2019-01-01 至 2020-12-31

项目摘要

项目成果

Zulkernine, Mohammad的其他基金

相似基金

相关文献

中文摘要
翻译
加拿大和世界各地每天都会发生重大的软件安全漏洞。因此,关键是要提高软件安全性,以确保数字环境是有益的,并得到用户的信任。为了及时为云等新兴领域提供软件功能,软件服务提供商通常将功能置于安全需求之上,导致软件存在潜在的安全风险,系统容易受到攻击。软件系统及其不断变化的运行环境的日益复杂要求安全分析师和软件工程师提高监控此类系统的安全性的能力。拟议的研究计划将开发各种自动化技术,通过解决开发生命周期不同阶段的安全问题和随后的运行时监控来开发安全软件。*拟议的研究将开发用于入侵场景描述和从场景自动生成签名的方法和工具。将开发一个监测系统,通过将软件系统的运行时行为与生成的签名进行比较来检测对软件系统的入侵。通常重复出现的安全问题可以使用安全模式来解决。这些模式将用于实现软件设计中的安全需求,并通过模式的自动运行时分析来检测违规。由于安全模式是与安全需求相对应的设计组件,因此对模式的任何违反都将指示对需求的违反。软件即服务(SaaS)越来越多地被用于随时随地访问各种应用程序。鉴于基于云的系统不断受到各种攻击的威胁,安全需求必须与功能需求同等重要,为此,拟议的研究将提供一个新颖的综合平台,允许将安全需求和服务纳入SaaS开发生命周期的每个阶段。我们将调查云的底层运行环境,并在开发和监控阶段建立防御机制,确保云环境及其应用或服务的安全。*该研究计划将对弥合新范式复杂软件和包括云在内的计算环境的软件工程和安全工程实践之间的差距起到至关重要的作用。该计划与加拿大政府对信息安全和安全的优先事项及其保护加拿大人免受网络攻击的承诺一致。该计划的一个独特之处是每年为两名博士和两名硕士学生提供均衡的培训设施,其中将包括开发更安全的软件应用程序的软件工程和安全工程原理。
英文摘要
Major software security breaches occur daily in Canada and around the world. It is thus critical to improve software security to ensure that the digital environment is helpful and trusted by users. To deliver software functionalities in a timely manner for emerging domains such as the cloud, software service providers usually prioritize functionality over security requirements, resulting in software with potential security risks and systems vulnerable to attack. The growing complexity of software systems and their ever-changing runtime environments requires improved capability of security analysts and software engineers to monitor the security of such systems. The proposed research program will develop a variety of automated techniques to develop secure software by addressing security issues in different stages of a development life cycle and subsequent monitoring at runtime.******The proposed research will develop methods and tools for intrusion scenario description and automatic signature generation from the scenarios. A monitoring system will be developed to detect intrusions into software systems by comparing their run-time behavior with the generated signatures. Commonly recurring security problems can be addressed using security patterns. Such patterns will be used to realize security requirements in software design, with violation detected by automatic runtime analysis of the patterns. As security patterns are the design components that correspond to security requirements, any violation of patterns will indicate violation of the requirements. Software-as-a-Service (SaaS) are being used more and more to access various applications anytime anywhere. Given the constant threat of various attacks on cloud-based systems, security requirements must be given the same importance as functionality requirements and to this end, the proposed research will provide a novel comprehensive platform that allows security requirements and services to be incorporated in each stage of the SaaS development lifecycle. We will investigate the underlying operational environments of cloud and build defense mechanisms in the development and monitoring stages for ensuring the security of the cloud environment and its applications or services.******This research program will play a vital role in bridging the gap between software engineering and security engineering practices for complex software of new paradigms and computing environments that include cloud. The program is in alignment with the Government of Canada's priority for information security and safety and its commitment to protect Canadians from cyberattacks. A unique aspect of this program is to provide a balanced training facility for two PhD and two MSc students each year that will include both software engineering and security engineering principles for developing more secure software applications.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Building and Monitoring Security in Emerging Softwarized Systems
  • 批准号:
    RGPIN-2020-03980
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $4.01万
  • 财政年份:
    2022
  • 负责人:
    Zulkernine, Mohammad
  • 依托单位:
Building and Monitoring Security in Emerging Softwarized Systems
  • 批准号:
    RGPIN-2020-03980
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $4.01万
  • 财政年份:
    2021
  • 负责人:
    Zulkernine, Mohammad
  • 依托单位:
Software Reliability And Security
  • 批准号:
    CRC-2016-00203
  • 项目类别:
    Canada Research Chairs
  • 资助金额:
    $3.64万
  • 财政年份:
    2021
  • 负责人:
    Zulkernine, Mohammad
  • 依托单位:
Building and Monitoring Security in Emerging Softwarized Systems
  • 批准号:
    RGPIN-2020-03980
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $4.01万
  • 财政年份:
    2020
  • 负责人:
    Zulkernine, Mohammad
  • 依托单位:
海外基金