课题基金 / 基金详情

Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis

Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
使用程序分析自动检测、解释和修复 Web 应用程序访问控制中的安全不一致
批准号:
RGPIN-2017-05700
负责人:
Merlo, Ettore
金额:
$1.46万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2020
资助国家:
加拿大
项目状态:
已结题
起止时间:
2020-01-01 至 2021-12-31

项目摘要

项目成果

Merlo, Ettore的其他基金

相似基金

相关文献

中文摘要
翻译
本研究旨在从应用安全的角度提高软件的质量和安全完整性,同时降低软件的开发成本。 如今,Web和移动应用程序、云服务和网络物理系统的大规模部署需要频繁且短的发布周期或连续发布。这给总体质量保证和应用程序安全带来了更大的压力和时间限制。 我建议设计、实现和评估自动化和可伸缩的方法,以便对软件应用程序访问控制中的安全不一致和漏洞进行早期故障定位和自动修复。 我建议通过调查安全模型中违反策略的反例来定位有缺陷的安全代码,并综合人类可用的解释。 在本提案中,我希望通过对与违反某些角色特权策略的执行相对应的本地化错误进行推理,来解决和研究检测到的安全不一致的自动修复。 例如,可以通过自动插入适当的授权检查来修复丢失的检查,以恢复所需的安全可达性和对安全敏感资源的访问。 在寻求基于路径的安全修复时会出现两个问题: (A)选择实施适当安全检查的代码片段以插入、删除或修改以修复检测到的不一致。 (B)沿着可能违反安全可达性约束的许多路径插入检查的位置。 在这项提议中,我想首先解决自动安全维修的问题,其次是所需新安全检查的最佳位置问题。 我想确定哪些类别的安全问题可以自动修复,从而减轻开发人员的这一负担。 我想调查它们在大型工业或开放源码系统中的意义。 当某些不一致类别不能完全实现自动化时,我想研究一种交互式和基于推荐的策略,通过提供解释和建议来支持开发人员手动修复不一致。 拟议的关于自动修复的研究将防止发现和修复的不一致被公布。软件系统将更加安全,更不容易受到攻击。从检测到修复释放的整个过程将会更短。因此,袭击的机会窗口将大大减少。 这项研究的结果将为研究人员从安全角度自动分析和修复大型应用程序提供方法和工具。还将提出关于自动检测和修复大型和流行的开放源码应用程序中不一致的有效性的结论。
英文摘要
The proposed research aims at improving the quality and the security integrity of software, while reducing its development cost in the perspective of application security. Today's large deployment of Web and mobile applications, cloud services, and cyber-physical systems demand frequent and short release cycles or continuous releases. This puts even more stress and time constraints on quality assurance in general and on application security. I propose to design, implement, and evaluate automated and scalable methods for the early fault localization and automated repair of security inconsistencies and vulnerabilties in access controls in software applications. I propose to localize faulty security code by investigating counter-examples from violated policies in security models and to synthesize human-usable explanations. In this proposal, I want to address and investigate the automated repair of detected security inconsistencies by reasoning on the localized faults that correspond to executions that violate some role-privilege policies. For example, missing checks could be repaired by automatically inserting proper authorization checks to restore the desired security reachability and accesses to security sensitive resources. Two problems appear when path based security repair is sought: (a) selection of code fragments implementing appropriate security checks to be inserted, deleted, or modified to repair the detected inconsistencies. (b) where to insert the checks along the possibly many paths that violate the security reachability constraints. In this proposal, I want to address first the problem of automated security repairs and second the problem of optimal placement of required new security checks. I want to determine the categories of security problems that can be automatically repaired, thus relieving the developers from this burden. I want to investigate their significance in large industrial or open source systems. When automation cannot be completely achieved for some inconsistency category, I want to investigate an interactive and recommendation-based strategy to support the developers during their manual repair of inconsistencies by supplying explanations and suggestions. The proposed research on automated repairs will prevent detected and repaired inconsistencies from being released. Software systems will be more secure and less vulnerable to attacks. The overall process from detection to repaired release will be shorter. Therefore, the window of opportunity for attacks will be dramatically reduced. Results from this research will be methods and tools available to researchers for automatically analyzing and repairing large applications in the perspective of security. Findings about the effectiveness of automated detection and repair of inconsistencies in large and popular open source applications will also be produced.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
  • 批准号:
    RGPIN-2017-05700
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.46万
  • 财政年份:
    2021
  • 负责人:
    Merlo, Ettore
  • 依托单位:
Automated AI-supported methane plume detection from satellite and aircraft images
  • 批准号:
    568677-2021
  • 项目类别:
    Alliance Grants
  • 资助金额:
    $7.04万
  • 财政年份:
    2021
  • 负责人:
    Merlo, Ettore
  • 依托单位:
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
  • 批准号:
    RGPIN-2017-05700
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.46万
  • 财政年份:
    2019
  • 负责人:
    Merlo, Ettore
  • 依托单位:
Automated detection, explanation, and remediation of security inconsistencies in Web application access controls using program analysis
  • 批准号:
    RGPIN-2017-05700
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.46万
  • 财政年份:
    2018
  • 负责人:
    Merlo, Ettore
  • 依托单位:
国内基金
海外基金
Graphon mean field games with partial observation and application to failure detection in distributed systems
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    MATHIEULOUROCHLAURIERE
  • 依托单位:
基于深穿透拉曼光谱的安全光照剂量的深层病灶无创检测与深度预测
  • 批准号:
    82372016
  • 项目类别:
    面上项目
  • 资助金额:
    48.00万元
  • 批准年份:
    2023
  • 负责人:
    林俐
  • 依托单位:
膀胱癌高表达基因UPK3A的筛选、鉴定和相关研究
  • 批准号:
    81101922
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    23.0万元
  • 批准年份:
    2011
  • 负责人:
    来永庆
  • 依托单位:
图像分类方法研究及其在色情监测中的应用
  • 批准号:
    61172103
  • 项目类别:
    面上项目
  • 资助金额:
    62.0万元
  • 批准年份:
    2011
  • 负责人:
    王春恒
  • 依托单位: