Collaborative Reseach: Type Qualifiers for Software Security
协作研究:软件安全的类型限定符
基本信息
- 批准号:0430378
- 负责人:
- 金额:--
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2004
- 资助国家:美国
- 起止时间:2004-09-15 至 2010-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
0430378PI Alex AikenCollaborative Research: Type Qualifiers for Software Security0430118 Foster, Jeffrey 0430585 Wagner, DavidThis research aims to develop tools and techniques to find and eliminate security vulnerabilities in software. The approach is based on static analysis, which by analyzing source code can model all possible executions of a program. The distinguishing feature of the project is to show that very large applications are free from classes of security vulnerabilities. Thus, the focus is not just in finding security holes in software, but in verifying their absence. Previous experience has shown that simple, approximate tools do not find all oreven nearly all security vulnerabilities; the higher assurance given by verification is needed. The experimental goal is to apply these techniques to the Linux kernel, a security-critical application withmillions of lines of code.The main technical approach being investigated is based on user-defined type qualifiers that refine the standard types of the programming language. Previous work has shown that type qualifiers are a natural and useful way to explicitly specify desired security properties that are normally only implicit in a program. In much the same way that a correctly typed program cannot have run-time type errors, having consistent type qualifiers throughout a program implies that the property expressed by those qualifiers must hold in everyexecution. The significance of this work is that, if successful, it will improve the understanding of how to perform sophisticated static analysis of very large programs. The broader impact will be in discovering andrepairing new security vulnerabilities in widely-used software infrastructure and in verifying that some of that infrastructure is free from at least some security flaws.
0430378PI ALEX AIKENCOLLABORAVITAL研究:软件安全性的键入预选赛0430118 Foster,Jeffrey 0430585 Wagner,Davidthis Research旨在开发工具和技术以查找和消除软件中的安全性漏洞。 该方法基于静态分析,通过分析源代码可以建模程序的所有可能执行。 该项目的显着特征是表明,很大的应用程序没有安全漏洞类别。 因此,重点不仅在于在软件中找到安全孔,还在于验证其缺席。 以前的经验表明,简单的,近似工具几乎没有发现几乎所有安全漏洞。需要通过验证给出的更高的保证。 实验目标是将这些技术应用于Linux内核,这是一项具有数百万个代码行的关键安全应用程序。研究的主要技术方法基于使用用户定义的类型预选赛,可完善编程语言的标准类型。 先前的工作表明,类型的预选赛是一种自然而有用的方法,可以显式指定通常仅在程序中隐含的所需的安全属性。 与正确键入的程序不能具有运行时类型错误的方式,在整个程序中具有一致的类型预选赛,这意味着这些资格表达的属性必须在EverySexuction中保留。 这项工作的重要性是,如果成功,它将提高人们对如何对非常大的程序进行复杂的静态分析的理解。 在广泛使用的软件基础架构中发现安装新的安全漏洞,并验证某些基础架构是否至少没有某些安全缺陷,这将是更广泛的影响。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Alexander Aiken其他文献
DataSplash: A Direct Manipulation Environment for Programming Semantic Zoom Visualizations of Tabular Data
DataSplash:用于对表格数据的语义缩放可视化进行编程的直接操作环境
- DOI:
10.1006/jvlc.2001.0219 - 发表时间:
2001 - 期刊:
- 影响因子:0
- 作者:
Allison Woodruff;Christopher Olston;Alexander Aiken;Michael Chu;V. Ercegovac;Mark Lin;Mybrid Spalding;Michael Stonebraker - 通讯作者:
Michael Stonebraker
The Imported Fever Service; a UK-wide system for improved management and diagnosis of fever in returned travellers
- DOI:
10.1016/j.jinf.2013.07.012 - 发表时间:
2013-10-01 - 期刊:
- 影响因子:
- 作者:
Alexander Aiken;Jonathan Lambourne;Amanda Semper;Meera Chand;Jane Osborne;Behzad Nadjm;Catherine Roberts;Katherine Russell;Surabhi Taori;Malur Sudhanva;Peter Chiodini;Nick Beeching;Tim Brooks - 通讯作者:
Tim Brooks
VIQING: visual interactive querying
VIQING:可视化交互式查询
- DOI:
10.1109/vl.1998.706159 - 发表时间:
1998 - 期刊:
- 影响因子:0
- 作者:
Christopher Olston;Michael Stonebraker;Alexander Aiken;J. M. Hellerstein - 通讯作者:
J. M. Hellerstein
CommBench: Micro-Benchmarking Hierarchical Networks with Multi-GPU, Multi-NIC Nodes
CommBench:使用多 GPU、多 NIC 节点对分层网络进行微基准测试
- DOI:
- 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Mert Hidayetoğlu;Simon Garcia De Gonzalo;Elliott Slaughter;Yu Li;Christopher Zimmer;Tekin Bicer;Bin Ren;William Gropp;Wen;Alexander Aiken - 通讯作者:
Alexander Aiken
Alexander Aiken的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Alexander Aiken', 18)}}的其他基金
SHF: Medium: Stochastic Program Optimization
SHF:中:随机程序优化
- 批准号:
1409813 - 财政年份:2014
- 资助金额:
-- - 项目类别:
Standard Grant
Synthesis and Analysis of Heap Data Structures
堆数据结构的综合与分析
- 批准号:
1160904 - 财政年份:2012
- 资助金额:
-- - 项目类别:
Continuing Grant
SHF: Small: Statistical Analysis of Software
SHF:小型:软件统计分析
- 批准号:
0915766 - 财政年份:2009
- 资助金额:
-- - 项目类别:
Standard Grant
CT-T: Collaborative Research: Complex, High-level, Integrated Properties for Security
CT-T:协作研究:复杂、高级、集成的安全属性
- 批准号:
0716695 - 财政年份:2007
- 资助金额:
-- - 项目类别:
Standard Grant
CSR---EHS: Static and Dynamic Analysis of Embedded Systems
CSR---EHS:嵌入式系统的静态和动态分析
- 批准号:
0509558 - 财政年份:2005
- 资助金额:
-- - 项目类别:
Continuing Grant
Program Analysis: Logics, Algorithms, and Application
程序分析:逻辑、算法和应用
- 批准号:
9416973 - 财政年份:1995
- 资助金额:
-- - 项目类别:
Continuing Grant
NYI: Constraint-Based Program Analysis
NYI:基于约束的程序分析
- 批准号:
9457812 - 财政年份:1994
- 资助金额:
-- - 项目类别:
Continuing Grant
相似国自然基金
指向提议者的共情关怀对第三方惩罚行为的影响:心理、脑与计算机制
- 批准号:32371102
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
经济博弈中提议者对先前第三方干预者的分配公平性研究
- 批准号:
- 批准年份:2020
- 资助金额:24 万元
- 项目类别:青年科学基金项目
基于深度层次特征相似性度量的视觉跟踪方法研究
- 批准号:61773397
- 批准年份:2017
- 资助金额:65.0 万元
- 项目类别:面上项目
构造类型专家系统及其开发工具的研究
- 批准号:68875006
- 批准年份:1988
- 资助金额:2.0 万元
- 项目类别:面上项目
相似海外基金
Reseach on employment stability and autonomy of professional-type white-collar and the structure of division and cooperation of labor
职业型白领就业稳定性、自主性及分工合作结构研究
- 批准号:
17530217 - 财政年份:2005
- 资助金额:
-- - 项目类别:
Grant-in-Aid for Scientific Research (C)
Reseach on an electro-mechanical energy conversion system with small size and 95% efficiency
研究%20on%20an%20机电%20energy%20conversion%20system%20with%20small%20size%20and%2095%%20efficiency
- 批准号:
07555406 - 财政年份:1995
- 资助金额:
-- - 项目类别:
Grant-in-Aid for Scientific Research (B)
Reseach for Mulltinational Corporations of Japanese-type Agribusiness
日式农业跨国公司研究
- 批准号:
06660274 - 财政年份:1994
- 资助金额:
-- - 项目类别:
Grant-in-Aid for Scientific Research (C)
Basic reseach for a remedy to allergic tissue inflammation
过敏性组织炎症治疗的基础研究
- 批准号:
05671833 - 财政年份:1993
- 资助金额:
-- - 项目类别:
Grant-in-Aid for General Scientific Research (C)
Reseach of operators and operator algebras and of its applications
算子和算子代数及其应用的研究
- 批准号:
61540076 - 财政年份:1986
- 资助金额:
-- - 项目类别:
Grant-in-Aid for General Scientific Research (C)