TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
TWC:中:协作:改进纵深防御软件
基本信息
- 批准号:1408826
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2014
- 资助国家:美国
- 起止时间:2014-09-01 至 2016-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The computer security community has long advocated the concept of building multiple layers of defense to protect a system. Unfortunately, it has been difficult to realize this vision in the practice of software development, and software often ships with inadequate defenses, typically developed in an ad hoc fashion.Developers face a number of challenges when protecting a software system with multiple layers of defense. They lack holistic frameworks in which to express policies and mechanisms for different software layers, automated tools to add these defenses, and tools to prove that software enhanced with defenses has an advertised level of assurance.This project develops new techniques to retrofit software for defense in depth. It takes a comprehensive view of the problem, with an emphasis on automated, interactive tools that developers can use to identify site-level security goals, explore the design space of adding security mechanisms, and retrofit legacy code to enforce security policies in a manner that can be machine-verified for assurance. The project develops theory and tools for formal policy language design and validation, static and dynamic code analyses, interactive tools for developers to explore the design space of security, functionality and performance tradeoffs, and methods to formally verify the correctness of program transformations to introduce defenses such as authorization, attacker containment, and auditing mechanisms.The broader impact stems from the improved security of systems and the reduced cost of achieving better security, also education activities in the form of summer schools for graduate, undergraduate and high-school students. The tools developed will be released to the public domain, benefiting software developers in the field.
长期以来,计算机安全界一直主张建立多层防御以保护系统的概念。 不幸的是,很难在软件开发实践中意识到这一愿景,而软件通常会以不足的防御措施发货,通常以临时方式开发。开发人员在保护具有多层防御层的软件系统时面临许多挑战。他们缺乏向不同软件层表达策略和机制的整体框架,添加这些防御工具的自动化工具以及证明软件增强的工具具有广告的保证水平。该项目开发了对深度防御的改造软件的新技术。它可以全面了解该问题,重点是开发人员可以用来识别站点级安全目标的自动交互式工具,探索添加安全机制的设计空间以及改进旧版代码以以机器验证的方式执行安全策略以确保保证。该项目为形式的政策语言设计和验证开发理论和工具,进行静态和动态代码分析,开发人员的交互式工具,探索安全性,功能性和绩效折衷的设计空间,以及正式验证程序转换的正确性,以介绍授权,攻击者遏制和审核机制的改进的较高的安全性,使得越来越多的夏季安全性,以及改进的安全性。毕业生,本科和高中生的学校。开发的工具将发布给公共领域,使该领域的软件开发人员受益。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Gang Tan其他文献
Detection and Classification of Different Botnet C&C Channels
- DOI:
10.1007/978-3-642-23496-5_17 - 发表时间:
2011-01-01 - 期刊:
- 影响因子:0
- 作者:
Fedynyshyn, Gregory;Mooi Choo Chuah;Gang Tan - 通讯作者:
Gang Tan
Braille to print translations for Chinese
盲文将打印中文翻译
- DOI:
10.1016/s0950-5849(01)00220-8 - 发表时间:
2002 - 期刊:
- 影响因子:3.9
- 作者:
Minghu Jiang;Xiaoyan Zhu;G. Gielen;E. Drábek;Ying Xia;Gang Tan;Ta Bao - 通讯作者:
Ta Bao
JNI Light: An Operational Model for the Core JNI (Technical Report)
- DOI:
- 发表时间:
2010 - 期刊:
- 影响因子:0
- 作者:
Gang Tan - 通讯作者:
Gang Tan
Designing sustainable built environments for Mars habitation: Integrating innovations in architecture, systems, and human well-being
- DOI:
10.1016/j.ynexs.2024.100030 - 发表时间:
2024-09-17 - 期刊:
- 影响因子:
- 作者:
Hongli Sun;Mengfan Duan;Yifan Wu;Yunyi Zeng;Hengxin Zhao;Shuangdui Wu;Borong Lin;Ronggui Yang;Gang Tan - 通讯作者:
Gang Tan
A state of the art review on the prediction of building energy consumption using data-driven technique and evolutionary algorithms
使用数据驱动技术和进化算法预测建筑能耗的最新技术综述
- DOI:
10.1177/0143624419843647 - 发表时间:
2020-01 - 期刊:
- 影响因子:1.7
- 作者:
Kangji Li;Wenping Xue;Gang Tan;Anthony S Denzer - 通讯作者:
Anthony S Denzer
Gang Tan的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Gang Tan', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Small: Detecting and Localizing Non-Functional Vulnerabilities in Machine Learning Libraries
协作研究:SaTC:核心:小型:检测和本地化机器学习库中的非功能性漏洞
- 批准号:
2230061 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Precise and Robust Binary Reverse Engineering and its Applications
SaTC:核心:小型:精确而鲁棒的二进制逆向工程及其应用
- 批准号:
2243632 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CAPA: Collaborative Research: Lightweight Abstract Memory Features
CAPA:协作研究:轻量级抽象内存功能
- 批准号:
1723571 - 财政年份:2017
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CAREER: User-Space Protection Domains for Compositional Information Security
职业:组合信息安全的用户空间保护域
- 批准号:
1624124 - 财政年份:2016
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
SHF:小型:协作研究:用于机器代码形式化建模的可重用工具
- 批准号:
1624125 - 财政年份:2016
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
TWC:中:协作:改进纵深防御软件
- 批准号:
1624126 - 财政年份:2016
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
SHF:小型:协作研究:用于机器代码形式化建模的可重用工具
- 批准号:
1217710 - 财政年份:2012
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CAREER: User-Space Protection Domains for Compositional Information Security
职业:组合信息安全的用户空间保护域
- 批准号:
1149211 - 财政年份:2012
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
TC: Small: Collaborative Research: Securing Multilingual Software Systems
TC:小型:协作研究:保护多语言软件系统
- 批准号:
0915157 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
III-CXT-Small: Collaborative Research: Structuring, Reasoning, and Querying in a Very Large Medical Image Database
III-CXT-Small:协作研究:在超大型医学图像数据库中构建、推理和查询
- 批准号:
0812073 - 财政年份:2008
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
相似国自然基金
复合低维拓扑材料中等离激元增强光学响应的研究
- 批准号:12374288
- 批准年份:2023
- 资助金额:52 万元
- 项目类别:面上项目
基于管理市场和干预分工视角的消失中等企业:特征事实、内在机制和优化路径
- 批准号:72374217
- 批准年份:2023
- 资助金额:41.00 万元
- 项目类别:面上项目
托卡马克偏滤器中等离子体的多尺度算法与数值模拟研究
- 批准号:12371432
- 批准年份:2023
- 资助金额:43.5 万元
- 项目类别:面上项目
中等质量黑洞附近的暗物质分布及其IMRI系统引力波回波探测
- 批准号:12365008
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
中等垂直风切变下非对称型热带气旋快速增强的物理机制研究
- 批准号:42305004
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1840790 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
- 批准号:
1937622 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
- 批准号:
1855391 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
- 批准号:
1854000 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant