CAREER: At-scale Analysis of Issues in Cyber-Security and Software Engineering
职业:网络安全和软件工程问题的大规模分析
基本信息
- 批准号:1552836
- 负责人:
- 金额:$ 48.72万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2016
- 资助国家:美国
- 起止时间:2016-05-15 至 2022-04-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
One of the most significant challenges in cybersecurity is that humans are involved in software engineering and inevitably make security mistakes in their implementation of specifications, leading to software vulnerabilities. A challenge to eliminating these mistakes is the relative lack of empirical evidence regarding what secure coding practices (e.g., secure defaults, validating client data, etc.), threat modeling, and educational solutions are effective in reducing the number of application-level vulnerabilities that software engineers produce. This research aims to perform experiments analyzing programming assignment submissions to Massively Open Online Courses (MOOCs) before and after secure coding and threat modeling techniques are taught to empirically measure their impact on the rate of security vulnerabilities in assignment implementations. A key component of this research will be the use of MOOC assignment specifications and variations that have the potential to be affected by common cybersecurity vulnerabilities, such as problems with input validation to web applications or privilege escalation on mobile platforms. Because these critical security implementation issues will be known ahead of time, the MOOC assignments will allow automated assessment of how successfully each assignment implementation manages these security issues.Key questions investigated by this research include analyzing the impact of varying secure coding and threat modeling techniques on vulnerability production in software, what level of abstraction these techniques need to be taught at to be effective, the relative return on investment of threat modeling vs. automated vulnerability assessment effort, and the comparative effectiveness of making developers aware of security issues versus requiring active application of secure coding and threat modeling techniques. The broader impact of this research is substantial. Very little empirical data is available for organizations to use to properly value the secure coding and threat modeling techniques that have been developed. By creating a large body of rigorous evidence to illustrate how effective (or possibly not effective) different techniques are, the research will allow organizations to evaluate their return on investment and improve the use of these techniques in the software engineering process.
网络安全方面最重要的挑战之一是,人类参与软件工程,不可避免地犯了安全错误,从而导致软件漏洞。消除这些错误的挑战是,相对缺乏有关哪种安全编码实践(例如,安全默认,验证客户数据等),威胁建模和教育解决方案有效减少应用程序级别漏洞的数量,这些证据相对缺乏经验证据。软件工程师生产。这项研究旨在进行实验,以分析编程作业提交内容,以在安全的编码和威胁建模技术之前和之后大规模打开在线课程(MOOC),以经验来衡量其对分配实施中安全脆弱性率的影响。这项研究的关键组成部分是使用MOOC分配规格和有可能受到常见网络安全漏洞影响的变化,例如对Web应用程序的输入验证问题或移动平台上的特权升级。由于这些关键的安全实施问题将提前知道,因此MOOC任务将允许自动评估每个任务实施如何管理这些安全问题。本研究所调查的关键问题包括分析不同的安全编码和威胁建模技术对上的影响软件中的脆弱性生产,需要教授这些技术的何种抽象,要有效,威胁建模与自动漏洞评估工作的相对投资回报率以及使开发人员意识到安全问题而不是需要主动应用程序的比较有效性安全的编码和威胁建模技术。这项研究的更广泛影响是巨大的。几乎没有经验数据可供组织使用,以正确地重视已开发的安全编码和威胁建模技术。通过创建大量严格的证据来说明不同技术的有效性(或可能无效),该研究将使组织能够评估其投资回报率并改善这些技术在软件工程过程中的使用。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Christopher White其他文献
Understanding the Human Brain using Brain Organoids and a Structure-Function Theory
使用脑类器官和结构功能理论了解人脑
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
G. Silva;A. Muotri;Christopher White - 通讯作者:
Christopher White
Experimental Investigation of Magnesium/Regolith Combustion for In-Situ Production of Materials on the Moon
- DOI:
- 发表时间:
2011 - 期刊:
- 影响因子:0
- 作者:
Christopher White - 通讯作者:
Christopher White
Reinforcement Motor Learning After Cerebellar Damage Is Related to State Estimation
小脑损伤后的强化运动学习与状态估计有关
- DOI:
10.1101/2023.08.17.553756 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Christopher White;Evan C. Snow;A. Therrien - 通讯作者:
A. Therrien
Cortisol-dehydroepiandrosterone ratios are inversely associated with hippocampal and prefrontal brain volume in schizophrenia
皮质醇-脱氢表雄酮比率与精神分裂症患者的海马和前额叶脑体积呈负相关
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:3.7
- 作者:
E. Ji;C. Weickert;T. Purves;Christopher White;David Handelsman;R. Desai;M. O’Donnell;Dennis Liu;C. Galletly;R. Lenroot;T. Weickert - 通讯作者:
T. Weickert
Gone to the Dogs: Closure and Restoration of the Former Elk Meadow Park Dog Off-Leash Area
去狗处:前麋鹿草甸公园狗脱绳区的关闭和恢复
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0.9
- 作者:
A. Rayburn;S. Murdock;J. Lile;Matt Robbins;Christopher White - 通讯作者:
Christopher White
Christopher White的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Christopher White', 18)}}的其他基金
Strathclyde Discipline Hopping for Discovery Science 2022-23
斯特拉斯克莱德学科跳跃发现科学 2022-23
- 批准号:
NE/X017206/1 - 财政年份:2022
- 资助金额:
$ 48.72万 - 项目类别:
Research Grant
EMERGE: Multi-hazards and emergent risks in Northern Europe's remote and vulnerable regions
出现:北欧偏远和脆弱地区的多重灾害和紧急风险
- 批准号:
NE/W003775/1 - 财政年份:2021
- 资助金额:
$ 48.72万 - 项目类别:
Research Grant
CPS: TTP Option: Medium: Collaborative Research: Cyber-Physical System Integrity and Security with Impedance Signatures
CPS:TTP 选项:中:协作研究:具有阻抗签名的网络物理系统完整性和安全性
- 批准号:
1931931 - 财政年份:2019
- 资助金额:
$ 48.72万 - 项目类别:
Continuing Grant
I-Corps Teams: Leaf Global Fintech: Virtual Banking Beyond Borders
I-Corps 团队:Leaf Global Fintech:超越国界的虚拟银行
- 批准号:
1906995 - 财政年份:2018
- 资助金额:
$ 48.72万 - 项目类别:
Standard Grant
CPS: Synergy: Collaborative Research: Cyber-Physical Approaches to Advanced Manufacturing Security
CPS:协同:协作研究:先进制造安全的网络物理方法
- 批准号:
1446304 - 财政年份:2015
- 资助金额:
$ 48.72万 - 项目类别:
Cooperative Agreement
Collaborative Research: Building Capacity for Middle School Master Science Teacher Development
合作研究:中学科学硕士教师发展能力建设
- 批准号:
1439865 - 财政年份:2014
- 资助金额:
$ 48.72万 - 项目类别:
Standard Grant
NSF/DOE Advanced Combustion Engines: Collaborative Research: A Comprehensive Investigation of Unsteady Reciprocating Effects on Near-Wall Heat Transfer in Engines
NSF/DOE 先进内燃机:合作研究:对发动机近壁传热的非定常往复效应的综合研究
- 批准号:
1258702 - 财政年份:2013
- 资助金额:
$ 48.72万 - 项目类别:
Continuing Grant
RAPID: Collaborative Research: Cloud Environmental Analysis and Relief
RAPID:协作研究:云环境分析与缓解
- 批准号:
1047753 - 财政年份:2010
- 资助金额:
$ 48.72万 - 项目类别:
Standard Grant
Collaborative Research: Fundamental Investigation of Turbulent Ablation
合作研究:湍流消融的基础研究
- 批准号:
0967224 - 财政年份:2010
- 资助金额:
$ 48.72万 - 项目类别:
Standard Grant
相似国自然基金
大规模软件系统的性能缺陷机理分析与检测技术研究
- 批准号:62302514
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于基因组数据自动化分析为后生动物类群大规模开发扩增子捕获探针的实现
- 批准号:32370477
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
超大规模集成GPU系统的可靠性分析及优化研究
- 批准号:62372207
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
大规模网络数据统计分析与应用
- 批准号:72301258
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于光学成像的大规模活体细胞跟踪及其对细胞行为的定量分析
- 批准号:82302255
- 批准年份:2023
- 资助金额:20 万元
- 项目类别:青年科学基金项目
相似海外基金
CAREER: Computation-efficient Algorithms for Grid-scale Energy Storage Control, Bidding, and Integration Analysis
职业:用于电网规模储能控制、竞价和集成分析的计算高效算法
- 批准号:
2239046 - 财政年份:2023
- 资助金额:
$ 48.72万 - 项目类别:
Continuing Grant
2023 Chromosome Dynamics Gordon Research Conference and Seminar
2023年染色体动力学戈登研究会议暨研讨会
- 批准号:
10750086 - 财政年份:2023
- 资助金额:
$ 48.72万 - 项目类别:
CAREER: Interpretable Provenance Analysis for Heterogeneous Systems at Scale
职业:大规模异构系统的可解释来源分析
- 批准号:
2342250 - 财政年份:2023
- 资助金额:
$ 48.72万 - 项目类别:
Continuing Grant
Yuva Sath: A peer-led intervention to support substance use treatment and HIV prevention among young people who inject drugs in India
Yuva Sath:一项由同伴主导的干预措施,旨在支持印度注射吸毒年轻人的药物滥用治疗和艾滋病毒预防
- 批准号:
10698376 - 财政年份:2023
- 资助金额:
$ 48.72万 - 项目类别:
Leveraging complementary big data methods and patient intervention designs to optimize neural markers of adolescent cannabis use
利用互补的大数据方法和患者干预设计来优化青少年大麻使用的神经标记
- 批准号:
10739527 - 财政年份:2023
- 资助金额:
$ 48.72万 - 项目类别: