Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
协作研究:SaTC:核心:中:重新思考安全性模糊测试
基本信息
- 批准号:2031377
- 负责人:
- 金额:$ 59.6万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-10-01 至 2022-02-28
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
In software, a vulnerability is a flaw in the code that can be exploited by a malicious actor to perform unauthorized activities or change the behavior of the software. Although a topic heavily studied by security researchers, finding software vulnerabilities is becoming increasingly challenging because the software widely used in day-to-day life is growing larger and more complicated. This project addresses this challenge by rethinking a classic technique called fuzzing for finding vulnerabilities from large software. The high-level idea of fuzzing is to create a large number of random inputs to run software and in turn trigger vulnerabilities. The novelties of this project are the new approaches, techniques, and tools that revolutionize fuzzing and make the nearly random testing process more intelligent and targeted. This way, this project will enhance security of various types of widely used software, ranging from web browsers to server-side programs.To that end, this project is investigating vulnerability-coverage-driven fuzzing. Existing fuzzing techniques primarily followed an approach called code-coverage-driven fuzzing, motivated by the belief that code coverage and vulnerability finding are strongly correlated. Challenging this widely held belief, this project shows that code coverage has weaker-than-expected ties with vulnerabilities and code-coverage-driven fuzzing is not well suited for vulnerability finding. Pioneering vulnerability-coverage-driven fuzzing, this project invents a series of novel techniques to (1) obtain feedback on vulnerability coverage (2) prioritize test inputs that can reach more vulnerabilities and (3) maximize the chance to trigger vulnerabilities reached by the test inputs. This project also produces new metrics, new benchmarks, and new frameworks for comprehensively evaluating the use of fuzzing for vulnerability finding. With the investigators' experience in research of software security and system security, this project provides a group of education, training, and research opportunities for both undergraduate and graduate students. Through industry outreach, the investigators pursue technology transfers and raise the awareness of software security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在软件中,漏洞是代码中的一个缺陷,恶意演员可以利用该漏洞来执行未经授权的活动或更改软件的行为。尽管安全研究人员大量研究的主题,但发现软件漏洞的越来越具有挑战性,因为在日常生活中广泛使用的软件越来越大,并且越来越复杂。该项目通过重新思考一种称为模糊的经典技术来解决这一挑战,以从大型软件中找到漏洞。模糊的高级想法是创建大量的随机输入来运行软件并触发漏洞。该项目的新颖性是彻底改变模糊并使几乎随机的测试过程更加聪明和有针对性的新方法,技术和工具。这样,该项目将增强各种广泛使用的软件的安全性,从Web浏览器到服务器端程序。现有的模糊技术主要遵循一种称为代码覆盖驱动的模糊的方法,其动机是因为人们认为代码覆盖率和脆弱性发现密切相关。该项目挑战了这种普遍认为的信念,表明代码覆盖范围与脆弱性和代码覆盖驱动的模糊相比较弱,不太适合发现脆弱性发现。该项目开创了以漏洞覆盖的驱动的损害,该项目发明了一系列新型技术,以(1)获得有关漏洞覆盖率的反馈(2)优先级测试输入,这些输入可以达到更多漏洞,并且(3)最大限度地触发了通过测试输入触发漏洞的机会。该项目还生产了新的指标,新的基准和新框架,以全面评估模糊的脆弱性发现。凭借研究人员在软件安全和系统安全研究方面的经验,该项目为本科生和研究生提供了一系列教育,培训和研究机会。通过行业宣传,调查人员进行技术转移并提高了软件安全的认识。该奖项反映了NSF的法定任务,并使用基金会的知识分子优点和更广泛的影响审查标准,被认为值得通过评估来获得支持。
项目成果
期刊论文数量(1)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Facilitating Parallel Fuzzing with mutually-exclusive Task Distribution
- DOI:10.1007/978-3-030-90022-9_10
- 发表时间:2021-09
- 期刊:
- 影响因子:0
- 作者:Yifan Wang;Yuchen Zhang;Chengbin Pang;Peng Li;Nikolaos Triandopoulos;Jun Xu
- 通讯作者:Yifan Wang;Yuchen Zhang;Chengbin Pang;Peng Li;Nikolaos Triandopoulos;Jun Xu
共 1 条
- 1
Jun Xu其他文献
The role of biasing electric field in intrinsic resistive switching characteristics of highly silicon-rich a-SiOx films1
偏置电场在高富硅 a-SiOx 薄膜本征电阻开关特性中的作用1
- DOI:
- 发表时间:20142014
- 期刊:
- 影响因子:0
- 作者:Yuefei Wang;Kunji Chen;Xin;Zhonghui Fang;Wei Li;Jun XuYuefei Wang;Kunji Chen;Xin;Zhonghui Fang;Wei Li;Jun Xu
- 通讯作者:Jun XuJun Xu
Free-standing reduced graphene oxide (rGO) membrane for salt-rejecting solar desalination via size effect
通过尺寸效应用于脱盐太阳能海水淡化的独立式还原氧化石墨烯(rGO)膜
- DOI:10.1515/nanoph-2020-039610.1515/nanoph-2020-0396
- 发表时间:20202020
- 期刊:
- 影响因子:7.5
- 作者:Pengyu Zhuang;Hanyu Fu;Ning Xu;Bo Li;Jun Xu;Lin ZhouPengyu Zhuang;Hanyu Fu;Ning Xu;Bo Li;Jun Xu;Lin Zhou
- 通讯作者:Lin ZhouLin Zhou
Cryptanalysis of elliptic curve hidden number problem from PKC 2017
PKC 2017 椭圆曲线隐数问题的密码分析
- DOI:10.1007/s10623-019-00685-y10.1007/s10623-019-00685-y
- 发表时间:2019-102019-10
- 期刊:
- 影响因子:0
- 作者:Jun Xu;Lei Hu;Santanu SarkarJun Xu;Lei Hu;Santanu Sarkar
- 通讯作者:Santanu SarkarSantanu Sarkar
Exploring the intercalation chemistry of layered yttrium hydroxides by 13C solid-state NMR spectroscopy
通过 13C 固态核磁共振波谱探索层状氢氧化钇的插层化学
- DOI:10.1016/j.mrl.2022.03.00110.1016/j.mrl.2022.03.001
- 发表时间:2022-032022-03
- 期刊:
- 影响因子:0
- 作者:Yanxin Liu;Shijia Jiang;Jun XuYanxin Liu;Shijia Jiang;Jun Xu
- 通讯作者:Jun XuJun Xu
Association of C(-106)T polymorphism in aldose reductase gene with diabetic retinopathy in Chinese patients with type 2 diabetes mellitus.
醛糖还原酶基因C(-106)T多态性与中国2型糖尿病患者糖尿病视网膜病变的关系
- DOI:10.1016/s1001-9294(14)60016-x10.1016/s1001-9294(14)60016-x
- 发表时间:20142014
- 期刊:
- 影响因子:0
- 作者:Yu Deng;Xiu;H. Gu;Apiradee Lim;Munkhtulga Ulziibat;T. Snellingen;Jun Xu;Kai Ma;N. LiuYu Deng;Xiu;H. Gu;Apiradee Lim;Munkhtulga Ulziibat;T. Snellingen;Jun Xu;Kai Ma;N. Liu
- 通讯作者:N. LiuN. Liu
共 1116 条
- 1
- 2
- 3
- 4
- 5
- 6
- 224
Jun Xu的其他基金
CAREER: Fuzzing Large Software: Principles, Methods, and Tools
职业:模糊大型软件:原理、方法和工具
- 批准号:23401982340198
- 财政年份:2024
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Continuing GrantContinuing Grant
Travel: NSF Student Travel Grant for 2023 ACM Conference on Computer and Communications Security (CCS)
旅行:2023 年 ACM 计算机和通信安全 (CCS) 会议 NSF 学生旅行补助金
- 批准号:23417732341773
- 财政年份:2023
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
CICI: TCR: Prompt, Reliable, and Safe Security Update for Cyberinfrastructure
CICI:TCR:网络基础设施的及时、可靠和安全的安全更新
- 批准号:23198802319880
- 财政年份:2023
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
协作研究:SaTC:核心:中:重新思考安全性模糊测试
- 批准号:22137272213727
- 财政年份:2022
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
CNS Core: Small: Towards Hybrid Data Center Switching Using Partially Reconfigurable Circuit Switch
CNS 核心:小型:使用部分可重构电路交换机实现混合数据中心交换
- 批准号:20070062007006
- 财政年份:2020
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
CNS Core: Small: Ultra-Low-Complexity Switching Algorithms for Scalable High Network Performance
CNS 核心:小型:超低复杂度交换算法,实现可扩展的高网络性能
- 批准号:19090481909048
- 财政年份:2019
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
NeTS: Small: Collaborative Research: Research into Worst-Case Large Deviation Theory for Network Algorithmics
NeTS:小型:协作研究:网络算法最坏情况大偏差理论的研究
- 批准号:14231821423182
- 财政年份:2014
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
NeTS: Medium: Collaborative Research: Towards Building Time Capsule for Online Social Activities
NeTS:媒介:协作研究:为在线社交活动构建时间胶囊
- 批准号:13021971302197
- 财政年份:2013
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
NeTS: Small: Collaborative Research: Towards Principled Network Troubleshooting via Efficient Packet Stream Processing
NetS:小型:协作研究:通过高效的数据包流处理实现有原则的网络故障排除
- 批准号:12180921218092
- 财政年份:2012
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
SBIR Phase I: Nanocomposites for Electronic Packaging
SBIR 第一阶段:用于电子封装的纳米复合材料
- 批准号:09125440912544
- 财政年份:2009
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Standard GrantStandard Grant
相似国自然基金
钛基骨植入物表面电沉积镁氢涂层及其促成骨性能研究
- 批准号:52371195
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
CLMP介导Connexin45-β-catenin复合体对先天性短肠综合征的致病机制研究
- 批准号:82370525
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
人工局域表面等离激元高灵敏传感及其系统小型化的关键技术研究
- 批准号:62371132
- 批准年份:2023
- 资助金额:49 万元
- 项目类别:面上项目
优先流对中俄原油管道沿线多年冻土水热稳定性的影响机制研究
- 批准号:42301138
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
用于稳定锌负极的界面层/电解液双向调控研究
- 批准号:52302289
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:23309402330940
- 财政年份:2024
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:23172322317232
- 财政年份:2024
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:23383012338301
- 财政年份:2024
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:23172332317233
- 财政年份:2024
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Continuing GrantContinuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:23383022338302
- 财政年份:2024
- 资助金额:$ 59.6万$ 59.6万
- 项目类别:Continuing GrantContinuing Grant