FMitF: Track II: Usability, Scalability, and Deployment Improvement of VerioT

FMITF:轨道 II:VerioT 的可用性、可扩展性和部署改进

基本信息

  • 批准号:
    2124225
  • 负责人:
  • 金额:
    $ 10万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2021
  • 资助国家:
    美国
  • 起止时间:
    2021-07-01 至 2023-12-31
  • 项目状态:
    已结题

项目摘要

The Internet-of-Things (IoT) access-delegation paradigm is emerging and supported by mainstream IoT vendors. In this paradigm, companies provide support to delegate device access to a delegatee cloud/vendor (such as Google Home, SmartThings, and Apple Home), thus permitting a user to manage multiple devices from different vendors through a single app of the delegatee. Flawed design and implementation of IoT delegation protocols incur serious security and safety consequences, such as unauthorized control of smart door locks and health devices. This project improves and extends VerioT (built on the Spin model-checker), the first formal-verification tool for real-world IoT delegation protocols. The project’s novelties are in new methods to facilitate (1) IoT security analysis leveraging usability-enhanced verification reporting, (2) automatic, scalability-enhanced model construction, and (3) integrating verification techniques to modern IoT software development lifecycle. The project’s impacts will be to enable IoT stakeholders and developers to find security flaws earlier --- ideally as soon as the flaws are introduced --- and to increase assurance in the security of IoT systems.The project includes three main tasks. First, to increase the usability of VerioT, the investigators are improving bug reporting by automatically annotating the reported counter-examples with IoT contexts and operations in natural language texts, producing industry-standard security-bug reports. Second, to increase scalability, the investigators are automating model construction by adopting novel Natural Language Processing (NLP) based document analysis techniques, called Dilution, which can precisely construct protocol state machines from unstructured documentation. Third, the investigators are developing support for enterprise-level deployment by integrating VerioT into modern Continuous Integration/Continuous Deployment (CI/CD) pipelines in the software-engineering and IoT industries. The project is intended to yield an industry-strength IoT protocol verifier that keeps up with the development of verification technology and IoT software practices, and helps developers proactively identify new bugs in IoT protocols and software before they are deployed in production.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
主流物联网供应商正在出现和支持。在此范式中,公司提供了支持设备访问委托云/供应商(例如Google Home,Smartthings和Apple Home)的支持,从而允许用户通过Veclegatee的单个应用程序管理来自不同供应商的多个设备。物联网代表团协议的设计和实施有缺陷,会产生严重的安全和安全后果,例如未经授权控制智能门锁和健康设备。该项目改进并扩展了Veriot(建立在Spin Model-Checker上),这是现实世界IoT代表团协议的第一个正式验证工具。该项目的新颖性是支持(1)IOT安全分析的新方法,利用可用性增强的验证报告,(2)自动,可伸缩性增强的模型构建,以及(3)将验证技术集成到现代IoT软件开发生命周期。该项目的影响将是使物联网利益相关者和开发人员早些时候找到安全缺陷 - 理想情况下,一旦引入了这些缺陷,并提高了物联网系统安全性的保证。该项目包括三个主要任务。首先,为了提高Veriot的可用性,调查人员通过自动注释自然语言文本中的物联网上下文和操作来改善错误报告,从而产生行业标准的安全性BUG报告。其次,为了提高可扩展性,研究人员通过采用新型的自然语言处理(NLP)的文档分析技术(称为稀释)来自动化模型构建,该技术可以准确地从非结构化文档中构建协议状态机器。第三,调查人员正在通过将Veriot集成到软件工程和物联网行业中的现代连续集成/连续部署(CI/CD)管道中,从而为企业级部署提供支持。该项目旨在产生一个行业强度的物联网协议验证器,以跟上验证技术和物联网软件实践的开发,并帮助开发人员在生产中部署在物联网协议和软件中的新错误。这奖反映了NSF的法定任务,并通过使用基础的智力效果和广泛的范围来评估支持,并通过评估值得评估。

项目成果

期刊论文数量(3)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
MQTTactic: Security Analysis and Verification for Logic Flaws in MQTT Implementations
MQTTactic:MQTT 实现中逻辑缺陷的安全分析和验证
P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access Policies
Who's In Control? On Security Risks of Disjointed IoT Device Management Channels
  • DOI:
    10.1145/3460120.3484592
  • 发表时间:
    2021-11
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Yan Jia;Bin Yuan;Luyi Xing;Dongfang Zhao;Yifan Zhang;Xiaofeng Wang;Yijing Liu;Kaimin Zheng;Peyton Crnjak;Yuqing Zhang;Deqing Zou;Hai Jin
  • 通讯作者:
    Yan Jia;Bin Yuan;Luyi Xing;Dongfang Zhao;Yifan Zhang;Xiaofeng Wang;Yijing Liu;Kaimin Zheng;Peyton Crnjak;Yuqing Zhang;Deqing Zou;Hai Jin
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Luyi Xing其他文献

Superoxide radical mediated persulfate activation by nitrogen doped bimetallic MOF (FeCo/N-MOF) for efficient tetracycline degradation, , 282 (2022): 120124.
氮掺杂双金属 MOF (FeCo/N-MOF) 介导的超氧自由基介导的过硫酸盐活化可有效降解四环素,, , 282 (2022): 120124。
A chip thermal management method realizing integrated applications of cooling, power generation and heat flow measurement based on thermoelectric effect
  • DOI:
    10.1016/j.applthermaleng.2024.124739
  • 发表时间:
    2025-01-15
  • 期刊:
  • 影响因子:
  • 作者:
    Liuyijie Huang;Luyi Xing;Yihua Zheng;Huimin Yao
  • 通讯作者:
    Huimin Yao
SmartPatch: Verifying the Authenticity of the Trigger-Event in the IoT Platform
SmartPatch:验证物联网平台中触发事件的真实性
Cloud repository as a malicious service: challenge, identification and implication
云存储库作为恶意服务:挑战、识别和影响
  • DOI:
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Xiaojing Liao;Sumayah A. Alrwais;Kan Yuan;Luyi Xing;Xiaofeng Wang;S. Hao;R. Beyah
  • 通讯作者:
    R. Beyah

Luyi Xing的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Luyi Xing', 18)}}的其他基金

Collaborative Research: EAGER: Towards Safeguarding the Emerging Miniapp Paradigm in Mobile Super Apps
合作研究:EAGER:捍卫移动超级应用中新兴的小应用范式
  • 批准号:
    2330265
  • 财政年份:
    2023
  • 资助金额:
    $ 10万
  • 项目类别:
    Standard Grant
CAREER: Foundations for IoT Cloud Security
职业:物联网云安全的基础
  • 批准号:
    2145675
  • 财政年份:
    2022
  • 资助金额:
    $ 10万
  • 项目类别:
    Continuing Grant

相似国自然基金

石羊河上游径流水源追踪量化的模拟研究
  • 批准号:
    42301153
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
面向复杂场景的说话人追踪关键技术研究
  • 批准号:
    62306029
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
单波段机载LiDAR测深的瞬时海面确定及光线追踪
  • 批准号:
    42304051
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
用户兴趣迁移现象下基于图神经网络的舆情追踪技术研究
  • 批准号:
    62302199
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
基于量子电压动态追踪补偿的精密磁通测量方法研究
  • 批准号:
    52307021
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

FMitF: Track II: Educating Developers about Ownership in Rust
FMITF:轨道 II:对开发人员进行 Rust 所有权教育
  • 批准号:
    2319014
  • 财政年份:
    2023
  • 资助金额:
    $ 10万
  • 项目类别:
    Standard Grant
FMitF: Track II: SMT-Based Reachability Analyzer of NGAC Policies
FMitF:轨道 II:NGAC 策略的基于 SMT 的可达性分析器
  • 批准号:
    2318891
  • 财政年份:
    2023
  • 资助金额:
    $ 10万
  • 项目类别:
    Standard Grant
Collaborative Research: FMitF: Track II: Cross-Language Support for Runtime Verification
合作研究:FMitF:轨道 II:运行时验证的跨语言支持
  • 批准号:
    2319473
  • 财政年份:
    2023
  • 资助金额:
    $ 10万
  • 项目类别:
    Standard Grant
FMitF: Track II: Bringing Verification-Aware Languages and Federated Authentication to Enable Secure Computing for Scientific Communities
FMITF:轨道 II:引入验证感知语言和联合身份验证,为科学界提供安全计算
  • 批准号:
    2319190
  • 财政年份:
    2023
  • 资助金额:
    $ 10万
  • 项目类别:
    Standard Grant
FMitF: Track II: Cybolic: a symbolic execution technique and tool for analyzing CMake build scripts
FMITF:轨道 II:Cybolic:用于分析 CMake 构建脚本的符号执行技术和工具
  • 批准号:
    2319131
  • 财政年份:
    2023
  • 资助金额:
    $ 10万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了