CRII: SaTC: Towards Detecting and Mitigating Vulnerabilities
CRII:SaTC:致力于检测和缓解漏洞
基本信息
- 批准号:2153474
- 负责人:
- 金额:$ 17.49万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-07-01 至 2024-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This award is funded in whole or in part under the American Rescue Plan Act of 2021 (Public Law 117-2).Numerous real-world attacks exploit software vulnerabilities to compromise computer systems such as servers, desktops, smart phones, and Internet of Things (IoT) devices. Recent studies show that it is challenging to detect vulnerabilities accurately and patch vulnerabilities rapidly. State-of-the-art techniques can mitigate unpatched vulnerabilities effectively, but they usually sacrifice the availability of systems. The goal of this project is to improve vulnerability detection and mitigation. The project’s novelties are two-fold. First, the project team is developing an approach to significantly increasing the accuracy of vulnerability detection. Second, the project team is developing an approach to substantially reducing the availability loss of vulnerability mitigation. The project's broader significance and importance are that 1) the approaches developed by the project can be used by other projects addressing vulnerabilities, 2) the outcome of the project can help the software industry in designing mechanisms to detect vulnerabilities and defend against vulnerability exploits; and 3) the project is tightly integrated with undergraduate-level and graduate-level curriculum development and student advising. A diverse group of undergraduate and graduate students are participating in the project and developing their interests and expertise in software security.The project aims to develop an accurate vulnerability-detection technique and an unobtrusive vulnerability-mitigation technique. To improve the accuracy, the vulnerability-detection technique uses vulnerability conditions, each of which captures the intrinsic characteristics of a type of vulnerabilities, to detect vulnerabilities. To reduce the availability loss, the vulnerability-mitigation technique uses basic blocks and program paths as the granularity of vulnerability mitigation. The project consists of three key tasks: 1) designing a scheme for encoding vulnerability conditions, 2) developing a technique based on fuzzing to detect vulnerabilities using vulnerability conditions, and 3) developing a technique based on code-disabling to mitigates vulnerabilities at the granularity of basic blocks and program paths. The major contributions of the project include the design of the techniques, prototype implementations of the techniques, and an evaluation of the implementations with real-world vulnerabilities.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
该奖项的全部或部分资金来源于《2021 年美国救援计划法案》(公法 117-2)。现实世界中的许多攻击利用软件漏洞来危害服务器、台式机、智能手机和物联网等计算机系统最近的研究表明,准确检测漏洞并快速修补漏洞具有挑战性,最先进的技术可以有效地缓解未修补的漏洞,但它们通常会牺牲可用性。该项目的目标是改进漏洞检测和缓解。该项目的新颖性有两个方面:第一,项目团队正在开发一种显着提高漏洞检测准确性的方法。该项目更广泛的意义和重要性在于:1)该项目开发的方法可以被其他解决漏洞的项目使用,2)该项目的结果可以帮助软件行业进行设计。检测漏洞的机制和防御漏洞利用;3) 该项目与本科生和研究生课程开发以及学生咨询紧密结合,不同的本科生和研究生群体正在参与该项目并培养他们在软件安全方面的兴趣和专业知识。该项目旨在开发一种准确的漏洞检测技术和一种不显眼的漏洞缓解技术。为了提高准确性,漏洞检测技术使用漏洞条件来检测,每个漏洞条件都捕获一类漏洞的内在特征。为了减少可用性损失,漏洞缓解技术使用基本块和程序路径作为漏洞缓解的粒度,该项目包括三个关键任务:1)设计漏洞条件编码方案,2)开发基于漏洞的技术。模糊测试使用漏洞条件来检测漏洞,3)开发一种基于代码禁用的技术,以在基本块和程序路径的粒度上减轻漏洞。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力优点和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Runtime Recovery for Integer Overflows
整数溢出的运行时恢复
- DOI:10.1109/icsrs56243.2022.10067783
- 发表时间:2022-11-23
- 期刊:
- 影响因子:0
- 作者:Zhen Huang
- 通讯作者:Zhen Huang
Multiclass Classification of Software Vulnerabilities with Deep Learning
利用深度学习对软件漏洞进行多类分类
- DOI:10.1145/3587716.3587738
- 发表时间:2023-02-17
- 期刊:
- 影响因子:0
- 作者:Crystal Contreras;Hristina Dokic;Zhen Huang;Daniela Stan Raicu;Jacob D. Furst;Roselyne B. Tchoua
- 通讯作者:Roselyne B. Tchoua
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Zhen Huang其他文献
Improving Transmission Availability for Wireless Cognitive Networks: SkyChannel Query Processing
提高无线认知网络的传输可用性:SkyChannel 查询处理
- DOI:
10.4028/www.scientific.net/amm.121-126.3977 - 发表时间:
2011-10-01 - 期刊:
- 影响因子:0
- 作者:
L. Liu;Gang Hu;Zhen Huang;Yuxing Peng - 通讯作者:
Yuxing Peng
Induction of somatic embryogenesis by anther-derived callus culture and plantlet ploidy determination in poplar (Populus × beijingensis)
杨树花药愈伤组织培养诱导体细胞胚胎发生和植株倍性测定(北京杨树)
- DOI:
10.1007/s11240-014-0649-3 - 发表时间:
2015-03-01 - 期刊:
- 影响因子:0
- 作者:
Zhen Huang;Congping Xu;Yun Li;P. Wang;Yuan Li;X. Kang - 通讯作者:
X. Kang
Towards breeding of rapeseed (Brassica napus) with alien cytoplasm and powdery mildew resistance from Ethiopian mustard (Brassica carinata)
培育具有外源细胞质和埃塞俄比亚芥菜(Brassica carinata)白粉病抗性的油菜籽(Brassica napus)
- DOI:
10.1270/jsbbs.20017 - 发表时间:
2020-05-19 - 期刊:
- 影响因子:2.4
- 作者:
Qiong Gong;C. Dai;Xiao;Xiao;Zhen Huang;Aixia Xu;Jungang Dong;Chengyu Yu - 通讯作者:
Chengyu Yu
Large Enhancement of 2D Electron Gases Mobility Induced by Interfacial Localized Electron Screening Effect
界面局域电子屏蔽效应导致二维电子气体迁移率大幅增强
- DOI:
10.1002/adma.201707428 - 发表时间:
2018-05-01 - 期刊:
- 影响因子:29.4
- 作者:
X. Chi;Zhen Huang;T. Asmara;K. Han;Xinmao Yin;Xiaojiang Yu;C. Diao;Ming Yang;Ming Yang;Daniel Schmidt;P. Yang;P. E. Trevisanutto;T. J. Whitcher;T. Venkatesan;M. Breese;Ari;o;o;A. Rusydi - 通讯作者:
A. Rusydi
Development of multi-component surrogates of diesel from indirect coal liquefaction for spray analysis
开发用于喷雾分析的煤炭间接液化柴油的多组分替代品
- DOI:
10.1016/j.energy.2018.03.167 - 发表时间:
2018-06-01 - 期刊:
- 影响因子:9
- 作者:
Zhong Huang;Xiaochen Xu;D. Ju;D. Han;X. Qiao;Zhen Huang - 通讯作者:
Zhen Huang
Zhen Huang的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Zhen Huang', 18)}}的其他基金
I-Corps: Selenium Nucleic Acids for Structure Determination, Drug Discovery and Commercialization
I-Corps:用于结构测定、药物发现和商业化的硒核酸
- 批准号:
1340153 - 财政年份:2013
- 资助金额:
$ 17.49万 - 项目类别:
Standard Grant
SBIR Phase II: Energy Efficient COD Removal and De-nitrification for Re-circulating Aquaculture Facilities with a Combined Bio-electrochemical Process
SBIR 第二阶段:采用组合生物电化学工艺对再循环水产养殖设施进行节能 COD 去除和反硝化
- 批准号:
1127435 - 财政年份:2011
- 资助金额:
$ 17.49万 - 项目类别:
Standard Grant
Atom-specific Selenium Derivatization of Nucleic Acids for Crystallization and Structure Studies
用于结晶和结构研究的核酸原子特异性硒衍生化
- 批准号:
0824837 - 财政年份:2008
- 资助金额:
$ 17.49万 - 项目类别:
Continuing Grant
New Paradigm of Nucleic Acids Engineered with Selenium
用硒设计的核酸的新范例
- 批准号:
0750235 - 财政年份:2008
- 资助金额:
$ 17.49万 - 项目类别:
Continuing Grant
Systematic Derivatization of Nucleic Acids with Selenium for X-ray Crystallography
用于 X 射线晶体学的硒系统核酸衍生化
- 批准号:
0517092 - 财政年份:2005
- 资助金额:
$ 17.49万 - 项目类别:
Continuing Grant
相似海外基金
CRII: SaTC: Towards a Secure and Efficient Ethereum P2P Network with Client Diversity
CRII:SaTC:迈向具有客户端多样性的安全高效的以太坊 P2P 网络
- 批准号:
2347486 - 财政年份:2024
- 资助金额:
$ 17.49万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
CRII:SaTC:了解图神经网络对抗图扰动的鲁棒性
- 批准号:
2241713 - 财政年份:2023
- 资助金额:
$ 17.49万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Understanding and Defending Against New Waves of Online Hate
CRII:SaTC:理解和防御新一波的网络仇恨
- 批准号:
2245983 - 财政年份:2023
- 资助金额:
$ 17.49万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Data-effective and Cost-efficient Security Attack Detections
CRII:SaTC:迈向数据有效且经济高效的安全攻击检测
- 批准号:
2245968 - 财政年份:2023
- 资助金额:
$ 17.49万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Secure and Privacy-preserving Input on Augmented Reality Systems
CRII:SaTC:增强现实系统的安全和隐私保护输入
- 批准号:
2153397 - 财政年份:2022
- 资助金额:
$ 17.49万 - 项目类别:
Standard Grant