Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
协作研究:SaTC:核心:中:大胆探索:通过智能文档分析自动发现网络系统中的安全缺陷
基本信息
- 批准号:2409269
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-10-01 至 2026-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Specifications, developer guides and other documentations of networked systems (e.g., Internet applications, carrier networks) describe how these systems are designed, used and operate. These documentations are important sources for understanding security weaknesses in these systems and have not been fully leveraged due to the difficulty in analyzing their imprecise, convoluted and ambiguous content. Project Audacity (AUtomated Documentation Analysis for seCurITY) aims at addressing the challenge for security weakness discovery and remedy. Its novelties are the development of innovative technologies to enable automated document analysis for security protection. The project’s broader significance and importance include transferring the technologies to industry, involving members from under-represented groups in the project and disseminating outcomes through K9-12 outreach and community services. The project focuses on mitigating security risks of both design flaws and implementation vulnerabilities in networked systems, through automatically recovering security-related information (e.g., models, security properties) and confusing descriptions (e.g., inconsistent statements) from documentations to evaluate their security implications (e.g., verification of system designs, validation of predicted weaknesses on system implementations). This purpose is served by novel techniques based upon machine learning and natural language processing for analyzing different types of documentations, such as those for payment, single-sign-on, and for the 3rd Generation Partnership Project or 3GPP. Examples of such techniques include sentiment analysis for finding the statements related to security requirements and a similarity and differential analysis that compares different statements about similar security-critical operations to capture inconsistency. Furthermore, the project studies emerging techniques such as service syndication through comparing the documentations of different services and the 3GPP ecosystem from analyzing its public text data for risk measurement, identification and mitigation. This work complements program analysis to help enhance the security quality of networked systems, contributing to a better procedure and ecosystem that make security-critical documentations more precise, more consistent and less error-prone.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
规格,开发人员指南和其他网络系统的文档(例如,互联网应用程序,运营商网络)的设计,使用和操作是理解这些系统中安全弱点的重要来源,并且由于扩散性而没有完全利用在分析不精确的内容时,请参阅“ Audacity IMS”,以解决安全性和补救措施。社区服务。尽管自动推荐信息(例如,模型,安全属性),例如,不一致的陈述以评估其安全性(例如,验证系统设计,对系统实施的验证)根据学习和自然语言处理的新技术,例如分析以下付款,单签名和第三基因项目或3GPP的情感分析。通过构成不同服务的文档和3GPP生态系统的限制性操作,以分析其公共文本数据,以提高风险测量,识别和缓解。制作关键安全文件的生态系统M. Ore精确,更加一致,更容易出错。这一奖项反映了NSF的Beend Demed值得支持Thentel thentel宗教优点和更广泛的影响审查标准。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Feng Qian其他文献
Leaderless synchronization of coupled neural networks with the event-triggered mechanism
具有事件触发机制的耦合神经网络的无领导同步
- DOI:
10.1016/j.neunet.2018.05.012 - 发表时间:
2018-09 - 期刊:
- 影响因子:7.8
- 作者:
Siqi Lv;Wangli He;Feng Qian;Jinde Cao - 通讯作者:
Jinde Cao
Modeling and Optimization of a Steam System in a Chemical Plant Containing Multiple Direct Drive Steam Turbines
多台直驱汽轮机化工厂蒸汽系统建模与优化
- DOI:
10.1021/ie402438t - 发表时间:
2014-06 - 期刊:
- 影响因子:0
- 作者:
Zeqiu Li;Wenli Du;Liang Zhao;Feng Qian - 通讯作者:
Feng Qian
Unveiling the microscopic compression failure behavior of mesophase-pitch-based carbon fibers for improving the compressive strength of their polymer composites
揭示中间相沥青基碳纤维的微观压缩破坏行为,以提高其聚合物复合材料的压缩强度
- DOI:
10.1016/j.compositesb.2024.111658 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Ningyuan Zhang;Dong Huang;Huafeng Quan;Chong Ye;Chaoyi Peng;Lei Tao;Shi;Zhen Fan;Kui Shi;Feng Qian;Jinshui Liu - 通讯作者:
Jinshui Liu
Dense understory dwarf bamboo alters the retention of canopy tree seeds
茂密的林下矮竹改变了树冠种子的保留
- DOI:
10.1016/j.actao.2016.02.004 - 发表时间:
2016-05 - 期刊:
- 影响因子:0
- 作者:
Feng Qian;Tengda Zhang;Qinxue Guo;Jianping Tao - 通讯作者:
Jianping Tao
Synthesis and retarder mechanism study of a novel amphoteric composite high temperature-resistant retarder for oil well cement.
- DOI:
10.1039/c8ra01139g - 发表时间:
2018-04-18 - 期刊:
- 影响因子:3.9
- 作者:
Peng Zhigang;Zhang Jian;Feng Qian;Zou Changjun;Zheng Yong;Zhang Bojian;Huo Jinhua - 通讯作者:
Huo Jinhua
Feng Qian的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Feng Qian', 18)}}的其他基金
Conference: ACM SIGCOMM 2023 Travel Grant
会议:ACM SIGCOMM 2023 旅行补助金
- 批准号:
2335184 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: Innovating Volumetric Video Streaming with Motion Forecasting, Intelligent Upsampling, and QoE Modeling
合作研究:CNS 核心:中:通过运动预测、智能上采样和 QoE 建模创新体积视频流
- 批准号:
2409008 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CPS: Medium: Collaborative Research: Transforming Connected and Automated Transportation with Smart Networking, Cooperative Sensing, and Edge Computing
CPS:中:协作研究:通过智能网络、协作传感和边缘计算改变互联和自动化交通
- 批准号:
2409271 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: Innovating Volumetric Video Streaming with Motion Forecasting, Intelligent Upsampling, and QoE Modeling
合作研究:CNS 核心:中:通过运动预测、智能上采样和 QoE 建模创新体积视频流
- 批准号:
2212298 - 财政年份:2022
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
协作研究:SaTC:核心:中:大胆探索:通过智能文档分析自动发现网络系统中的安全缺陷
- 批准号:
2154078 - 财政年份:2022
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: Foundations and Scalable Algorithms for Personalized and Collaborative Virtual Reality Over Wireless Networks
协作研究:CNS 核心:中:无线网络上个性化和协作虚拟现实的基础和可扩展算法
- 批准号:
2106090 - 财政年份:2021
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CPS: Medium: Collaborative Research: Transforming Connected and Automated Transportation with Smart Networking, Cooperative Sensing, and Edge Computing
CPS:中:协作研究:通过智能网络、协作传感和边缘计算改变互联和自动化交通
- 批准号:
2038559 - 财政年份:2021
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
XPS: FULL: Collaborative Research: Enabling Scalable Cloud And Edge-device Integration Using Cross-layer Parallelism
XPS:完整:协作研究:使用跨层并行性实现可扩展的云和边缘设备集成
- 批准号:
1903880 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CAREER: Improving Mobile Video Delivery for Emerging Contents and Networks
职业:改进新兴内容和网络的移动视频传输
- 批准号:
1915122 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CAREER: Improving Mobile Video Delivery for Emerging Contents and Networks
职业:改进新兴内容和网络的移动视频传输
- 批准号:
1750890 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
相似国自然基金
离子型稀土渗流-应力-化学耦合作用机理与溶浸开采优化研究
- 批准号:52364012
- 批准年份:2023
- 资助金额:32 万元
- 项目类别:地区科学基金项目
亲环蛋白调控作物与蚜虫互作分子机制的研究
- 批准号:32301770
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于金属-多酚网络衍生多相吸波体的界面调控及电磁响应机制研究
- 批准号:52302362
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
职场网络闲逛行为的作用结果及其反馈效应——基于行为者和观察者视角的整合研究
- 批准号:72302108
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
EIF6负调控Dicer活性促进EV71复制的分子机制研究
- 批准号:32300133
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant