Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
协作研究:SaTC:核心:中:大胆探索:通过智能文档分析自动发现网络系统中的安全缺陷
基本信息
- 批准号:2409269
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-10-01 至 2026-06-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Specifications, developer guides and other documentations of networked systems (e.g., Internet applications, carrier networks) describe how these systems are designed, used and operate. These documentations are important sources for understanding security weaknesses in these systems and have not been fully leveraged due to the difficulty in analyzing their imprecise, convoluted and ambiguous content. Project Audacity (AUtomated Documentation Analysis for seCurITY) aims at addressing the challenge for security weakness discovery and remedy. Its novelties are the development of innovative technologies to enable automated document analysis for security protection. The project’s broader significance and importance include transferring the technologies to industry, involving members from under-represented groups in the project and disseminating outcomes through K9-12 outreach and community services. The project focuses on mitigating security risks of both design flaws and implementation vulnerabilities in networked systems, through automatically recovering security-related information (e.g., models, security properties) and confusing descriptions (e.g., inconsistent statements) from documentations to evaluate their security implications (e.g., verification of system designs, validation of predicted weaknesses on system implementations). This purpose is served by novel techniques based upon machine learning and natural language processing for analyzing different types of documentations, such as those for payment, single-sign-on, and for the 3rd Generation Partnership Project or 3GPP. Examples of such techniques include sentiment analysis for finding the statements related to security requirements and a similarity and differential analysis that compares different statements about similar security-critical operations to capture inconsistency. Furthermore, the project studies emerging techniques such as service syndication through comparing the documentations of different services and the 3GPP ecosystem from analyzing its public text data for risk measurement, identification and mitigation. This work complements program analysis to help enhance the security quality of networked systems, contributing to a better procedure and ecosystem that make security-critical documentations more precise, more consistent and less error-prone.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
网络系统(例如互联网应用程序、运营商网络)的规范、开发人员指南和其他文档描述了这些系统的设计、使用和操作方式。这些文档是了解这些系统中的安全弱点的重要来源,但由于以下原因尚未得到充分利用。分析其不精确、复杂和模糊的内容的困难。 Audacity 项目(安全自动化文档分析)旨在解决安全漏洞发现和补救的挑战,其新颖之处在于开发创新技术来实现。该项目更广泛的意义和重要性包括将技术转移到行业,让代表性不足的群体的成员参与该项目,并通过 K9-12 外展和社区服务传播成果。通过自动从文档中恢复与安全相关的信息(例如模型、安全属性)和令人困惑的描述(例如不一致的陈述)来评估网络系统中的设计缺陷和实现漏洞,以评估其安全影响(例如,验证系统设计、验证系统实现的预测弱点)通过基于机器学习和自然语言处理的新技术来实现这一目的,用于分析不同类型的文档,例如支付、单点登录的文档。对于第三代合作伙伴项目或 3GPP,此类技术的示例包括用于查找与安全要求相关的语句的情绪分析以及比较有关类似安全关键操作的不同语句以捕获项目的不一致之处的相似性和差异分析。研究新兴技术,例如作为服务联合组织,通过比较不同服务和 3GPP 生态系统的文档,分析其公共文本数据来进行风险测量、识别和缓解。这项工作补充了程序分析,有助于提高网络系统的安全质量,为更好的程序和生态系统做出贡献。使安全关键文档更加精确、更加一致且不易出错。该奖项反映了 NSF 的法定使命,并通过使用基金会的智力优点和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Feng Qian其他文献
Re-configurable Industrial Automation
可重新配置的工业自动化
- DOI:
10.1109/wcica.2008.4592961 - 发表时间:
2008-06-25 - 期刊:
- 影响因子:0
- 作者:
H. Tianfield;Feng Qian - 通讯作者:
Feng Qian
Evaluation of Phase Transformation and Mechanical Properties of Metastable Yttria-Stabilized Zirconia by Nanoindentation
纳米压痕评价亚稳态氧化钇稳定氧化锆的相变和机械性能
- DOI:
10.3390/ma12101677 - 发表时间:
2019-05-01 - 期刊:
- 影响因子:3.4
- 作者:
Ningning Song;Ziyuan Wang;Yan Xing;M. Zhang;Peng Wu;Feng Qian;Jing Feng;L. Qi;C. Wan;W. Pan - 通讯作者:
W. Pan
Distributed parameter modeling to prevent charge cancellation for discrete thickness piezoelectric energy harvester
用于防止离散厚度压电能量收集器电荷抵消的分布式参数建模
- DOI:
10.1016/j.sse.2017.12.010 - 发表时间:
2017-12-01 - 期刊:
- 影响因子:1.7
- 作者:
M. Krishnasamy;Feng Qian;L. Zuo;T. Lenka - 通讯作者:
T. Lenka
Cell membrane tethers generate mechanical force in response to electrical stimulation.
细胞膜系链响应电刺激而产生机械力。
- DOI:
10.1016/j.bpj.2010.05.025 - 发表时间:
2010-08-04 - 期刊:
- 影响因子:3.4
- 作者:
W. Brownell;Feng Qian;B. Anvari - 通讯作者:
B. Anvari
Improvement of quantum genetic algorithm and its application: Improvement of quantum genetic algorithm and its application
量子遗传算法的改进及其应用: 量子遗传算法的改进及其应用
- DOI:
10.3724/sp.j.1087.2008.00286 - 发表时间:
2008-02-20 - 期刊:
- 影响因子:0
- 作者:
Chuan;Feng Qian - 通讯作者:
Feng Qian
Feng Qian的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Feng Qian', 18)}}的其他基金
CPS: Medium: Collaborative Research: Transforming Connected and Automated Transportation with Smart Networking, Cooperative Sensing, and Edge Computing
CPS:中:协作研究:通过智能网络、协作传感和边缘计算改变互联和自动化交通
- 批准号:
2409271 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Conference: ACM SIGCOMM 2023 Travel Grant
会议:ACM SIGCOMM 2023 旅行补助金
- 批准号:
2335184 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: Innovating Volumetric Video Streaming with Motion Forecasting, Intelligent Upsampling, and QoE Modeling
合作研究:CNS 核心:中:通过运动预测、智能上采样和 QoE 建模创新体积视频流
- 批准号:
2409008 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: Medium: Innovating Volumetric Video Streaming with Motion Forecasting, Intelligent Upsampling, and QoE Modeling
合作研究:CNS 核心:中:通过运动预测、智能上采样和 QoE 建模创新体积视频流
- 批准号:
2212298 - 财政年份:2022
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
协作研究:SaTC:核心:中:大胆探索:通过智能文档分析自动发现网络系统中的安全缺陷
- 批准号:
2154078 - 财政年份:2022
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: Foundations and Scalable Algorithms for Personalized and Collaborative Virtual Reality Over Wireless Networks
协作研究:CNS 核心:中:无线网络上个性化和协作虚拟现实的基础和可扩展算法
- 批准号:
2106090 - 财政年份:2021
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CPS: Medium: Collaborative Research: Transforming Connected and Automated Transportation with Smart Networking, Cooperative Sensing, and Edge Computing
CPS:中:协作研究:通过智能网络、协作传感和边缘计算改变互联和自动化交通
- 批准号:
2038559 - 财政年份:2021
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
NeTS: Small: Collaborative Research:Practical HTTPS Traffic Manipulation At Middleboxes
NetS:小型:协作研究:中间盒的实用 HTTPS 流量操纵
- 批准号:
1917424 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CAREER: Improving Mobile Video Delivery for Emerging Contents and Networks
职业:改进新兴内容和网络的移动视频传输
- 批准号:
1915122 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
XPS: FULL: Collaborative Research: Enabling Scalable Cloud And Edge-device Integration Using Cross-layer Parallelism
XPS:完整:协作研究:使用跨层并行性实现可扩展的云和边缘设备集成
- 批准号:
1903880 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
相似国自然基金
基于肿瘤病理图片的靶向药物敏感生物标志物识别及统计算法的研究
- 批准号:82304250
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
肠道普拉梭菌代谢物丁酸抑制心室肌铁死亡改善老龄性心功能不全的机制研究
- 批准号:82300430
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
社会网络关系对公司现金持有决策影响——基于共御风险的作用机制研究
- 批准号:72302067
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
面向图像目标检测的新型弱监督学习方法研究
- 批准号:62371157
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
面向开放域对话系统信息获取的准确性研究
- 批准号:62376067
- 批准年份:2023
- 资助金额:51 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317232 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330940 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Using Intelligent Conversational Agents to Empower Adolescents to be Resilient Against Cybergrooming
合作研究:SaTC:核心:中:使用智能会话代理使青少年能够抵御网络诱骗
- 批准号:
2330941 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Differentially Private SQL with flexible privacy modeling, machine-checked system design, and accuracy optimization
协作研究:SaTC:核心:中:具有灵活隐私建模、机器检查系统设计和准确性优化的差异化私有 SQL
- 批准号:
2317233 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant