This Project Grant from the National Science Foundation Division of Computer and Network Systems, under the Computer and Information Science and Engineering federal grant program (CFDA 47.070), provides $517,545 in funding to the University of Utah from January 1, 2022 to September 30, 2024. The award supports research to advance software vulnerability detection techniques. Specifically, the university researchers will develop new approaches to fuzz testing, a method for identifying software...
This $500,000 project grant from the National Science Foundation's Computer and Information Science and Engineering program aims to develop new techniques for software vulnerability discovery. Specifically, the University of California, Riverside will receive funding from February 2022 through January 2025 to create a fast binary code concolic execution engine and dual concolic execution approach that combines source code and binary code analysis. These new methods seek to significantly...
This National Science Foundation (NSF) Computer and Information Science and Engineering (CISE) Federal Grant Award (CFDA 47.070) provides $311,482 to Purdue University to develop a comprehensive methodology for creating, deploying, and verifying software patches, particularly in scenarios where the original software source code is unavailable. The project aims to address security vulnerabilities in millions of devices that are currently left unpatched due to the challenges of patching legacy...
This $600,000 National Science Foundation project grant will fund the development of an Artificial Intelligence-Enabled Vulnerability Assessment and Remediation framework at Colorado State University-Pueblo from August 2022 to July 2025. The framework aims to address challenges in effectively assessing and prioritizing the hundreds of thousands of vulnerabilities often identified across multiple virtual environments in cloud infrastructures through two research thrusts. The first thrust will...
The University of Utah received a $220,500 Project Grant award from the National Science Foundation (NSF) under the Computer and Information Science and Engineering (CISE) program (CFDA 47.070). This 5-year award, beginning March 1, 2024, supports research to develop scalable security testing techniques for large software systems. The project focuses on advancing "fuzzing" - a predominant software vulnerability detection method - to address the unique challenges posed by software...
This Project Grant from the National Science Foundation's Division of Computing and Communication Foundations, under the Computer and Information Science and Engineering program (CFDA 47.070), provides $321,347 to Northwestern University to develop approaches combining crowd-reported and machine-generated data with program analysis to automate the reproduction of kernel vulnerabilities. Specifically, the university will create inference methods to determine kernel compilation configurations from...
The National Science Foundation awarded a $341k project grant to Northeastern University under the Social, Behavioral, and Economic Sciences program (CFDA 47.075) for research titled "Making Security Work: Vulnerability Disclosure Programs (VDPs) and the Organizational Foundations of Cybersecurity." The two-year project examines how organizations adopt and sustain vulnerability disclosure programs to crowdsource security work from independent researchers. Through qualitative and...
This Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) Federal Grant Program (CFDA 47.070) will fund a $1,200,000 project to develop practical, systematic fuzzing tools that enhance the security of scientific software. The 3-year project, led by the University of Utah, aims to address vulnerabilities in complex, multi-language scientific software by introducing (1) performant cross-language instrumentation, (2) automated...
The National Science Foundation (NSF) awarded a $330,000 Project Grant through its STEM Education (47.076) program to the University of Massachusetts Lowell. The grant supports the development of advanced teaching modules on software security, focusing on memory corruption attack and defense techniques for the Microsoft Windows operating system. Key objectives include: Innovating the Armitage open-source software vulnerability identification tool. Developing teaching content on Windows exploit...
This federal Project Grant award, valued at $353,258.00 and awarded by the National Science Foundation (NSF) under the Computer and Information Science and Engineering (CFDA 47.070) program, aims to develop new methods for reasoning about and evaluating security vulnerabilities in computer hardware and microarchitecture. The key objectives are to: Introduce a new programming interface for software to specify desired memory regions, and an abstract model to represent vulnerable microarchitectural...