Project Grant 2154199
- This National Science Foundation Project Grant of $349,276 supports research at Worcester Polytechnic Institute to develop innovative machine learning and natural language processing techniques for automated analysis of documentation related to networked systems security. Funded under the NSF's Computer and Information Science and Engineering program (CFDA 47.070), the project aims to leverage documentation sources like specifications, developer guides, and other materials to discover security...
- This two-year, $174,900 project grant from the National Science Foundation's Division of Computer and Network Systems will fund research at DePaul University towards developing more accurate vulnerability detection and less disruptive vulnerability mitigation techniques. The goal is to address challenges in reliably finding software vulnerabilities and patching them without compromising system availability. Researchers will design a scheme for encoding intrinsic vulnerability characteristics...
- This Project Grant award of $387,341 from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program (CFDA 47.070) supports research to extend auto-active verification techniques to enable the verification of security and privacy properties, known as hyperproperties, for software systems. The key objectives of the three-year project are to: 1) develop new deductive logics and algebras to support automated reasoning about relationships between...
- The National Science Foundation awarded $349,079 under its Computer and Information Science and Engineering program (CFDA 47.070) to Stony Brook University for a collaborative research project titled "COLLABORATIVE RESEARCH: SATC: CORE: MEDIUM: APP-DRIVEN WEB BROWSING: NOVEL RISKS, VULNERABILITIES, AND DEFENSES." The project, taking place from October 1, 2022 to September 30, 2026, will analyze security risks inherent in non-browser applications that enable web browsing. Researchers...
- This $265,948 federal Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program supports research to improve the reliability and scientific integrity of threat modeling experiments in software security. The project aims to develop best practices for conducting human-centered threat modeling studies, which are essential for ensuring software is secure. Key research activities include qualitative investigations of current...
- This three-year, $244,997 Project Grant from the National Science Foundation's Computer and Information Science and Engineering program aims to develop scalable methods for analyzing large-scale network traffic data to quantify internet-of-things (IoT) device insecurities and characterize malicious IoT campaigns. The awardee, San Diego State University Research Foundation, will work with collaborators to design algorithms and formal methods using supervised deep learning to fingerprint exploited...
- This $102,471 Project Grant awarded by the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program (CFDA 47.070) will support the development of a general query framework to enhance cyber attack investigation using system audit logs. The key products and services to be delivered under this grant include: Building an infrastructure to compute discriminative weights for dependencies and identify attack-relevant events and entry points from system audit...
- This Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program (CFDA 47.070) supports the development of a learner-centered artificial intelligence (AI) co-pilot tool to crowd-source the curation of comprehensive cybersecurity attack artifacts. The $299,999 award to the Rochester Institute of Technology (RIT) aims to leverage large language models and techniques like prompt engineering to guide users in emulating end-to-end...
- This Project Grant from the National Science Foundation's Division of Computing and Communication Foundations, under the Computer and Information Science and Engineering program (CFDA 47.070), provides $321,347 to Northwestern University to develop approaches combining crowd-reported and machine-generated data with program analysis to automate the reproduction of kernel vulnerabilities. Specifically, the university will create inference methods to determine kernel compilation configurations from...
- The National Science Foundation awarded a $341k project grant to Northeastern University under the Social, Behavioral, and Economic Sciences program (CFDA 47.075) for research titled "Making Security Work: Vulnerability Disclosure Programs (VDPs) and the Organizational Foundations of Cybersecurity." The two-year project examines how organizations adopt and sustain vulnerability disclosure programs to crowdsource security work from independent researchers. Through qualitative and...
COLLABORATIVE RESEARCH: SATC: CORE: MEDIUM: AUDACITY OF EXPLORATION: TOWARD AUTOMATED DISCOVERY OF SECURITY FLAWS IN NETWORKED SYSTEMS THROUGH INTELLIGENT DOCUMENTATION ANALYSIS -SPECIFICATIONS, DEVELOPER GUIDES AND OTHER DOCUMENTATIONS OF NETWORKED SYSTEMS (E.G., INTERNET APPLICATIONS, CARRIER NETWORKS) DESCRIBE HOW THESE SYSTEMS ARE DESIGNED, USED AND OPERATE. THESE DOCUMENTATIONS ARE IMPORTANT SOURCES FOR UNDERSTANDING SECURITY WEAKNESSES IN THESE SYSTEMS AND HAVE NOT BEEN FULLY LEVERAGED DUE TO THE DIFFICULTY IN ANALYZING THEIR IMPRECISE, CONVOLUTED AND AMBIGUOUS CONTENT. PROJECT AUDACITY (AUTOMATED DOCUMENTATION ANALYSIS FOR SECURITY) AIMS AT ADDRESSING THE CHALLENGE FOR SECURITY WEAKNESS DISCOVERY AND REMEDY. ITS NOVELTIES ARE THE DEVELOPMENT OF INNOVATIVE TECHNOLOGIES TO ENABLE AUTOMATED DOCUMENT ANALYSIS FOR SECURITY PROTECTION. THE PROJECT?S BROADER SIGNIFICANCE AND IMPORTANCE INCLUDE TRANSFERRING THE TECHNOLOGIES TO INDUSTRY, INVOLVING MEMBERS FROM UNDER-REPRESENTED GROUPS IN THE PROJECT AND DISSEMINATING OUTCOMES THROUGH K9-12 OUTREACH AND COMMUNITY SERVICES. THE PROJECT FOCUSES ON MITIGATING SECURITY RISKS OF BOTH DESIGN FLAWS AND IMPLEMENTATION VULNERABILITIES IN NETWORKED SYSTEMS, THROUGH AUTOMATICALLY RECOVERING SECURITY-RELATED INFORMATION (E.G., MODELS, SECURITY PROPERTIES) AND CONFUSING DESCRIPTIONS (E.G., INCONSISTENT STATEMENTS) FROM DOCUMENTATIONS TO EVALUATE THEIR SECURITY IMPLICATIONS (E.G., VERIFICATION OF SYSTEM DESIGNS, VALIDATION OF PREDICTED WEAKNESSES ON SYSTEM IMPLEMENTATIONS). THIS PURPOSE IS SERVED BY NOVEL TECHNIQUES BASED UPON MACHINE LEARNING AND NATURAL LANGUAGE PROCESSING FOR ANALYZING DIFFERENT TYPES OF DOCUMENTATIONS, SUCH AS THOSE FOR PAYMENT, SINGLE-SIGN-ON, AND FOR THE 3RD GENERATION PARTNERSHIP PROJECT OR 3GPP. EXAMPLES OF SUCH TECHNIQUES INCLUDE SENTIMENT ANALYSIS FOR FINDING THE STATEMENTS RELATED TO SECURITY REQUIREMENTS AND A SIMILARITY AND DIFFERENTIAL ANALYSIS THAT COMPARES DIFFERENT STATEMENTS ABOUT SIMILAR SECURITY-CRITICAL OPERATIONS TO CAPTURE INCONSISTENCY. FURTHERMORE, THE PROJECT STUDIES EMERGING TECHNIQUES SUCH AS SERVICE SYNDICATION THROUGH COMPARING THE DOCUMENTATIONS OF DIFFERENT SERVICES AND THE 3GPP ECOSYSTEM FROM ANALYZING ITS PUBLIC TEXT DATA FOR RISK MEASUREMENT, IDENTIFICATION AND MITIGATION. THIS WORK COMPLEMENTS PROGRAM ANALYSIS TO HELP ENHANCE THE SECURITY QUALITY OF NETWORKED SYSTEMS, CONTRIBUTING TO A BETTER PROCEDURE AND ECOSYSTEM THAT MAKE SECURITY-CRITICAL DOCUMENTATIONS MORE PRECISE, MORE CONSISTENT AND LESS ERROR-PRONE. THIS AWARD REFLECTS NSF'S STATUTORY MISSION AND HAS BEEN DEEMED WORTHY OF SUPPORT THROUGH EVALUATION USING THE FOUNDATION'S INTELLECTUAL MERIT AND BROADER IMPACTS REVIEW CRITERIA.
Mod # | Description | ReasonForModification | Federal Obligation | Date |
|---|---|---|---|---|
| Not listed | $0 | 4/16/25 | ||
| Not listed | $550.0k | 4/22/22 |