Project Grant 2155213

Award Date 7/1/22
Completion Date 6/30/25
Dollars Obligated $250K
Federal Grant Program
47.070
Assistance Type
Project Grant
Place of Performance
Riverside, CA 92521, USA
Similar Awards
This three-year, $250,000 project grant from the National Science Foundation's Computer and Information Science and Engineering program aims to improve open-source operating system kernel security through automated analyses. The Regents of the University of Minnesota will develop techniques to reason about patches, bug behaviors, and their impacts across decentralized kernel ecosystems. Specifically, the awardee will analyze upstream patches to identify those fixing critical issues,...
This Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program will develop a comprehensive methodology for generating, deploying, and verifying software patches, particularly in scenarios where the original software source code is unavailable. The $311,482 award, effective from April 1, 2025 to March 31, 2030, will focus on advancing differential binary analysis techniques to assess the security improvements and potential...
This Project Grant from the National Science Foundation's Division of Computing and Communication Foundations, under the Computer and Information Science and Engineering program (CFDA 47.070), provides $321,347 to Northwestern University to develop approaches combining crowd-reported and machine-generated data with program analysis to automate the reproduction of kernel vulnerabilities. Specifically, the university will create inference methods to determine kernel compilation configurations from...
This $500,000 project grant from the National Science Foundation's Computer and Information Science and Engineering program aims to develop new techniques for software vulnerability discovery. Specifically, the University of California, Riverside will receive funding from February 2022 through January 2025 to create a fast binary code concolic execution engine and dual concolic execution approach that combines source code and binary code analysis. These new methods seek to significantly...
This $450,000 Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) program will support research at the University of California, Riverside (UC Riverside) to explore how large language models (LLMs) can assist with program analysis. The project aims to investigate strategies for integrating LLMs with existing software analysis tools to improve their accuracy and scalability in detecting bugs and vulnerabilities in complex...
This $150,000 Project Grant was awarded by the National Science Foundation (NSF) under the Computer and Information Science and Engineering (CFDA 47.070) federal grant program. The goal of the project is to develop new automated techniques to formally verify the correctness of the abstract interpretation algorithms used in the Extended Berkeley Packet Filter (eBPF) verifier within the Linux kernel. This work aims to enhance the security and reliability of the widely deployed eBPF software and...
This two-year, $174,900 project grant from the National Science Foundation's Division of Computer and Network Systems will fund research at DePaul University towards developing more accurate vulnerability detection and less disruptive vulnerability mitigation techniques. The goal is to address challenges in reliably finding software vulnerabilities and patching them without compromising system availability. Researchers will design a scheme for encoding intrinsic vulnerability characteristics...
The National Science Foundation (NSF) awarded the Regents of the University of Michigan a $541,887 Project Grant under the Computer and Information Science and Engineering (CFDA 47.070) program. The award, with a performance period of August 2023 to September 2024, aims to develop an architecture for lightweight data collection in the operating system kernel and use machine learning to discover and deploy improved kernel policies without compromising security. The project, titled...
The National Science Foundation awarded a $900,000 project grant to the University of California, San Diego to develop foundations, techniques, and frameworks for building end-to-end verified secure sandboxed systems from May 2022 through April 2026. This award falls under the Computer and Information Science and Engineering program (CFDA 47.070), which supports investigator-initiated research and education in computing, communications, and information science and engineering. Specifically,...
The National Science Foundation awarded a $1.167 million project grant to Columbia University from March 2021 to February 2025 under the Computer and Information Science and Engineering program (CFDA 47.070). The grant funds research to microverify the information-flow security of the Linux operating system kernel. The Computer and Information Science and Engineering program supports investigator-initiated research and education across computing, communications, and information science and...

This Project Grant from the National Science Foundation's Computer and Information Science and Engineering program will fund $250,000 to develop automated analyses that improve the security of open-source operating system kernels. The Regents of the University of California at Riverside will receive the award to conduct research from July 1, 2022 to June 30, 2025.

A large number of downstream operating system kernels are derived from upstream kernels like Linux to reduce development costs. However, this means downstream security relies on timely patch propagation from upstream. The diversity and decentralized nature of downstream kernels causes delays or missed upstream patches. Even if a vulnerability exists in a downstream and a patch is available, additional work is often required to port and test upstream patches.

This project aims to develop analyses that reason about patches, bug behaviors, and impacts. Specifically, it will analyze upstream patches to identify critical bug fixes, infer which downstream kernels are affected by an upstream bug and the security impact, and determine if corresponding upstream patches can be safely and correctly applied. The results are intended to alleviate human burden in reviewing and adopting patches, ultimately improving security across the entire open-source operating system ecosystem.

Generated 1/6/24, 5:37 PM