Project Grant 2339350
- This Project Grant from the National Science Foundation Division of Computer and Network Systems, under the Computer and Information Science and Engineering federal grant program (CFDA 47.070), provides $517,545 in funding to the University of Utah from January 1, 2022 to September 30, 2024. The award supports research to advance software vulnerability detection techniques. Specifically, the university researchers will develop new approaches to fuzz testing, a method for identifying software...
- This Project Grant award from the National Science Foundation's (NSF) Computer and Information Science and Engineering (CISE) Federal Grant Program (CFDA 47.070) will fund a $1,200,000 project to develop practical, systematic fuzzing tools that enhance the security of scientific software. The 3-year project, led by the University of Utah, aims to address vulnerabilities in complex, multi-language scientific software by introducing (1) performant cross-language instrumentation, (2) automated...
- This two-year, $174,900 project grant from the National Science Foundation's Division of Computer and Network Systems will fund research at DePaul University towards developing more accurate vulnerability detection and less disruptive vulnerability mitigation techniques. The goal is to address challenges in reliably finding software vulnerabilities and patching them without compromising system availability. Researchers will design a scheme for encoding intrinsic vulnerability characteristics...
- The University of Utah received a $220,500 Project Grant award from the National Science Foundation (NSF) under the Computer and Information Science and Engineering (CISE) program (CFDA 47.070). This 5-year award, beginning March 1, 2024, supports research to develop scalable security testing techniques for large software systems. The project focuses on advancing "fuzzing" - a predominant software vulnerability detection method - to address the unique challenges posed by software...
- This Project Grant from the National Science Foundation's Division of Computing and Communication Foundations, under the Computer and Information Science and Engineering program (CFDA 47.070), provides $321,347 to Northwestern University to develop approaches combining crowd-reported and machine-generated data with program analysis to automate the reproduction of kernel vulnerabilities. Specifically, the university will create inference methods to determine kernel compilation configurations from...
- This Project Grant award, provided by the National Science Foundation (NSF) under the Computer and Information Science and Engineering (CFDA 47.070) program, supports research to enhance the scalability and automation of binary symbolic execution, a critical technique for detecting software vulnerabilities. The project, titled "CAREER: Achieving Autonomous Symbolic Execution through Learning from Humans - Vulnerability Discovery for Software Security," will develop an automated...
- This $500,000 project grant from the National Science Foundation's Computer and Information Science and Engineering program aims to develop new techniques for software vulnerability discovery. Specifically, the University of California, Riverside will receive funding from February 2022 through January 2025 to create a fast binary code concolic execution engine and dual concolic execution approach that combines source code and binary code analysis. These new methods seek to significantly...
- This National Science Foundation Project Grant of $349,276 supports research at Worcester Polytechnic Institute to develop innovative machine learning and natural language processing techniques for automated analysis of documentation related to networked systems security. Funded under the NSF's Computer and Information Science and Engineering program (CFDA 47.070), the project aims to leverage documentation sources like specifications, developer guides, and other materials to discover security...
- The National Science Foundation Division of Computer and Network Systems awarded a $500,000 Project Grant to The Johns Hopkins University to study and measure the consequences of prototype pollution vulnerabilities automatically via joint taintflow analysis. This award falls under the Computer and Information Science and Engineering program (CFDA 47.070), which supports research and education in all areas of computing, communications, and information science and engineering. Specifically, the...
- Virginia Polytechnic Institute & State University (Virginia Tech) was awarded a $323,982 project grant from the National Science Foundation (NSF) under the Computer and Information Science and Engineering program. The grant will fund a collaborative research project titled "Reinventing Fuzz Testing for Data and Compute Intensive Systems" from October 1, 2021 to September 30, 2025. The research aims to advance the development of fuzz testing techniques for data-intensive and...
CAREER: CONTEXT-SENSITIVE FUZZING FOR NETWORKED SYSTEMS -INTERNET-FACING SECURITY-CRITICAL NETWORK PROTOCOLS ARE SUSCEPTIBLE TO EXPLOITATION BY REMOTE ADVERSARIES SEEKING TO COMPROMISE OVERALL SECURITY. THESE ADVERSARIES EMPLOY CRAFTED INPUTS TO EXPLOIT UNDISCLOSED OR UNPATCHED SECURITY FLAWS (BUGS) IN PROTOCOL IMPLEMENTATIONS. DESPITE THE COMMON STRATEGY OF BUG IDENTIFICATION AND PATCHING, UNEARTHING ELUSIVE BUGS IN PROTOCOL IMPLEMENTATIONS REMAINS CHALLENGING AS IT REQUIRES NAVIGATING STRINGENT INPUT VALIDATION TO DISCOVER BUGS THAT LURK DEEP IN THE CODE. FUZZING, ENDORSED BY THE NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST), AUTOMATES SECURITY TESTING BY PASSING ABNORMAL INPUTS TO PROGRAMS IN ORDER TO DISCOVER BUGS. WHILE FUZZING HAS EFFECTIVELY UNCOVERED BUGS IN MANY REAL-WORLD SYSTEMS, IT STILL STRUGGLES TO GENERATE SEMANTICALLY CORRECT INPUTS ESSENTIAL FOR TESTING BEYOND INITIAL INPUT VALIDATION. THIS PROJECT BRIDGES THIS GAP IN TRADITIONAL FUZZING BY DEVELOPING AN INNOVATIVE AUTOMATED SOLUTION THAT EFFECTIVELY ENHANCES THE TESTING OF PROTOCOL IMPLEMENTATIONS. THE CORE OBJECTIVE OF THIS PROJECT IS TO DEVELOP AN AUTOMATED, CONTEXT-SENSITIVE FUZZING APPROACH THAT EFFECTIVELY UNCOVERS BUGS IN SECURITY-CRITICAL PROTOCOL IMPLEMENTATIONS. THIS PROJECT REALIZES ITS OBJECTIVE THROUGH ACTIVITIES ACROSS THREE COMPLEMENTARY RESEARCH THRUSTS. THE FIRST THRUST DESIGNS A DOMAIN SPECIFIC LANGUAGE TO ENCODE CONTEXT-SENSITIVE HIERARCHICAL STRUCTURES OF INPUTS AND DEVELOPS ALGORITHMS TO EFFICIENTLY GENERATE SEMANTICALLY CORRECT INPUTS. THE SECOND THRUST DEVISES SEVERAL MUTATION TECHNIQUES, ESSENTIAL FOR FUZZING, THAT WILL MAINTAIN THE CONTEXT-SENSITIVITY OF THE INPUT. THE THIRD THRUST DEVELOPS MECHANISMS TO FAITHFULLY MAINTAIN THE INTERNAL STATE OF A STATEFUL PROTOCOL SO THAT EACH FUZZ INPUT CAN BE TESTED IN A SUITABLE STATE OF THE PROTOCOL. THIS PROJECT HAS THE POTENTIAL TO SIGNIFICANTLY ENHANCE THE ROBUSTNESS OF PROTOCOL IMPLEMENTATIONS, BENEFITING SOCIETY. THIS PROJECT'S EDUCATION COMPONENT INCLUDES ORGANIZING CAPTURE-THE-FLAG (CTF) COMPETITIONS, IMPROVING CYBERSECURITY COURSES, AND CONDUCTING K-12 WORKSHOPS TO RAISE CYBERSECURITY AWARENESS. UNDERGRADUATE AND GRADUATE STUDENTS FROM HISTORICALLY MARGINALIZED COMMUNITIES WILL BE RECRUITED TO INCREASE THEIR PARTICIPATION IN RESEARCH AND EDUCATIONAL ACTIVITIES. THIS AWARD REFLECTS NSF'S STATUTORY MISSION AND HAS BEEN DEEMED WORTHY OF SUPPORT THROUGH EVALUATION USING THE FOUNDATION'S INTELLECTUAL MERIT AND BROADER IMPACTS REVIEW CRITERIA.- SUBAWARDS ARE NOT PLANNED FOR THIS AWARD.
Mod # | Description | ReasonForModification | Federal Obligation | Date |
|---|---|---|---|---|
| Not listed | $221.1k | 9/15/25 | ||
| Not listed | $105.2k | 5/7/25 | ||
| Not listed | $98.8k | 3/29/24 |