ProSVED · Projection of Security Vulnerabilities caused by Exploits in Dependencies
„Хоризонт Европа“ — Действия „Мария Склодовска-Кюри“
- Период
- 2022-06-21 → 2024-06-20
- Финансиране от ЕС
- 172 750 €
- Участници
- 1
- Схема
- HORIZON-TMA-MSCA-PF-EF
Линиите свързват координатора с партньорите.
Накратко на български
Сигурността на софтуера се анализира чрез проследяване на уязвимостите, които идват от външни библиотеки и чужд код. Това помага за изборто на по-добри стратегии за обновяване на програмите, за да се намалят рисковете от кибератаки.
Кратко обяснение, генерирано от езиков модел по текста на CORDIS. Оригиналът е по-долу.
Резултати накратко
Projection of Security Vulnerabilities caused by Exploits in Dependencies
ProSVED (Projection of Security Vulnerabilities caused by Exploits in Dependencies) aims to forecast software vulnerabilities originating from security exploits in third-party libraries. In modern software projects, the code directly managed by developers, such as for security patches, represents only a small portion of the entire codebase. The majority resides in external dependencies, which pose significant security risks to the entire project. These risks can be mitigated through strategic update policies, but identifying optimal policies requires solving a complex prognosis problem: detecting the critical vulnerabilities hidden among vast amounts of third-party code. ProSVED introduces an innovative approach to address this challenge, facilitating the selection of the most effective update policies to minimize security risks from external code. This project advances the field of software security analysis beyond traditional empirical methods into the realm of formal risk modeling for prediction and mitigation. Estimating the quantity and severity of security vulnerabilities in code is crucial for software quality and control. While empirical methods are limited to detection, and traditional formal approaches rely on assumptions that don't hold in this context (such as the independence of codebases), Statistical Model Checking, though a relevant formal method, is often ineffective due to the rarity of significant events. ProSVED presents a new formalism to accurately model the propagation of vulnerabilities from third-party libraries to the main codebase. This enables the development of a risk analysis theory to assess and optimize software-update policies for different codebases, significantly enhancing the ability to predict and mitigate security vulnerabilities.
Текст от CORDIS, на английски · Данни: CORDIS, © Европейски съюз
Цел на проекта
ProSVED stands for Projection of Security Vulnerabilities caused by Exploits in Dependencies, and targets the prognosis of software vulnerabilities via security exploits in third-party libraries. The code controlled by developers, e.g. to add security patches, is a small fraction of the whole codebase that supports any software project today. Most lines of code reside in external dependencies whose security vulnerabilities pose threats to the entire project. This can be mitigated via strategic update policies. However, measuring the risks to find optimal policies constitutes a tremendous prognosis problem, to find the needle of offending lines that hide in a haystack of third-party libraries. ProSVED proposes a novel rare-event approach to the challenge, to estimate the most promising update policies in order to reduce the security risks inherited from external code. Working with experts from the University of Trento, ProSVED will thus push the frontiers of software security analysis, taking it beyond its classical empirical approach, and into the horizon of formal risk modelling for prediction and mitigation.
Оригинален текст от CORDIS (на английски).
Участници
- UNIVERSITA DEGLI STUDI DI TRENTO · TrentoКоординаторИталия
Връзки
- Виж в CORDIS
- DOI: 10.3030/101067199
- https://ec.europa.eu/research/participants/documents/downloadPublic?documentIds=080166e50cb4fe91&appId=PPGMS
- https://ec.europa.eu/research/participants/documents/downloadPublic?documentIds=080166e5f43d4487&appId=PPGMS
Данни: CORDIS, © Европейски съюз
