Federal grant · project grant (b)
Career: Context-sensitive Fuzzing for Networked Systems -internet-facing Security-critical Network Protocols Are Susceptible to Exploitation by Remote Adversaries Seeking to Compromise Overall Security. These Adversaries Employ Crafted Inputs to Exploit Undisclosed or Unpatched Security Flaws (BUGS) in Protocol Implementations. Despite the Common Strategy of Bug Identification and Patching, Unearthing Elusive Bugs in Protocol Implementations Remains Challenging as It Requires Navigating Stringent Input Validation to Discover Bugs That Lurk Deep in the Code. Fuzzing, Endorsed by the National Institute of Standards and Technology (nist), Automates Security Testing by Passing Abnormal Inputs to Programs in Order to Discover Bugs. While Fuzzing Has Effectively Uncovered Bugs in Many Real-world Systems, It Still Struggles to Generate Semantically Correct Inputs Essential for Testing Beyond Initial Input Validation. This Project Bridges This Gap in Traditional Fuzzing by Developing an Innovative Automated Solution That Effectively Enhances the Testing of Protocol Implementations. the Core Objective of This Project Is to Develop an Automated, Context-sensitive Fuzzing Approach That Effectively Uncovers Bugs in Security-critical Protocol Implementations. This Project Realizes Its Objective Through Activities Across Three Complementary Research Thrusts. the First Thrust Designs a Domain Specific Language to Encode Context-sensitive Hierarchical Structures of Inputs and Develops Algorithms to Efficiently Generate Semantically Correct Inputs. the Second Thrust Devises Several Mutation Techniques, Essential for Fuzzing, That Will Maintain the Context-sensitivity of the Input. the Third Thrust Develops Mechanisms to Faithfully Maintain the Internal State of a Stateful Protocol So That Each Fuzz Input Can Be Tested in a Suitable State of the Protocol. This Project Has the Potential to Significantly Enhance the Robustness of Protocol Implementations, Benefiting Society. This Project's Education Component Includes Organizing Capture-the-flag (CTF) Competitions, Improving Cybersecurity Courses, and Conducting K-12 Workshops to Raise Cybersecurity Awareness. Undergraduate and Graduate Students From Historically Marginalized Communities Will Be Recruited to Increase Their Participation in Research and Educational Activities. This Award Reflects NSF'S Statutory Mission and Has Been Deemed Worthy of Support Through Evaluation Using the Foundation's Intellectual Merit and Broader Impacts Review Criteria.- Subawards Are Not Planned for This Award.
Committed
$425,140
Paid out
$90.0K
21%
Committed, not yet paid
$335.2K
79%
Loading…
Everything here is this single award's whole record — signed, amended, paid — not a fiscal-year slice. The by-year charts elsewhere split an award across the years it was committed; this page keeps it whole.
Committed is what the government has legally promised on this award so far. Contracts can also carry a ceiling — the maximum if every option is exercised. Unspent ceiling is headroom, not money owed.
The cash actually disbursed against this award. The gap from committed is the disbursement pipeline: promised, not yet cashed.
Each transaction is a signing event — an action that created or changed the award, dated the day it was signed — not a payment. Negative amounts are real: money de-committed at closeout or renegotiation.
One bar, the award’s whole arithmetic: paid out, then committed, not yet paid, then unspent ceiling.