Projection of Security Vulnerabilities caused by Exploits in Dependencies
ProSVED stands for Projection of Security Vulnerabilities caused by Exploits in Dependencies, and targets the prognosis of software vulnerabilities via security exploits in third-party libraries. The code controlled by developers,...
ver más
¿Tienes un proyecto y buscas un partner? Gracias a nuestro motor inteligente podemos recomendarte los mejores socios y ponerte en contacto con ellos. Te lo explicamos en este video
Proyectos interesantes
Ghostbuster
A Principled Plan to Prevent Transient Execution Attacks
2M€
Cerrado
SHIELDS
Detecting known security vulnerabilities from within design...
4M€
Cerrado
REVEN-X1
REVEN X1 Automatic Vulnerability Detection in Binary
71K€
Cerrado
STANCE
A Source code analysis Toolbox for software security AssuraN...
6M€
Cerrado
NESSoS
Network of Excellence on Engineering Secure Future Internet...
5M€
Cerrado
SCR
Disruptive Cybersecurity SaaS for SMEs and freelance develop...
71K€
Cerrado
Información proyecto ProSVED
Duración del proyecto: 23 meses
Fecha Inicio: 2022-06-21
Fecha Fin: 2024-06-20
Fecha límite de participación
Sin fecha límite de participación.
Descripción del proyecto
ProSVED stands for Projection of Security Vulnerabilities caused by Exploits in Dependencies, and targets the prognosis of software vulnerabilities via security exploits in third-party libraries. The code controlled by developers, e.g. to add security patches, is a small fraction of the whole codebase that supports any software project today. Most lines of code reside in external dependencies whose security vulnerabilities pose threats to the entire project. This can be mitigated via strategic update policies. However, measuring the risks to find optimal policies constitutes a tremendous prognosis problem, to find the needle of offending lines that hide in a haystack of third-party libraries. ProSVED proposes a novel rare-event approach to the challenge, to estimate the most promising update policies in order to reduce the security risks inherited from external code. Working with experts from the University of Trento, ProSVED will thus push the frontiers of software security analysis, taking it beyond its classical empirical approach, and into the horizon of formal risk modelling for prediction and mitigation.