Resilient and Sustainable Software Security

The RS³ project aims to enhance software security by developing resilient and sustainable countermeasures through innovative testing, secure compilers, attack mitigation, and hardware improvements.

Subsidie
€ 1.998.851
2023

Projectdetails

Introduction

In parallel with the ongoing digitization, computer security has become an increasingly important and urgent challenge. In particular, the sound and robust implementation of complex software systems is still not well understood in practice, as evidenced by the steady stream of successful attacks observed in the wild. The current state of the art in software security consists of solutions that are often technically sound, but do not provide operational security in practice.

Project Overview

With the Resilient and Sustainable Software Security (RS³) project, we propose a compelling research agenda to fundamentally change this situation by developing novel countermeasures at different system levels that fundamentally improve security.

Key Objectives

On the one hand, the system must be "resilient" against entire classes of attack vectors. On the other hand, the system must be "sustainable", i.e., it must be able to maintain its security at least over its design lifetime and possibly even adapt over time.

Work Plan

Our work plan addresses the problem from four different angles by:

  1. Developing novel software testing strategies that enable accurate and efficient vulnerability discovery.
  2. Designing secure compiler chains that embed security properties during the compilation phase that can be enforced at runtime.
  3. Devising robust mechanisms that mitigate and patch advanced attacks.
  4. Investigating how hardware changes for open-source hardware (e.g., RISC-V processors) can improve the efficiency and accuracy of all of these goals.

Expected Outcomes

We expect to develop innovative methods and fundamental principles to build, test, and patch complex systems securely and efficiently. This holistic approach covers multiple layers of the computing stack, and each aspect has the potential to improve security significantly.

Success Criteria

The main success criterion will be our ability to perform a security analysis of a complex system an order of magnitude more effectively and efficiently than with current state-of-the-art methods.

Financiële details & Tijdlijn

Financiële details

Subsidiebedrag€ 1.998.851
Totale projectbegroting€ 1.998.851

Tijdlijn

Startdatum1-1-2023
Einddatum31-12-2027
Subsidiejaar2023

Partners & Locaties

Projectpartners

  • CISPA - HELMHOLTZ-ZENTRUM FUR INFORMATIONSSICHERHEIT GGMBHpenvoerder

Land(en)

Germany

Vergelijkbare projecten binnen European Research Council

ERC Advanced...

Hardware-assisted Adaptive Cross-Layer Security for Computing Systems

HYDRANOS aims to revolutionize computing security by designing adaptable hardware within SoCs for post-fabrication reconfiguration to combat emerging cross-layer attacks.

€ 2.485.281
ERC Starting...

Foundations for Sustainable Security

The FSSec project aims to enhance energy efficiency in IT systems by integrating cryptography-grade security into all layers, targeting a 20% efficiency increase while minimizing vulnerabilities.

€ 1.498.489
ERC Starting...

SecuStack: Securing the Leaky Hardware/Software Boundary

SecuStack aims to eliminate side-channel leaks by developing precise hardware-level leakage models to create provably secure systems, enhancing data protection against emerging attacks.

€ 1.500.000
ERC Proof of...

Realizing the benefits of safety-security co-analysis through effective tool support

RUBICON aims to develop a proof-of-concept software tool for integrated safety-security risk analysis in technology, enhancing decision-making through advanced algorithms and multi-objective optimization.

€ 150.000
ERC Consolid...

Decentralized Cryptographic Systems

This project aims to develop robust cryptographic systems that align theoretical models with real-world challenges, enhancing security and efficiency for decentralized infrastructures.

€ 1.998.351

Vergelijkbare projecten uit andere regelingen

Mkb-innovati...

Integrated Safety for Deeply Embedded Systems Software (ISAFE)

Het ISAFE-project ontwikkelt een geïntegreerde aanpak voor de kwalificatie van softwaretools in veiligheid kritische systemen, gericht op het voldoen aan veiligheidsstandaarden en het verbeteren van softwareontwikkeling.

€ 160.200
Mkb-innovati...

Secure software co-design

Het project onderzoekt veilige software co-development binnen het Reach platform door risicoprofielen op te stellen en mitigatiemogelijkheden voor gebruikersgegevens en malware te identificeren.

€ 20.000
Mkb-innovati...

SecuriPi

SecuriPi ontwikkelt een geavanceerd multi-factor authenticatiesysteem om digitale weerbaarheid tegen cyberdreigingen te versterken.

€ 20.000
EIC Accelerator

Protecting modern open-source web applications

The project aims to enhance website security by integrating independent security researchers with automated virtual patching technology to protect against open-source code vulnerabilities.

€ 1.904.000
EIC Accelerator

REVOLUTIONISING INDUSTRIAL ROBOTICS WITH THE NEXT GENERATION ROBOT-SPECIFIC AI-POWERED SECURITY PLATFORM

RIS is an innovative AI-based Endpoint Protection Platform designed to secure industrial robots by detecting vulnerabilities and protecting against known and unknown threats.

€ 2.499.875