Skip to main content

Assurance and certification in secure Multi-party Open Software and Services.

Objective

Continuous, distributed changes rule today's European Digital Single Market as no single company does master its own national, in-house software. Software is mostly assembled from “the internet” and more than half come from Open Source Software repositories (some in Europe, most elsewhere). Security & privacy assurance, verification and process certification techniques designed for large, controlled updates over months or years, must now cope with small, continuous changes in weeks, happening in sub-components and decided by third party developers one did not even know they existed.
AssureMOSS addresses these challenges to the fullest extent: « Open Source Software - Designed Everywhere, Secured in Europe ».
AssureMOSS proposes to switch from process-based to an artefact-based security evaluation by supporting all phases of the continuous software lifecycle (Design, Develop, Deploy, Evaluate and back) their artefacts (Models, Source code, Container images, Services). The key idea is to support mechanisms for lightweigth and scalable screenings applicable automatically to the entire population of software components by
- Machine intelligent identification of security issues across artifacts,
- Sound analysis and verification of changes by tracing the security and privay side effects,
- Business insight by risk analysis and security evaluation.
This approach supports fast-paced development of better software by a new notion: continuous (re)certification.
AssureMOSS has assembled a team including 5 leading Universities (Delft, Gotheborg, Trento, Vienna, VU Amsterdam), 3 innovative SMEs (FrontEndART, Search-Lab, Pluribus One), 3 Large Enterprises (E&Y, SAP, Thales) and 1 Special Interest Group Organization (EU-VRi) and an Advisory Board with key figures from OSS and industry at large.
The project will generate not only a set of innovative methods and open source tools but also benchmark datasets with thousands of vulnerabilities and code that can be used by other researchers.

Field of science

  • /natural sciences/computer and information sciences/software
  • /social sciences/sociology/governance/public services

Call for proposal

H2020-SU-ICT-2019
See other projects for this call

Funding Scheme

RIA - Research and Innovation action

Coordinator

UNIVERSITA DEGLI STUDI DI TRENTO
Address
Via Calepina 14
38122 Trento
Italy
Activity type
Higher or Secondary Education Establishments
EU contribution
€ 426 362,40

Participants (11)

SAP SE
Germany
EU contribution
€ 680 625
Address
Dietmar Hopp Allee 16
69190 Walldorf
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
GOETEBORGS UNIVERSITET
Sweden
EU contribution
€ 419 500
Address
Vasaparken
405 30 Goeteborg
Activity type
Higher or Secondary Education Establishments
EY ADVISORY SPA
Italy
EU contribution
€ 286 875
Address
Via Meravigli 14
20123 Milano
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
TECHNISCHE UNIVERSITEIT DELFT
Netherlands
EU contribution
€ 309 800
Address
Stevinweg 1
2628 CN Delft
Activity type
Higher or Secondary Education Establishments
THALES SIX GTS FRANCE SAS
France
EU contribution
€ 399 530
Address
Avenue Des Louvresses 4
92230 Gennevilliers
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
UNIVERSITAT WIEN
Austria
EU contribution
€ 334 095
Address
Universitatsring 1
1010 Wien
Activity type
Higher or Secondary Education Establishments
PLURIBUS ONE SRL
Italy
EU contribution
€ 306 250
Address
Via Vincenzo Bellini 9
09128 Cagliari
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
FRONTENDART SZOFTVER KFT
Hungary
EU contribution
€ 345 625
Address
Somogyi Utca 19
6720 Szeged
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
EUROPEAN VIRTUAL INSTITUTE FOR INTEGRATED RISK MANAGEMENT EU VRI EWIV
Germany
EU contribution
€ 448 125
Address
Fangelsbachstrasse 14
70178 Stuttgart
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
SEARCH-LAB BIZTONSAGI ERTEKELO ELEMZO ES KUTATO LABORATORIUM KORLATOLTFELELOSSEGU TARSASAG
Hungary
EU contribution
€ 446 250
Address
Szeruskert Utca 19 1 Em 6
1033 Budapest
Activity type
Private for-profit entities (excluding Higher or Secondary Education Establishments)
STICHTING VU
Netherlands
EU contribution
€ 286 387,60
Address
De Boelelaan 1105
1081 HV Amsterdam
Activity type
Higher or Secondary Education Establishments