CAREER: Rethinking Mobile Security in the New Age of App-As-A-Platform
职业:重新思考应用程序即平台新时代的移动安全
基本信息
- 批准号:1748334
- 负责人:
- 金额:$ 50.05万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2017
- 资助国家:美国
- 起止时间:2017-08-01 至 2023-04-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
An ongoing evolution in the design of mobile applications (apps) and services, called "app-as-a-platform", is posing fundamental challenges to mobile security and privacy, exposing consumers, enterprises, and governments to new threats. Existing security technologies were not designed to address apps' emerging role as micro-platforms and are, therefore, incapable of providing sufficient protections. This research project is developing security foundations in three dimensions of app-as-a-platform architectures: (1) In-app Dimension, where modules within the same app can adversely affect or manipulate one another, (2) App-cloud Dimension, where apps may spy on or abuse integrated cloud services, and vice versa, and (3) App-IoT Dimension, where unauthorized apps can manipulate IoT (Internet-of-Things)-connected devices. This research project is investigating approaches to safeguard mobile apps' integration with third-party modules, cloud services, and IoT devices that are organized by app-as-a-platform architectures. The project is developing security foundations for these architectures by retrofitting mobile middleware and operating systems (OS) with new isolation, mediation, and attestation primitives and mechanisms. To establish a principled defense against threats to app-as-a-platform systems, the researchers are designing new OS abstractions for in-process memory isolation, language constructs for module-level security enforcement, trustworthy web integration mechanisms, remote attestation of mobile agents, and an IoT authorization and interoperation framework. The project also provides unique education and training opportunities for both graduate and undergraduate students.
移动应用程序(应用程序)和服务的持续发展,称为“ App-a-a-platform”,对移动安全和隐私提出了根本性的挑战,使消费者,企业和政府面临新威胁。现有的安全技术并非旨在解决应用程序作为微平台的新兴角色,因此无法提供足够的保护。 This research project is developing security foundations in three dimensions of app-as-a-platform architectures: (1) In-app Dimension, where modules within the same app can adversely affect or manipulate one another, (2) App-cloud Dimension, where apps may spy on or abuse integrated cloud services, and vice versa, and (3) App-IoT Dimension, where unauthorized apps can manipulate IoT (THIONTENT)连接的设备。该研究项目正在研究通过APS-A-A-A-A-Platform Architectures组织的第三方模块,云服务和IoT设备的整合方法。该项目通过使用新的隔离,中介和证明原始及机制来改造移动中间件和操作系统(OS),为这些体系结构开发安全基础。为了制定针对对应用程序的平台系统威胁的原则防御,研究人员正在设计新的OS摘要,用于过程中的内存隔离,用于模块级安全执行的语言构造,可信赖的Web集成机制,移动代理的远程证明以及IOT授权和Intherization和Interoperation框架。该项目还为研究生和本科生提供了独特的教育和培训机会。
项目成果
期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface Modeling
P2IM:通过自动外设接口建模进行可扩展且独立于硬件的固件测试
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Feng, Bo;Mera, Alejandro;Lu, Long
- 通讯作者:Lu, Long
OAT: Attesting Operation Integrity of Embedded Devices
- DOI:10.1109/sp40000.2020.00042
- 发表时间:2018-02
- 期刊:
- 影响因子:0
- 作者:Zhichuang Sun;Bo Feng;Long Lu;S. Jha
- 通讯作者:Zhichuang Sun;Bo Feng;Long Lu;S. Jha
SoK: Attacks on Industrial Control Logic and Formal Verification-Based Defenses
- DOI:10.1109/eurosp51992.2021.00034
- 发表时间:2020-06
- 期刊:
- 影响因子:0
- 作者:Ruimin Sun;Alejandro Mera;Long Lu;D. Choffnes
- 通讯作者:Ruimin Sun;Alejandro Mera;Long Lu;D. Choffnes
Secure Integration of Web Content and Applications on Commodity Mobile Operating Systems
- DOI:10.1145/3052973.3052998
- 发表时间:2017-04
- 期刊:
- 影响因子:0
- 作者:Drew Davidson;Yaohui Chen;F. George;Long Lu;S. Jha
- 通讯作者:Drew Davidson;Yaohui Chen;F. George;Long Lu;S. Jha
D-Box: DMA-enabled Compartmentalization for Embedded Applications
- DOI:10.14722/ndss.2022.24053
- 发表时间:2022-01
- 期刊:
- 影响因子:0
- 作者:Alejandro Mera;Yi Hui Chen;Ruimin Sun;E. Kirda;Long Lu
- 通讯作者:Alejandro Mera;Yi Hui Chen;Ruimin Sun;E. Kirda;Long Lu
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Long Lu其他文献
Effects of discharge power on the structural and optical properties of TGZO thin films prepared by RF magnetron sputtering technique
放电功率对射频磁控溅射TGZO薄膜结构和光学性能的影响
- DOI:
10.1007/s11801-016-5265-5 - 发表时间:
2016-05 - 期刊:
- 影响因子:0.9
- 作者:
Gu Jin-hua;Lu Zhou;Zhong Zhiyou;Long Lu;Long Hao - 通讯作者:
Long Hao
Nanosized V-Ce Oxides Supported on TiO2 as a Superior Catalyst for the Selective Catalytic Reduction of NO
TiO2 负载的纳米 V-Ce 氧化物作为选择性催化还原 NO 的优异催化剂
- DOI:
10.3390/catal10020202 - 发表时间:
2020-02 - 期刊:
- 影响因子:3.9
- 作者:
Long Lu;Xueman Wang;Chunhua Hu;Ying Liu;Xiongbo Chen;Ping Fang;Dingsheng Chen;Chaoping Cen - 通讯作者:
Chaoping Cen
SCRUTINIZER: Detecting Code Reuse in Malware via Decompilation and Machine Learning
SCRUTINIZER:通过反编译和机器学习检测恶意软件中的代码重用
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
Omid Mirzaei;Roman Vasilenko;E. Kirda;Long Lu;Amin Kharraz - 通讯作者:
Amin Kharraz
Atmospheric emission inventory of cadmium from anthropogenic sources. (SCI, IF=3.157(2011))
人为源镉的大气排放清单。
- DOI:
- 发表时间:
- 期刊:
- 影响因子:3.1
- 作者:
Ke Cheng;Hezhong Tian;Dan Zhao;Long Lu;Yan Wang;Jing Chen;Xingang Liu;Wenxiao Jia;Zhe Huang - 通讯作者:
Zhe Huang
Synthesis and Reactivity of a-Cumyl Bromodifluoromethanesulfenate: Application to the Radiosynthesis of [18F]ArylSCF3
α-溴二氟甲磺酸枯基酯的合成和反应性:在 [18F]ArylSCF3 放射合成中的应用
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Jiang Wu;Qunchao Zhao;Thomas C. Wilson;Stefan Verhoog;Long Lu;Veronique Gouverneur;Qilong Shen - 通讯作者:
Qilong Shen
Long Lu的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Long Lu', 18)}}的其他基金
CAREER: Rethinking Mobile Security in the New Age of App-As-A-Platform
职业:重新思考应用程序即平台新时代的移动安全
- 批准号:
1652205 - 财政年份:2017
- 资助金额:
$ 50.05万 - 项目类别:
Continuing Grant
TWC: Small: STRUCT: Enabling Secure and Trustworthy Compartments in Mobile Applications
TWC:小:STRUCT:在移动应用程序中启用安全且值得信赖的部分
- 批准号:
1800665 - 财政年份:2017
- 资助金额:
$ 50.05万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 50.05万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1514142 - 财政年份:2015
- 资助金额:
$ 50.05万 - 项目类别:
Standard Grant
TWC: Small: STRUCT: Enabling Secure and Trustworthy Compartments in Mobile Applications
TWC:小:STRUCT:在移动应用程序中启用安全且值得信赖的部分
- 批准号:
1421824 - 财政年份:2014
- 资助金额:
$ 50.05万 - 项目类别:
Standard Grant
相似海外基金
CNS Core: Small: Rethinking Runtime Power Management for Mobile System-on-a-Chip
CNS 核心:小型:重新思考移动片上系统的运行时电源管理
- 批准号:
2016422 - 财政年份:2020
- 资助金额:
$ 50.05万 - 项目类别:
Standard Grant
CNS Core: Small: Rethinking Runtime Power Management for Mobile System-on-a-Chip
CNS 核心:小型:重新思考移动片上系统的运行时电源管理
- 批准号:
1907962 - 财政年份:2019
- 资助金额:
$ 50.05万 - 项目类别:
Standard Grant
CNS Core: Small: Rethinking the Software Architecture for Mobile DNA Analysis
CNS 核心:小型:重新思考移动 DNA 分析的软件架构
- 批准号:
1910193 - 财政年份:2019
- 资助金额:
$ 50.05万 - 项目类别:
Standard Grant
CAREER: Rethinking Mobile Security in the New Age of App-As-A-Platform
职业:重新思考应用程序即平台新时代的移动安全
- 批准号:
1652205 - 财政年份:2017
- 资助金额:
$ 50.05万 - 项目类别:
Continuing Grant