CAREER: Principled and Practical Software Shielding against Advanced Exploits
职业:针对高级漏洞的有原则且实用的软件防护
基本信息
- 批准号:1749895
- 负责人:
- 金额:$ 49.99万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-06-01 至 2024-11-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The exploitation of memory corruption vulnerabilities in popular software is among the leading causes of system compromise and malware infection. While there are several reasons behind this proliferation of exploitable bugs, the reliance on unsafe programming languages such as C and C++ and the complexity of modern software play a major role. The continuous discovery of previously unknown (zero-day) vulnerabilities in browsers, document viewers, and other widely used software, and the lack of effective defenses against recent exploitation techniques that leverage memory disclosure vulnerabilities, necessitate the development of additional defense mechanisms.The main objective of this project is the design of software shielding techniques and their practical applicability to commodity software and systems. The key innovative aspects of the investigated techniques include: i) principled design that considers the strong adversarial models imposed by the latest exploitation advancements, i.e., disclosure-aided exploitation and data-only attacks, against which effective countermeasures remain an open problem; ii) novel code specialization and data protection techniques, to introduce process-level unpredictability and limit the exposure of critical data; iii) hardware-assisted implementation by leveraging recent and upcoming processor features to minimize the performance impact of the applied protections; and iv) focus on practical considerations, such as operational compatibility and non-disruptive deployment. The outcomes of this research effort are expected to improve the state of the art in defenses against advanced exploits, and achieve substantial practical impact by shielding existing vulnerable applications against exploitation, benefiting both end users and security researchers. The project also provides students the opportunity to conduct research in cybersecurity, and fosters the integration of cybersecurity into high school education through hands-on workshops for students and seminars for science teachers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在流行软件中对内存损坏漏洞的开发是系统折衷和恶意软件感染的主要原因之一。尽管这种可剥削性错误的扩散背后有几个原因,但对不安全的编程语言(例如C ++)的依赖,现代软件的复杂性起着重要作用。在浏览器,文档查看器和其他广泛使用的软件中不断发现以前未知的(零日)漏洞,以及缺乏针对利用记忆披露脆弱性的最新剥削技术的有效防御,需要开发其他防御机制。该项目的主要目标是该项目的软件屏蔽技术及其实践应用程序的设计。调查技术的关键创新方面包括:i)原则设计,这些设计考虑了最新的剥削进步所施加的强大对抗模型,即披露辅助援助的剥削和仅数据攻击,有效的反对仍然是一个开放的问题; ii)新颖的代码专业化和数据保护技术,以引入过程级别的不可预测性并限制关键数据的暴露; iii)通过利用最新和即将到来的处理器功能来最大程度地降低应用保护的性能影响来实现硬件辅助实现; iv)专注于实际考虑因素,例如操作兼容性和非破坏性部署。预计这项研究工作的结果有望改善防御高级利用的最新技术,并通过屏蔽现有脆弱应用程序免受剥削的侵害,从而使最终用户和安全研究人员受益。该项目还为学生提供了进行网络安全研究的机会,并通过为学生和科学老师的研讨会来促进网络安全融合到高中教育中。该奖项反映了NSF的法定任务,并被认为是通过基金会的知识分子和更广泛影响的评估来评估CRITERIA CRITERIA CRITERIA的评估。
项目成果
期刊论文数量(14)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
The SEVerESt Of Them All: Inference Attacks Against Secure Virtual Enclaves
- DOI:10.1145/3321705.3329820
- 发表时间:2019-07
- 期刊:
- 影响因子:0
- 作者:Jan Werner;Joshua Mason;M. Antonakakis;M. Polychronakis;F. Monrose
- 通讯作者:Jan Werner;Joshua Mason;M. Antonakakis;M. Polychronakis;F. Monrose
Temporal System Call Specialization for Attack Surface Reduction
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Seyedhamed Ghavamnia;Tapti Palit;Shachee Mishra;M. Polychronakis
- 通讯作者:Seyedhamed Ghavamnia;Tapti Palit;Shachee Mishra;M. Polychronakis
Confine: Automated System Call Policy Generation for Container Attack Surface Reduction
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Seyedhamed Ghavamnia;Tapti Palit;Azzedine Benameur;M. Polychronakis
- 通讯作者:Seyedhamed Ghavamnia;Tapti Palit;Azzedine Benameur;M. Polychronakis
Decap: Deprivileging Programs by Reducing Their Capabilities
Decap:通过降低程序的能力来剥夺程序的特权
- DOI:10.1145/3545948.3545978
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Hasan, Md Mehedi;Ghavamnia, Seyedhamed;Polychronakis, Michalis
- 通讯作者:Polychronakis, Michalis
C2C: Fine-grained Configuration-driven System Call Filtering
- DOI:10.1145/3548606.3559366
- 发表时间:2022-11
- 期刊:
- 影响因子:0
- 作者:Seyedhamed Ghavamnia;Tapti Palit;M. Polychronakis
- 通讯作者:Seyedhamed Ghavamnia;Tapti Palit;M. Polychronakis
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Michail Polychronakis其他文献
Michail Polychronakis的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Michail Polychronakis', 18)}}的其他基金
SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks
SaTC:核心:小型:针对面向数据和瞬态执行攻击的选择性数据保护
- 批准号:
2104148 - 财政年份:2021
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
TWC: Small: Combating Environment-aware Malware
TWC:小型:打击环境感知恶意软件
- 批准号:
1617902 - 财政年份:2016
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
CSR: Small: An Information Accountability Architecture for Distributed Enterprise Systems
CSR:小型:分布式企业系统的信息责任架构
- 批准号:
0914312 - 财政年份:2009
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
相似国自然基金
基于“碳循”原则的模块化建筑隐含碳排放系统测算和协同优化研究
- 批准号:72301232
- 批准年份:2023
- 资助金额:30.00 万元
- 项目类别:青年科学基金项目
手性液晶超结构的构筑原则与调控机制
- 批准号:22373089
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
完全统计学习原则下的零经验风险记忆学习研究
- 批准号:62366035
- 批准年份:2023
- 资助金额:31 万元
- 项目类别:地区科学基金项目
染色质空间结构的设计原则与随机动力学
- 批准号:12301646
- 批准年份:2023
- 资助金额:30.00 万元
- 项目类别:青年科学基金项目
基于“谁受益谁付费”原则的电网替代性储能成本疏导机制研究
- 批准号:72304056
- 批准年份:2023
- 资助金额:30.00 万元
- 项目类别:青年科学基金项目
相似海外基金
A Principled Framework for Explaining, Choosing and Negotiating Privacy Parameters of Differential Privacy
解释、选择和协商差异隐私的隐私参数的原则框架
- 批准号:
23K24851 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
CAREER: Principled yet practical observability for a microservices-based cloud
职业:基于微服务的云的原则性且实用的可观察性
- 批准号:
2340128 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Continuing Grant
CAREER: Principled Unsupervised Learning via Minimum Volume Polytopic Embedding
职业:通过最小体积多面嵌入进行有原则的无监督学习
- 批准号:
2237640 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Continuing Grant
Principled phylogenomic analysis without gene tree estimation
无需基因树估计的有原则的系统发育分析
- 批准号:
2308495 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
A principled generalization of the maximum entropy principle for non-Shannon systems
非香农系统最大熵原理的原则概括
- 批准号:
23K16855 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Grant-in-Aid for Early-Career Scientists