SaTC: STARSS: Small: Tackling the Corner Cases: Finding Security Vulnerabilities in CPU Designs
SaTC:STARSS:小型:解决极端情况:查找 CPU 设计中的安全漏洞
基本信息
- 批准号:1816637
- 负责人:
- 金额:$ 33.33万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-10-01 至 2022-09-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Computing hardware including processors, memory banks, and communication busses can harbor vulnerabilities that allow an attacker to gain unauthorized access to the programs and data on a machine. Hardware designers and security experts expend considerable time and effort to eliminate these vulnerabilities early in the design stage. The focus of this research is to support these activities towards improving efficiency and outcomes. In developing the methodologies and tools to find and contextualize hardware security vulnerabilities, this research will move the field of security validation of hardware designs forward.The research targets the security validation of central processing units in the design stage. The project has two goals: 1) To identify security critical properties of a processor. These properties will be stated in a temporal logic over the register transfer level design. 2) To develop the methodology and tools to automatically find and contextualize violations of those properties. A key innovation of this research will be the application of symbolic execution to hardware designs. In order to make symbolically executing a complex hardware design through multiple clock cycles feasible, the research will develop a targeted, backward search strategy.If successful, the project has the potential to significantly reduce the opportunity for a malicious actor to launch an effective attack against hardware, improving the security of computer systems.The tools, testbenches, papers, and presentations resulting from this research will be available at a site linked from https://cs.unc.edu/~csturton.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
计算包括处理器,内存库和通信总线在内的硬件可能会留下漏洞,从而使攻击者能够获得对机器上程序和数据的未经授权访问。硬件设计师和安全专家花费了大量时间和精力来消除设计阶段的早期这些漏洞。这项研究的重点是支持这些活动以提高效率和结果。在开发方法和工具以查找和上下文化硬件安全漏洞时,本研究将推动硬件设计的安全验证领域。该研究针对设计阶段中央处理单元的安全验证。该项目有两个目标:1)确定处理器的安全关键属性。这些属性将在寄存器传输级设计上的时间逻辑中说明。 2)开发方法和工具,以自动查找并将其上下文化对这些属性的行为。这项研究的关键创新将是将符号执行的应用到硬件设计。为了通过可行的多个时钟循环来象征性地执行复杂的硬件设计,该研究将制定有针对性的后退搜索策略。如果成功,该项目有可能大大减少恶意演员发动有效攻击的机会硬件,改善计算机系统的安全性。该研究产生的工具,测试台,论文和演示文稿将在https://cs.unc.edu/~csturton.this奖励的网站上获得。使用基金会的知识分子优点和更广泛的审查标准,通过评估被认为值得支持。
项目成果
期刊论文数量(6)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Mining Security Critical Linear Temporal Logic Specifications for Processors
采矿安全关键的线性时态逻辑处理器规范
- DOI:10.1109/mtv.2018.00013
- 发表时间:2018
- 期刊:
- 影响因子:0
- 作者:Deutschbein, Calvin;Sturton, Cynthia
- 通讯作者:Sturton, Cynthia
Evaluating Security Specification Mining for a CISC Architecture
评估 CISC 架构的安全规范挖掘
- DOI:10.1109/host45689.2020.9300291
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Deutschbein, Calvin;Sturton, Cynthia
- 通讯作者:Sturton, Cynthia
End-to-End Automated Exploit Generation for Processor Security Validation
用于处理器安全验证的端到端自动漏洞利用生成
- DOI:10.1109/mdat.2021.3063314
- 发表时间:2021
- 期刊:
- 影响因子:2
- 作者:Zhang, Rui;Deutschbein, Calvin;Huang, Peng;Sturton, Cynthia
- 通讯作者:Sturton, Cynthia
Isadora: Automated Information Flow Property Generation for Hardware Designs
- DOI:10.1145/3474376.3487286
- 发表时间:2021-06
- 期刊:
- 影响因子:0
- 作者:Calvin Deutschbein;Andres Meza;Francesco Restuccia;R. Kastner;C. Sturton
- 通讯作者:Calvin Deutschbein;Andres Meza;Francesco Restuccia;R. Kastner;C. Sturton
Transys: Leveraging Common Security Properties Across Hardware Designs
- DOI:10.1109/sp40000.2020.00030
- 发表时间:2020-05
- 期刊:
- 影响因子:0
- 作者:Rui Zhang;C. Sturton
- 通讯作者:Rui Zhang;C. Sturton
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Cynthia Sturton其他文献
Cynthia Sturton的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Cynthia Sturton', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
协作研究:SaTC:核心:中:硬件安全见解:分析硬件设计以了解和评估安全弱点和漏洞
- 批准号:
2247754 - 财政年份:2023
- 资助金额:
$ 33.33万 - 项目类别:
Continuing Grant
EAGER: Identifying Security Critical Properties of a Processor
EAGER:识别处理器的安全关键属性
- 批准号:
1651276 - 财政年份:2016
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
CPS: Frontier: Collaborative Research: VeHICaL: Verified Human Interfaces, Control, and Learning for Semi-Autonomous Systems
CPS:前沿:协作研究:VeHCaL:半自主系统的经过验证的人机界面、控制和学习
- 批准号:
1544924 - 财政年份:2016
- 资助金额:
$ 33.33万 - 项目类别:
Continuing Grant
CRII: SaTC: Detecting Security Vulnerabilities in Instruction Set Architectures
CRII:SaTC:检测指令集架构中的安全漏洞
- 批准号:
1464209 - 财政年份:2015
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
相似国自然基金
基于智能信号参数估计的雷达卫星星座非平稳舰船多维多域成像研究
- 批准号:62301191
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
银河系及其同类星系中的卫星星系对比研究
- 批准号:
- 批准年份:2022
- 资助金额:55 万元
- 项目类别:面上项目
星团中的恒星星族研究
- 批准号:12233013
- 批准年份:2022
- 资助金额:290 万元
- 项目类别:重点项目
微纳卫星星载主动光学压电复合变形镜结构优化和控制策略分析
- 批准号:
- 批准年份:2021
- 资助金额:30 万元
- 项目类别:青年科学基金项目
信息交互动态化的卫星星座控制系统自主故障诊断能力评价方法研究
- 批准号:
- 批准年份:2021
- 资助金额:30 万元
- 项目类别:青年科学基金项目
相似海外基金
SaTC: STARSS: Small: IoT Circuit Locking, Obfuscation & Authentication Kernel (CLOAK), A Compilable Architecture for Secure IoT Device Production, Testing, Activation & Ope
SaTC:STARSS:小型:物联网电路锁定、混淆
- 批准号:
2200446 - 财政年份:2021
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Combined Side-channel Attacks and Mathematical Foundations of Combined Countermeasures
SaTC:STARSS:小:组合侧信道攻击和组合对策的数学基础
- 批准号:
1929774 - 财政年份:2019
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Assuring Security and Privacy of Emerging Non-Volatile Memories
SaTC:STARSS:小型:确保新兴非易失性存储器的安全性和隐私
- 批准号:
1814710 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
SaTC:STARSS:小型:用于检测和防御恶意固件的领域知情技术
- 批准号:
1815883 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Analysis of Security and Countermeasures for Split Manufacturing of Integrated Circuits
SaTC:STARSS:小型:集成电路分片制造的安全性及对策分析
- 批准号:
1812600 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant