CAREER: Indistinguishability Prevents Information Leakage in Real-Time Schedulers

职业:不可区分性防止实时调度程序中的信息泄漏

基本信息

  • 批准号:
    2246937
  • 负责人:
  • 金额:
    $ 52.34万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2022
  • 资助国家:
    美国
  • 起止时间:
    2022-10-01 至 2027-05-31
  • 项目状态:
    未结题

项目摘要

Modern society relies heavily on systems that operate within strict timing requirements such as in engine control units in automobiles, aircraft avionics and navigation systems, programmable logic controllers in manufacturing plants, industrial control systems in the electricity sector, and many hundreds of others. The recent advent of autonomous cars, drones and internet-of-things (IoT) further expands the reach of these "real-time systems". The limitations of such devices viz., small computing power, less memory, limited battery power, has serious consequences for security, specifically, they become much harder to protect and defend. This research develops systematic security mechanisms for real-time embedded systems in critical applications to control what can be observed about them. An important reason why real-time systems are vulnerable is the fact that they are predictable by design, thus leaking critical information. Leakage, say via timing "side channels", might be misused as part of a campaign to disrupt normal operations by knowing the schedule of when critical applications will run. Any mitigations to information leakage must still allow real-time systems to operate within their required timing constraints. This project improves the security of real-time systems using concepts inspired from the area of differential privacy that was developed for database security, where the fundamental concept is to hide personally identifying information from queries on large databases by injecting "noise" in a systematic manner. By analogy for real-time systems, this project focuses on system states at runtime and develops the notion of "schedule indistinguishability" by strategically adding "noise" to the task scheduler, so individual tasks cannot be distinguished separately and cannot be known. The concept of "epsilon-indistinguishability" is developed to measure the probability of information leakage of schedule and timing information by observation of task-level behaviors. A task scheduler that effectively and efficiently uses indistinguishability is designed and prototyped. In addition, the project focuses on developing metrics for real-time systems to measure and assess the risk mitigations of using schedule indistinguishability. The long-term goal of this research is to explore the relationships of "indistinguishability" for cyber-physical systems and their application domains with regard to security, safety, dependability, and resilience.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
现代社会严重依赖在严格的时序要求下运行的系统,例如汽车的发动机控制单元、飞机航空电子设备和导航系统、制造工厂的可编程逻辑控制器、电力部门的工业控制系统以及数百种其他系统。最近自动驾驶汽车、无人机和物联网 (IoT) 的出现进一步扩大了这些“实时系统”的范围。此类设备的局限性,即计算能力小、内存少、电池电量有限,对安全性产生了严重后果,特别是,它们变得更难以保护和防御。这项研究为关键应用中的实时嵌入式系统开发了系统的安全机制,以控制可以观察到的内容。实时系统容易受到攻击的一个重要原因是它们在设计上是可预测的,从而泄露了关键信息。通过定时“侧通道”进行的泄漏可能会被滥用,作为通过了解关键应用程序运行时间表来扰乱正常操作的活动的一部分。 任何对信息泄漏的缓解措施都必须允许实时系统在其所需的时间限制内运行。该项目使用受差异隐私领域启发的概念来提高实时系统的安全性,该领域是为数据库安全而开发的,其基本概念是通过系统地注入“噪声”来隐藏大型数据库查询中的个人识别信息。类比实时系统,该项目关注运行时的系统状态,并通过策略性地向任务调度器添加“噪声”来发展“调度不可区分性”的概念,因此单个任务无法单独区分,也无法得知。提出“epsilon-不可区分性”的概念,通过观察任务级行为来衡量日程和计时信息的信息泄漏概率。设计并制作了一个有效且高效地利用不可区分性的任务调度程序。 此外,该项目的重点是开发实时系统的指标,以衡量和评估使用时间表不可区分性的风险缓解措施。这项研究的长期目标是探索网络物理系统及其应用领域在安全性、可靠性和弹性方面的“不可区分性”关系。该奖项反映了 NSF 的法定使命,被认为是值得的通过使用基金会的智力优势和更广泛的影响审查标准进行评估来提供支持。

项目成果

期刊论文数量(3)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Towards Efficient Auditing for Real-Time Systems
实现实时系统的高效审计
SchedGuard++: Protecting against Schedule Leaks Using Linux Containers on Multi-Core Processors
SchedGuard:在多核处理器上使用 Linux 容器防止计划泄漏
  • DOI:
    10.1145/3565974
  • 发表时间:
    2023-01
  • 期刊:
  • 影响因子:
    2.3
  • 作者:
    Chen, Jiyang;Kloda, Tomasz;Tabish, Rohan;Bansal, Ayoosh;Chen, Chien;Liu, Bo;Mohan, Sibin;Caccamo, Marco;Sha, Lui
  • 通讯作者:
    Sha, Lui
Insights on Using Deep Learning to Spoof Inertial Measurement Units for Stealthy Attacks on UAVs
关于使用深度学习欺骗惯性测量装置对无人机进行隐形攻击的见解
  • DOI:
    10.1109/milcom55135.2022.10017482
  • 发表时间:
    2022-11
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Kim, Kyo Hyun;Kara, Denizkhan;Paruchuri, Vineetha;Mohan, Sibin;Kimberly, Greg;Osipychev, Denis;Kim, Jae H.;Eckhardt, Josh D.;Pajic, Miroslav
  • 通讯作者:
    Pajic, Miroslav
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Sibin Mohan其他文献

First in Canada, Night and Day Field Demonstration of a New Photovoltaic Solar-Based Flexible AC Transmission System (FACTS) Device PV-STATCOM for Stabilizing Critical Induction Motor
加拿大首次昼夜现场演示新型光伏太阳能柔性交流输电系统 (FACTS) 装置 PV-STATCOM,用于稳定关键感应电机
  • DOI:
    10.1109/access.2019.2935161
  • 发表时间:
    2019-08-13
  • 期刊:
  • 影响因子:
    3.9
  • 作者:
    R. Varma;E. Siavashi;Sibin Mohan;T. V;erheide;erheide
  • 通讯作者:
    erheide
A Linux in unikernel clothing
披着单内核外衣的 Linux
Addressing Safety and Security Contradictions in Cyber-Physical Systems
解决网络物理系统中的安全矛盾
  • DOI:
  • 发表时间:
    2009
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Mu Sun;Sibin Mohan;Carl A. Gunter
  • 通讯作者:
    Carl A. Gunter
Schedule-Based Side-Channel Attack in Fixed-Priority Real-time Systems
固定优先级实时系统中基于时间表的侧信道攻击
  • DOI:
  • 发表时间:
    2024-09-13
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Chien;AmirEmad Ghassami;Stefan Nagy;Man;Sibin Mohan;N. Kiyavash;R. Bobba;R. Pellizzoni
  • 通讯作者:
    R. Pellizzoni
PIRMedic: physics-driven fault diagnosis for PIR sensors
PIRMedic:物理驱动的 PIR 传感器故障诊断

Sibin Mohan的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Sibin Mohan', 18)}}的其他基金

CAREER: Indistinguishability Prevents Information Leakage in Real-Time Schedulers
职业:不可区分性防止实时调度程序中的信息泄漏
  • 批准号:
    2145787
  • 财政年份:
    2022
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Small: An Exploration of Schedule-Based Vulnerabilities In Real-Time Embedded Systems
SaTC:核心:小型:实时嵌入式系统中基于调度的漏洞的探索
  • 批准号:
    1718952
  • 财政年份:
    2017
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Standard Grant
CPS: TTP Option: Frontiers: Collaborative Research: Software Defined Control for Smart Manufacturing Systems
CPS:TTP 选项:前沿:协作研究:智能制造系统的软件定义控制
  • 批准号:
    1544901
  • 财政年份:
    2016
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Continuing Grant
TWC: Small: Behavior-Based Zero-Day Intrusion Detection for Real-Time Cyber-Physical Systems
TWC:小型:针对实时网络物理系统的基于行为的零日入侵检测
  • 批准号:
    1423334
  • 财政年份:
    2014
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Standard Grant

相似国自然基金

关于公钥可搜索加密协议中的公开可验证问题的研究
  • 批准号:
    61772311
  • 批准年份:
    2017
  • 资助金额:
    59.0 万元
  • 项目类别:
    面上项目
面向移动位置服务的空间位置大数据差分隐私保护研究
  • 批准号:
    41671443
  • 批准年份:
    2016
  • 资助金额:
    65.0 万元
  • 项目类别:
    面上项目
伪随机序列分析及可证明安全性研究
  • 批准号:
    60573030
  • 批准年份:
    2005
  • 资助金额:
    24.0 万元
  • 项目类别:
    面上项目

相似海外基金

CAREER: Indistinguishability Prevents Information Leakage in Real-Time Schedulers
职业:不可区分性防止实时调度程序中的信息泄漏
  • 批准号:
    2145787
  • 财政年份:
    2022
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Continuing Grant
「一般・特定」の区別が日本人英語学習者の冠詞習得に果たす役割と冠詞指導への応用
“一般/具体”区分在日本英语学习者习得文章中的作用及其在文章教学中的应用
  • 批准号:
    20K00804
  • 财政年份:
    2020
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Representations and calculations of uncertainty for decision aid considering human factors and utilization of ambiguity
考虑人为因素和模糊性利用的决策辅助不确定性的表示和计算
  • 批准号:
    18H01658
  • 财政年份:
    2018
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
Welfare Analysis of Public Policy by an Overlapping-generations Model with Endogenous Fertility
内生生育力代际重叠模型的公共政策福利分析
  • 批准号:
    15K03514
  • 财政年份:
    2015
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Structural Identifiability and Indistinguishability Analysis as Tools for Quantitative and Systems Pharmacology to Support the 3Rs
结构可识别性和不可区分性分析作为定量和系统药理学工具支持 3R
  • 批准号:
    NC/K001205/1
  • 财政年份:
    2013
  • 资助金额:
    $ 52.34万
  • 项目类别:
    Research Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了