ITR-SY: System Hardening through Security Aware Compilation and Processor Architecture
ITR-SY: System Hardening through Security Aware Compilation and Processor Architecture
批准号:
0113409
负责人:
Gyungho Lee
金额:
$43.87万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2001
资助国家:
美国
项目状态:
已结题
起止时间:
2001-09-01 至 2002-06-30
中文摘要
网络计算机系统容易受到恶意攻击。这些攻击通过将处理器程序计数器(PC)重新指向攻击者的代码来接管对受害计算机系统的控制。本提案探讨了安全感知编译和处理器微架构在防止未经授权的PC修改中的作用。PC妥协的两个最常见的实例来自(1)激活记录中的返回地址和(2)函数指针的损坏。保护PC的基本方法是在任何潜在的PC值(如返回地址或函数指针表项)存储在任何内存位置(如数据或堆空间中的堆栈帧或函数指针表)之前应用编码函数。任何存储器值的读入PC首先必须经过解码功能。受损的PC值只会通过解码功能,因此会使恶意攻击无效。本研究探讨了几种不同的PC编码/解码方案,并评估了这些方案的计算开销及其有效性。本研究计划构建一个强化的Linux系统,gcc编译器和其他公共领域的实用程序,如Apache web服务器,结合建议的返回地址和函数指针保护方案。
英文摘要
Networked computer systems are vulnerable to malicious attack. These attackstry to take over the control of a victim computer system by re-pointing the processor program counter (PC) to the attacker's code. This proposal explores a role for security aware compilation and processor microarchitecture in preventing unauthorized PC modifications. The two most common instances of PC compromise arise from the corruption of (1) the return address in an activation record and (2) function pointers. The basic approach to guarding PC is to apply an encoding function before any potential PC value (such as return address, or function pointer table entry) is stored in any memory location (such as a stack frame or function pointer table in the data or heap space). Any read of a memory value into the PC first has to go through a decoding function. A compromised PC value would go only through the decoding function and hence would render the malicious attack ineffective. This research investigates several variations of PC encoding/decoding schemes and evaluates computational overhead of these schemes and their effectiveness. This research plans to build a hardened Linux system, gcc compiler and other public domain utilities such as Apache web server incorporating the proposed return address and function pointer protection schemes.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CT-ER: Augmenting Branch Prediction for Trusted Computing
-
批准号:0627341
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2006
-
负责人:Gyungho Lee
-
依托单位:
ITR-SY: System Hardening through Security Aware Compilation and Processor Architecture
-
批准号:0242222
-
项目类别:Continuing Grant
-
资助金额:$41.15万
-
财政年份:2002
-
负责人:Gyungho Lee
-
依托单位:
High-Bandwidth Memory Pipeline for Wide-Issue Processors
-
批准号:0225561
-
项目类别:Standard Grant
-
资助金额:$12.05万
-
财政年份:2002
-
负责人:Gyungho Lee
-
依托单位:
High-Bandwidth Memory Pipeline for Wide-Issue Processors
-
批准号:0073259
-
项目类别:Standard Grant
-
资助金额:$20.61万
-
财政年份:2000
-
负责人:Gyungho Lee
-
依托单位:
国内基金
海外基金
登录
查看更多内容
基于Nurr1调节YAP-INF2-线粒体分裂途径探讨龙琥醒脑颗粒在SH-SY5Y细胞氧糖剥夺再灌注诱发的神经元损伤的保护作用研究
-
批准号:2025JJ80982
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:张占伟
-
依托单位:
SY4835通过WEE1/DDR1双靶点抑制胰腺癌的作用及机制
-
批准号:82373136
-
项目类别:面上项目
-
资助金额:48万元
-
批准年份:2023
-
负责人:张晓飞
-
依托单位:
米糠黄酮抑制Aβ诱导的SH-SY5Y细胞中Tau蛋白过度磷酸化的分子机制研究
-
批准号:2022JJ31009
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2022
-
负责人:张琳
-
依托单位:
天目山来源链霉菌Streptomyces sp. SY1322中morindolestatin类新颖咔唑生物碱获取及其铁死亡抑制活性研究
-
批准号:LY21H300001
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2020
-
负责人:马列峰
-
依托单位:
基于MDM2-p53和MDMX-p53蛋白-蛋白相互作用的双重抑制剂SY1108的结构优化及抗肿瘤活性研究
-
批准号:21867013
-
项目类别:地区科学基金项目
-
资助金额:40.0万元
-
批准年份:2018
-
负责人:王亚丽
-
依托单位:
昆虫病原线虫共生菌SY5致死小菜蛾毒素的中肠靶标受体分离与鉴定
-
批准号:31301663
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2013
-
负责人:王欢
-
依托单位:
圆根大戟和甘遂中保护多巴胺所致SH-SY5Y细胞损伤帕金森模型作用和机制研究
-
批准号:81260628
-
项目类别:地区科学基金项目
-
资助金额:49.0万元
-
批准年份:2012
-
负责人:王金辉
-
依托单位:
拟南芥SY1蛋白抑制逆境基因表达的分子机理研究
-
批准号:31270316
-
项目类别:面上项目
-
资助金额:80.0万元
-
批准年份:2012
-
负责人:杨万年
-
依托单位:
刺五加有效组分对转染α-Syn的 SH-SY5Y细胞调控及机制研究
-
批准号:81073019
-
项目类别:面上项目
-
资助金额:32.0万元
-
批准年份:2010
-
负责人:刘树民
-
依托单位:
亚洲含SY基因组披碱草属植物地理分化的分子生物学基础
-
批准号:30270092
-
项目类别:面上项目
-
资助金额:20.0万元
-
批准年份:2002
-
负责人:卢宝荣
-
依托单位: