ITR-SY: System Hardening through Security Aware Compilation and Processor Architecture
ITR-SY: System Hardening through Security Aware Compilation and Processor Architecture
批准号:
0242222
负责人:
Gyungho Lee
金额:
$41.15万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-05-15 至 2005-08-31
中文摘要
联网的计算机系统容易受到恶意攻击。这些攻击通过将处理器程序计数器(PC)重新指向攻击者的代码来接管对受害者计算机系统的控制。该提案探讨了安全意识编译和处理器微体系结构在防止未经授权的PC修改方面的作用。PC危害的两个最常见的实例源于(1)激活记录中的返回地址和(2)函数指针的损坏。保护PC的基本方法是在任何潜在的PC值(如返回地址或函数指针表条目)存储到任何内存位置(如数据或堆空间中的堆栈帧或函数指针表)之前应用编码函数。任何将内存值读入PC的操作都必须首先通过解码功能。受损的PC值将只通过解码功能,因此将使恶意攻击无效。这项研究调查了PC编解码方案的几种变体,并评估了这些方案的计算开销及其有效性。本研究计划构建一个坚固的LINUX系统、GCC编译器和其他公共域实用程序,如整合了所提出的返回地址和函数指针保护方案的APACHE Web服务器。
英文摘要
Networked computer systems are vulnerable to malicious attack. These attackstry to take over the control of a victim computer system by re-pointing the processor program counter (PC) to the attacker's code. This proposal explores a role for security aware compilation and processor microarchitecture in preventing unauthorized PC modifications. The two most common instances of PC compromise arise from the corruption of (1) the return address in an activation record and (2) function pointers. The basic approach to guarding PC is to apply an encoding function before any potential PC value (such as return address, or function pointer table entry) is stored in any memory location (such as a stack frame or function pointer table in the data or heap space). Any read of a memory value into the PC first has to go through a decoding function. A compromised PC value would go only through the decoding function and hence would render the malicious attack ineffective. This research investigates several variations of PC encoding/decoding schemes and evaluates computational overhead of these schemes and their effectiveness. This research plans to build a hardened Linux system, gcc compiler and other public domain utilities such as Apache web server incorporating the proposed return address and function pointer protection schemes.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CT-ER: Augmenting Branch Prediction for Trusted Computing
-
批准号:0627341
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2006
-
负责人:Gyungho Lee
-
依托单位:
High-Bandwidth Memory Pipeline for Wide-Issue Processors
-
批准号:0225561
-
项目类别:Standard Grant
-
资助金额:$12.05万
-
财政年份:2002
-
负责人:Gyungho Lee
-
依托单位:
ITR-SY: System Hardening through Security Aware Compilation and Processor Architecture
-
批准号:0113409
-
项目类别:Continuing Grant
-
资助金额:$43.87万
-
财政年份:2001
-
负责人:Gyungho Lee
-
依托单位:
High-Bandwidth Memory Pipeline for Wide-Issue Processors
-
批准号:0073259
-
项目类别:Standard Grant
-
资助金额:$20.61万
-
财政年份:2000
-
负责人:Gyungho Lee
-
依托单位:
国内基金
海外基金
登录
查看更多内容
基于Nurr1调节YAP-INF2-线粒体分裂途径探讨龙琥醒脑颗粒在SH-SY5Y细胞氧糖剥夺再灌注诱发的神经元损伤的保护作用研究
-
批准号:2025JJ80982
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:张占伟
-
依托单位:
SY4835通过WEE1/DDR1双靶点抑制胰腺癌的作用及机制
-
批准号:82373136
-
项目类别:面上项目
-
资助金额:48万元
-
批准年份:2023
-
负责人:张晓飞
-
依托单位:
米糠黄酮抑制Aβ诱导的SH-SY5Y细胞中Tau蛋白过度磷酸化的分子机制研究
-
批准号:2022JJ31009
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2022
-
负责人:张琳
-
依托单位:
天目山来源链霉菌Streptomyces sp. SY1322中morindolestatin类新颖咔唑生物碱获取及其铁死亡抑制活性研究
-
批准号:LY21H300001
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2020
-
负责人:马列峰
-
依托单位:
基于MDM2-p53和MDMX-p53蛋白-蛋白相互作用的双重抑制剂SY1108的结构优化及抗肿瘤活性研究
-
批准号:21867013
-
项目类别:地区科学基金项目
-
资助金额:40.0万元
-
批准年份:2018
-
负责人:王亚丽
-
依托单位:
昆虫病原线虫共生菌SY5致死小菜蛾毒素的中肠靶标受体分离与鉴定
-
批准号:31301663
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2013
-
负责人:王欢
-
依托单位:
圆根大戟和甘遂中保护多巴胺所致SH-SY5Y细胞损伤帕金森模型作用和机制研究
-
批准号:81260628
-
项目类别:地区科学基金项目
-
资助金额:49.0万元
-
批准年份:2012
-
负责人:王金辉
-
依托单位:
拟南芥SY1蛋白抑制逆境基因表达的分子机理研究
-
批准号:31270316
-
项目类别:面上项目
-
资助金额:80.0万元
-
批准年份:2012
-
负责人:杨万年
-
依托单位:
刺五加有效组分对转染α-Syn的 SH-SY5Y细胞调控及机制研究
-
批准号:81073019
-
项目类别:面上项目
-
资助金额:32.0万元
-
批准年份:2010
-
负责人:刘树民
-
依托单位:
亚洲含SY基因组披碱草属植物地理分化的分子生物学基础
-
批准号:30270092
-
项目类别:面上项目
-
资助金额:20.0万元
-
批准年份:2002
-
负责人:卢宝荣
-
依托单位: