SBIR Phase I: Automatic Extraction and Enforcement of Application-Specific Security Policy
SBIR Phase I: Automatic Extraction and Enforcement of Application-Specific Security Policy
批准号:
0339955
负责人:
Tzi-cker Chiueh
金额:
$10.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2004
资助国家:
美国
项目状态:
已结题
起止时间:
2004-01-01 至 2004-06-30
中文摘要
这个小型企业创新研究(SBIR)第一阶段的项目是开发一个程序语义感知的入侵检测(付费)系统,该系统从应用程序的源代码中派生安全策略,并在运行时根据生成的策略检查应用程序的系统调用。该产品不仅可以完全自动派生这些策略,而且生成的安全策略是针对各个应用程序量身定做的,因此非常准确。一些最危险的网络安全威胁是“控制劫持”攻击,这种攻击劫持受攻击应用程序的控制,并以受攻击程序的有效用户的身份执行任意系统调用。这些类型的攻击非常危险,因为具有此类漏洞的商业应用程序似乎分布广泛,最近的SQL Slammer蠕虫病毒的猖獗就表明了这一点。系统调用监控被吹捧为控制劫持攻击的有效解决方案,因为它可以防止远程攻击者对受害者系统造成损害,即使他们可以成功破坏系统上运行的应用程序。这种方法的一个缺点是如何构建能够最大限度地减少误报和漏报的准确的安全策略。虽然已经尝试了各种方法来解决这个问题,但都不是令人满意的。基于系统调用监控的基于主机的入侵检测,也被称为行为拦截系统,是一种众所周知的倾向于保守或误报的错误。该工具将自动获得与个别应用程序的系统调用模式相对应的准确安全策略,从而将误报和漏报都减少到最低限度。付费系统代表着缩小当前行为屏蔽产品与现实世界信息技术(IT)系统实际需求之间的差距的一大步。
英文摘要
This Small Business Innovation Research (SBIR) Phase I project is to develop a Program semantics-Aware Intrusion Detection (PAID) system that derives a security policy from an application's source code, and checks the application's system calls against the resulting policy at run time. Not only can this product derive these policies completely automatically, but also the resulting security policy is tailored to individual applications and thus is highly accurate. Some of the most dangerous cyber security threats are "control hijacking" attacks, which hijack the control of a victim application, and execute arbitrary system calls assuming the identity of the victim program's effective user. These types of attacks are highly perilous because commercial applications with such vulnerabilities appear to be wide spread, as shown in the rampancy of the recent SQL Slammer Worm. System call monitoring has been touted as an effective solution to "control hijacking" attacks because it could prevent remote attackers from inflicting damage upon a victim system even if they can successfully compromise applications running on the system. A weakness of this approach is how to construct accurate security policy that could minimize false positives and negatives. Although various approaches have been tried to solve this problem, none of them is satisfactory. Host-based intrusion detection based on system call monitoring, also referred to as behavioral blocking systems, is a well known tend to err on the conservative or false positive side. The tool will automatically derive accurate security policies corresponding to the system call patterns of individual applications, thus reducing both false positives and negatives to the minimum. The PAID system represents a big step in closing the gap between current behavioral blocking products and the actual needs of real world information technology (IT) systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
登录
查看更多内容
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark
Supercooled Phase Transition
-
批准号:24ZR1429700
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:YUICHIRO NAKAI
-
依托单位:
ATLAS实验探测器Phase 2升级
-
批准号:11961141014
-
项目类别:国际(地区)合作与交流项目
-
资助金额:3350万元
-
批准年份:2019
-
负责人:刘衍文
-
依托单位:
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
-
批准号:41802035
-
项目类别:青年科学基金项目
-
资助金额:12.0万元
-
批准年份:2018
-
负责人:张里
-
依托单位:
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究
-
批准号:61675216
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2016
-
负责人:叶青
-
依托单位:
基于Phase-type分布的多状态系统可靠性模型研究
-
批准号:71501183
-
项目类别:青年科学基金项目
-
资助金额:17.4万元
-
批准年份:2015
-
负责人:陈童
-
依托单位:
纳米(I-Phase+α-Mg)准共晶的临界半固态形成条件及生长机制
-
批准号:51201142
-
项目类别:青年科学基金项目
-
资助金额:25.0万元
-
批准年份:2012
-
负责人:张英波
-
依托单位:
连续Phase-Type分布数据拟合方法及其应用研究
-
批准号:11101428
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2011
-
负责人:黄卓
-
依托单位:
D-Phase准晶体的电子行为各向异性的研究
-
批准号:19374069
-
项目类别:面上项目
-
资助金额:6.4万元
-
批准年份:1993
-
负责人:张殿琳
-
依托单位: