课题基金 / 基金详情

CT-ISG: Memory Safety for Legacy Software, A Quantitative Approach

CT-ISG: Memory Safety for Legacy Software, A Quantitative Approach
CT-ISG:遗留软件的内存安全,一种定量方法
批准号:
0831532
负责人:
Hovav Shacham
金额:
$40.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-09-01 至 2012-08-31

项目摘要

项目成果

Hovav Shacham的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The inability of programmers to write vulnerability free code is the most pressing problem in practical computer systems security. The most serious class of vulnerabilities is memory vulnerabilities, which generally allow an attacker to subvert the program's control flow. In response to this problem, generic mitigations have been widely deployed that, through changes to the operating system and processor, seek to make it impossible for attackers to exploit errors in programs.Implementers considering deploying such mitigations must know how much (if at all) a generic mitigation improves security and what its costs are if they are to allocate R&D resources wisely.Unfortunately, until recently, the benefits of generic mitigations were studied only superficially. Recent first steps have already shed some light, showing, e.g., that the widely deployed "W-xor-X"mitigation provides no security benefit whatsoever.This project puts imperfect, ad-hoc mitigation on a scientific footing. It provides a formal, comprehensive analysis to determine the cost-benefit equation is for generic mitigations.The project begins by producing quantitative analyses of current mitigation techniques and of attacks; these analyses facilitate the creation of new mitigations that resist attacks that foil current mitigations; these new mitigations are implemented, evaluated, and disseminated. In addition, the project develops a sandboxed environment for experimenting with software vulnerabilities and malicious code, and a curriculum for teaching systems security.The results will be better use of implementation resources for vendors; a more secure legacy software environment for users; and better security education for the next generation of programmers, so they will not make the mistakes earlier ones did.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Large: Building and Deploying a Verified JavaScript Runtime
  • 批准号:
    2120696
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $172.99万
  • 财政年份:
    2021
  • 负责人:
    Hovav Shacham
  • 依托单位:
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
  • 批准号:
    1937622
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.36万
  • 财政年份:
    2018
  • 负责人:
    Hovav Shacham
  • 依托单位:
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
  • 批准号:
    1410031
  • 项目类别:
    Standard Grant
  • 资助金额:
    $38.4万
  • 财政年份:
    2014
  • 负责人:
    Hovav Shacham
  • 依托单位:
InfoSec Scholars: Scholarship for Service
  • 批准号:
    1303328
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $213.6万
  • 财政年份:
    2013
  • 负责人:
    Hovav Shacham
  • 依托单位:
国内基金
海外基金
甘草苷通过IFN-I/ISG15信号通路促进卵巢颗粒细胞外泌体分泌延缓卵巢衰老的作用机制
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李璐邑
  • 依托单位:
ISG15/LFA-1调控肿瘤相关巨噬细胞浸润促进胆囊癌免疫逃逸的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    蔡炜龙
  • 依托单位:
ISG15类泛素化修饰多囊泡小体介导KNG1-PI3K/Akt信号轴在葡萄膜炎内皮屏障损伤中的作用机制研究
  • 批准号:
    JCZRQN202500743
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
  • 依托单位:
ISG15下调lncRNA RP11-5407.3介导细胞自噬促进子宫内膜癌进展的 作用及机制研究