课题基金 / 基金详情

TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems

TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems
TC:媒介:协作研究:确保现代系统中的并发性
批准号:
0905177
负责人:
Jedidiah Crandall
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2013-08-31

项目摘要

项目成果

Jedidiah Crandall的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5). Concurrency-related vulnerabilities are pervasive in modern computing systems. Concurrency exploits include time-of-check-to-time-of-use (TOCTTOU) race conditions in file systems, attacks on signal handlers, and evasive malware that uses concurrency to escape sandboxing mechanisms. As processors feature ever more parallelism, and computers process more of our sensitive data, defending against concurrency attacks is a key challenge for the coming decade. The first goal is to protect legitimate applications from concurrency attacks when they access system resources (e.g., prevent TOCTTOU attacks on file accesses and exploitable race conditions in signal handlers). The objective is to provide application programmers with mechanisms and policies for synchronizing access to system resources so they can avoid unintentional vulnerabilities. The second goal is to provide strong confinement of untrusted code in the presence of concurrency, i.e., blocking intentionally malicious behavior. Today's malware abuses concurrency mechanisms to bypass and circumvent containment mechanisms like reference monitors and system call wrappers. Providing robust system support for containing malicious code is a critical challenge in intrusion detection and prevention. Modern computing systems fundamentally depend on concurrency for their performance and functionality. Making sure that concurrency is used securely is essential for building a trusted cyber infrastructure. This research will have a significant impact on the practical development of secure software, and enable security-critical applications to realize the performance benefits of today's highly parallel systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Rethinking the Fundamentals of Tunneling Technologies for Security, Privacy, and Usability
  • 批准号:
    2141547
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $46.66万
  • 财政年份:
    2022
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
Collaborative Research: CNS Core: Small: Internet-Scale Measurement of TCP/IP Implementation Weaknesses
  • 批准号:
    2007741
  • 项目类别:
    Standard Grant
  • 资助金额:
    $22.5万
  • 财政年份:
    2020
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
  • 批准号:
    2042795
  • 项目类别:
    Standard Grant
  • 资助金额:
    $6.64万
  • 财政年份:
    2020
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
SaTC: CORE: Medium: Collaborative: REVELARE: A Hardware-Supported Dynamic Information Flow Tracking Framework for IoT Security and Forensics
  • 批准号:
    1801613
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.97万
  • 财政年份:
    2018
  • 负责人:
    Jedidiah Crandall
  • 依托单位:
海外基金