TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems
TC:媒介:协作研究:确保现代系统中的并发性
基本信息
- 批准号:0905602
- 负责人:
- 金额:$ 80万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2009
- 资助国家:美国
- 起止时间:2009-09-01 至 2013-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).Concurrency-related vulnerabilities are pervasive in modern computingsystems. Concurrency exploits include time-of-check-to-time-of-use(TOCTTOU) race conditions in file systems, attacks on signal handlers,and evasive malware that uses concurrency to escape sandboxingmechanisms. As processors feature ever more parallelism, andcomputers process more of our sensitive data, defending againstconcurrency attacks is a key challenge for the coming decade.The first goal is to protect legitimate applications from concurrencyattacks when they access system resources (e.g., prevent TOCTTOUattacks on file accesses and exploitable race conditions in signalhandlers). The objective is to provide application programmers withmechanisms and policies for synchronizing access to system resourcesso they can avoid unintentional vulnerabilities.The second goal is to provide strong confinement of untrusted code inthe presence of concurrency, i.e., blocking intentionally maliciousbehavior. Today's malware abuses concurrency mechanisms to bypass andcircumvent containment mechanisms like reference monitors and systemcall wrappers. Providing robust system support for containingmalicious code is a critical challenge in intrusion detection andprevention.Modern computing systems fundamentally depend on concurrency for theirperformance and functionality. Making sure that concurrency is usedsecurely is essential for building a trusted cyber infrastructure.This research will have a significant impact on the practicaldevelopment of secure software, and enable security-criticalapplications to realize the performance benefits of today's highlyparallel systems.
该奖项是根据2009年美国复苏和再投资法案(公法111-5)资助的。与并发相关的漏洞在现代计算系统中普遍存在。并发攻击包括文件系统中的检查时间到使用时间(TOCTTOU)争用条件、对信号处理程序的攻击以及使用并发来逃避沙箱机制的躲避恶意软件。随着处理器的并行性越来越强,计算机处理的敏感数据越来越多,防御并发攻击是未来十年的关键挑战。第一个目标是保护合法应用程序在访问系统资源时免受并发攻击(例如,防止对文件访问的TOCTTOU攻击和信号处理程序中可利用的竞争条件)。其目的是为应用程序程序员提供同步访问系统资源的机制和策略,以便他们可以避免无意的漏洞。第二个目标是在存在并发的情况下提供对不可信代码的严格限制,即故意阻止恶意行为。今天的恶意软件滥用并发机制来绕过和绕过引用监视器和系统调用包装等遏制机制。为遏制恶意代码提供可靠的系统支持是入侵检测和防御中的一个关键挑战。现代计算系统的性能和功能基本上依赖于并发性。确保并发的安全使用对构建可信的网络基础设施至关重要,这项研究将对安全软件的实际开发产生重大影响,并使安全关键应用程序能够实现当今高度并行系统的性能优势。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Emmett Witchel其他文献
Ingens: Huge Page Support for the OS and Hypervisor
Ingens:操作系统和虚拟机管理程序的大页面支持
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Youngjin Kwon;Hangchen Yu;Simon Peter;Christopher J. Rossbach;Emmett Witchel - 通讯作者:
Emmett Witchel
CARVE: A Cognitive Agent for Resource Value Estimation
CARVE:资源价值估算的认知代理
- DOI:
- 发表时间:
2008 - 期刊:
- 影响因子:0
- 作者:
Jonathan Wildstrom;P. Stone;Emmett Witchel - 通讯作者:
Emmett Witchel
Turn Your Storage Stack into a File System
将您的存储堆栈变成文件系统
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Youngjin Kwon;Henrique Fingler;Simon Peter;Emmett Witchel - 通讯作者:
Emmett Witchel
Mondriaan Memory Protection
- DOI:
- 发表时间:
2004 - 期刊:
- 影响因子:0
- 作者:
Emmett Witchel - 通讯作者:
Emmett Witchel
Improving server applications with system transactions
通过系统事务改进服务器应用程序
- DOI:
10.1145/2168836.2168839 - 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
Sangman Kim;Michael Z. Lee;Alan M. Dunn;O. S. Hofmann;Xuan Wang;Emmett Witchel;Donald E. Porter - 通讯作者:
Donald E. Porter
Emmett Witchel的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Emmett Witchel', 18)}}的其他基金
CNS Core: Small: Operating Systems Abstractions for Serverless Computing
CNS 核心:小型:无服务器计算的操作系统抽象
- 批准号:
2008321 - 财政年份:2020
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
XPS:CLCCA:Collaborative Research:Harnessing Highly Threaded Hardware for Server Workloads
XPS:CLCCA:协作研究:利用高线程硬件处理服务器工作负载
- 批准号:
1333594 - 财政年份:2013
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Trustworthy Programs Without A Trustworthy Operating System
TWC:媒介:协作:无需可信操作系统的可信程序
- 批准号:
1228843 - 财政年份:2012
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
CSR: Small: Operating System Abstractions for GPU-Accelerated Interactive Applications
CSR:小型:GPU 加速的交互式应用程序的操作系统抽象
- 批准号:
1017785 - 财政年份:2010
- 资助金额:
$ 80万 - 项目类别:
Continuing Grant
CAREER: Operating System Support For Transactional Memory: Construction and Performance Scalability of Parallel Programs
职业:操作系统对事务内存的支持:并行程序的构造和性能可扩展性
- 批准号:
0644205 - 财政年份:2007
- 资助金额:
$ 80万 - 项目类别:
Continuing Grant
CSR--PDOS: Autonomic Systems: Integrating Machine Learning with Computer Systems
CSR--PDOS:自主系统:机器学习与计算机系统的集成
- 批准号:
0615104 - 财政年份:2006
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
相似海外基金
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1630037 - 财政年份:2015
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064646 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064944 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065216 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
- 批准号:
1065130 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Securing Web Advertisements: Fixing the Short-term Crisis and Addressing Long-term Challenges
TC:媒介:协作研究:保护网络广告:解决短期危机并应对长期挑战
- 批准号:
1065537 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Program Analysis for Smartphone Application Security
TC:媒介:协作研究:智能手机应用程序安全的程序分析
- 批准号:
1064844 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Tracking Adversarial Behavior in Distributed Systems with Secure Networked Provenance
TC:中:协作研究:通过安全网络来源跟踪分布式系统中的对抗行为
- 批准号:
1064986 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Building Trustworthy Applications for Mobile Devices
TC:媒介:协作研究:为移动设备构建值得信赖的应用程序
- 批准号:
1064900 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Random Number Generation and Use in Virtualized Environments
TC:媒介:协作研究:虚拟化环境中的随机数生成和使用
- 批准号:
1065288 - 财政年份:2011
- 资助金额:
$ 80万 - 项目类别:
Standard Grant