课题基金 / 基金详情

TC: Small: Mining Operating System Semantics: Techniques and Applications

TC: Small: Mining Operating System Semantics: Techniques and Applications
TC:小型:挖矿操作系统语义:技术和应用
批准号:
1018217
负责人:
Heng Yin
金额:
$42.7万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-08-01 至 2014-07-31

项目摘要

项目成果

Heng Yin的其他基金

相似基金

相关文献

中文摘要
翻译
关于操作系统语义的知识是许多安全应用程序的基础,包括虚拟机自省、恶意软件检测和分析、计算机取证等。然而,现有的提取操作系统语义的技术存在不足。它们对操作系统源代码执行静态分析,因此不能应用于闭源操作系统。源代码分析也受到“所见即所得”(即,所见即所得)问题的困扰。此外,获得的语义知识很容易受到各种内核攻击的破坏。有了这样一个不健全的基础,这些安全应用程序的功能和可信度就变得值得怀疑。为了巩固这个基础,PI旨在构建一个以二进制为中心的健壮的分析框架,用于提取操作系统语义。它是以二进制为中心的,因为它可以从OS内核的二进制代码中提取语义信息。因此,WYSINWYX问题可以得到解决,并且可以克服闭源操作系统的语义障碍。它是健壮的,因为它可以捕获操作系统级语义中的不变量。因此,可以从这些不变量中获得可信的语义知识,从而检测出各种伪造攻击。然后,在此框架下,将进行进一步的研究,以研究如何加强各种安全应用程序的功能和健壮性。拟议的任务将导致发布原型系统和编制本科和研究生课程以及专业培训课程的教育材料。
英文摘要
The knowledge about operating system semantics is the foundation for many security applications, including virtual machine introspection, malware detection and analysis, computer forensics, etc. However, the existing techniques for extracting operating system semantics fall short. They perform static analysis on the OS source code, and thus cannot be applied to the closed-source operating systems. The source-code analysis also suffers from the WYSINWYX (i.e., What You See Is Not What You eXecute) problem. Furthermore, the obtained semantics knowledge can be easily compromised by various kernel attacks. With such an unsound foundation, the functionality and trustworthiness of these security applications become questionable.To fortify this foundation, the PI aims to build a binary-centric and robust analysis framework for extracting operating system semantics. It is binary-centric, because it can extract semantics information from the binary code of an OS kernel. Consequently, the WYSINWYX problem can be solved and the semantics barrier of closed-source operating systems can be overcome. It is robust, because it can capture the invariants in OS-level semantics. So trustworthy semantics knowledge can be derived from these invariants, and various forgery attacks can be detected. Then with this framework, further research will be conducted to investigate how the functionality and robustness of various security applications can be strengthen. The proposed tasks will lead to the release of prototype systems and the development of education materials for undergraduate and graduate courses and for professional training sessions.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Concolic-Execution-Centric Fuzzing
  • 批准号:
    2133487
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Heng Yin
  • 依托单位:
SaTC: CORE: Small: Towards Robust and Scalable Search of Binary Code and Data
  • 批准号:
    1719175
  • 项目类别:
    Standard Grant
  • 资助金额:
    $47.68万
  • 财政年份:
    2017
  • 负责人:
    Heng Yin
  • 依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
  • 批准号:
    1664315
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $16.89万
  • 财政年份:
    2016
  • 负责人:
    Heng Yin
  • 依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
  • 批准号:
    1054605
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $54.95万
  • 财政年份:
    2011
  • 负责人:
    Heng Yin
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: