CAREER: User-Space Protection Domains for Compositional Information Security
职业:组合信息安全的用户空间保护域
基本信息
- 批准号:1149211
- 负责人:
- 金额:$ 48.31万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2012
- 资助国家:美国
- 起止时间:2012-01-01 至 2016-03-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Attacks on software applications such as email readers and web browsers are common. These attacks can cause damages ranging from application malfunction, loss of private data, to a complete takeover of users' computers. One effective strategy for limiting the damage is to adopt the principle of least privilege in application design: the application is split into several protection domains and each domain is given only the necessary privileges to perform its task. In this design, the compromise of one domain does not directly lead to the compromise of other security-sensitive domains. The PI proposes to design and implement a framework that makes it easy for software developers to apply the principle of least privilege to their applications. The proposed framework will significantly improve the security of critical software applications. It will benefit the software industry by designing new technologies for building secure software systems.The proposed research combines several novel ideas: (1) user-space protection domains through binary-level enforcement of isolation and information-flow security; (2) a declarative language that allows for flexible configuration of an application's security architecture; (3) a binary-level partitioning tool that automatically splits an application into components of least privilege; (4) a compositional reasoning mechanism that allows developers to perform formal reasoning about an application's end-to-end information security. By staying in the user space, the proposed framework is OS independent, and by working on binary code, it is source-language agnostic, making it more broadly applicable. Developers can use it to partition an application, flexibly configure its security architecture, and reason about its information security. On the education side, the PI will organize a series of activities to increase high school students' awareness of security, privacy, and secure programming. The central activity is a summer workshop that gathers local high-school technology teachers and helps them design lesson plans that can be integrated into their schools' technology curriculum.
对电子邮件阅读器和Web浏览器等软件应用程序的攻击很常见。这些攻击可能会造成从应用程序故障、私人数据丢失到完全接管用户计算机的损害。 一个有效的策略是在应用程序设计中采用最小特权原则:将应用程序划分为几个保护域,每个域只被赋予执行其任务所需的特权。在这种设计中,一个域的危害不会直接导致其他安全敏感域的危害。 PI建议设计和实现一个框架,使软件开发人员能够轻松地将最小特权原则应用于他们的应用程序。拟议的框架将大大提高关键软件应用程序的安全性。该研究结合了几个新颖的思想:(1)通过二进制级别的隔离和信息流安全的实施来实现用户空间保护域;(2)允许灵活配置应用程序安全架构的声明性语言;(3)二进制级别的分区工具,自动将应用程序划分为最低权限的组件;(4)组合推理机制,允许开发人员对应用程序的端到端信息安全执行正式推理。 通过停留在用户空间中,所提出的框架是独立于操作系统的,并且通过处理二进制代码,它是源语言不可知的,使其具有更广泛的适用性。 开发人员可以使用它来划分应用程序,灵活地配置其安全架构,并考虑其信息安全性。 在教育方面,PI将组织一系列活动,以提高高中生的安全意识,隐私和安全编程。 中心活动是一个夏季研讨会,聚集当地高中技术教师,帮助他们设计可以融入学校技术课程的课程计划。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Gang Tan其他文献
Structural Optimization of Heat Sink for Thermoelectric Conversion Unit in Personal Comfort System
个人舒适系统热电转换单元散热器结构优化
- DOI:
10.3390/en15082781 - 发表时间:
2022-04 - 期刊:
- 影响因子:3.2
- 作者:
Wenping Xue;Xiao Cao;Guangfa Zhang;Gang Tan;Zilong Liu;Kangji Li - 通讯作者:
Kangji Li
A state of the art review on the prediction of building energy consumption using data-driven technique and evolutionary algorithms
使用数据驱动技术和进化算法预测建筑能耗的最新技术综述
- DOI:
10.1177/0143624419843647 - 发表时间:
2020-01 - 期刊:
- 影响因子:1.7
- 作者:
Kangji Li;Wenping Xue;Gang Tan;Anthony S Denzer - 通讯作者:
Anthony S Denzer
Certified Parsing of Dependent Regular Grammars
依赖正则语法的认证解析
- DOI:
10.1109/spw54247.2022.9833893 - 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
J. Sarracino;Gang Tan;Greg Morrisett - 通讯作者:
Greg Morrisett
Quantifying and Mitigating Cache Side Channel Leakage with Differential Set
使用差分集量化和减轻缓存侧通道泄漏
- DOI:
10.1145/3622850 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Cong Ma;Dinghao Wu;Gang Tan;M. Kandemir;Danfeng Zhang - 通讯作者:
Danfeng Zhang
Advances in icephobic coatings: Concepts, mechanisms, classifications and prospects
防冰涂层的进展:概念、机制、分类和前景
- DOI:
10.1016/j.coldregions.2025.104596 - 发表时间:
2025-11-01 - 期刊:
- 影响因子:3.800
- 作者:
Yanlong Zhan;Zhenqian Pang;Gang Tan - 通讯作者:
Gang Tan
Gang Tan的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Gang Tan', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Small: Detecting and Localizing Non-Functional Vulnerabilities in Machine Learning Libraries
协作研究:SaTC:核心:小型:检测和本地化机器学习库中的非功能性漏洞
- 批准号:
2230061 - 财政年份:2023
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Precise and Robust Binary Reverse Engineering and its Applications
SaTC:核心:小型:精确而鲁棒的二进制逆向工程及其应用
- 批准号:
2243632 - 财政年份:2023
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
CAPA: Collaborative Research: Lightweight Abstract Memory Features
CAPA:协作研究:轻量级抽象内存功能
- 批准号:
1723571 - 财政年份:2017
- 资助金额:
$ 48.31万 - 项目类别:
Continuing Grant
CAREER: User-Space Protection Domains for Compositional Information Security
职业:组合信息安全的用户空间保护域
- 批准号:
1624124 - 财政年份:2016
- 资助金额:
$ 48.31万 - 项目类别:
Continuing Grant
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
SHF:小型:协作研究:用于机器代码形式化建模的可重用工具
- 批准号:
1624125 - 财政年份:2016
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
TWC:中:协作:改进纵深防御软件
- 批准号:
1624126 - 财政年份:2016
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
TWC:中:协作:改进纵深防御软件
- 批准号:
1408826 - 财政年份:2014
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
SHF:小型:协作研究:用于机器代码形式化建模的可重用工具
- 批准号:
1217710 - 财政年份:2012
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
TC: Small: Collaborative Research: Securing Multilingual Software Systems
TC:小型:协作研究:保护多语言软件系统
- 批准号:
0915157 - 财政年份:2009
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
III-CXT-Small: Collaborative Research: Structuring, Reasoning, and Querying in a Very Large Medical Image Database
III-CXT-Small:协作研究:在超大型医学图像数据库中构建、推理和查询
- 批准号:
0812073 - 财政年份:2008
- 资助金额:
$ 48.31万 - 项目类别:
Continuing Grant
相似海外基金
CHS: Small: Investigating the Characteristics of User Representations and Long-Term Experiences in Personal Space Depth Perception in Virtual Reality
CHS:小:研究虚拟现实中个人空间深度感知的用户表征和长期体验的特征
- 批准号:
2007435 - 财政年份:2020
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
I-Corps Teams: IoT Sensor Networks Detecting User Behavior in Architectural Space
I-Corps 团队:物联网传感器网络检测建筑空间中的用户行为
- 批准号:
2011473 - 财政年份:2020
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
Contested Urban Street Space - Exploring the relationships between road user behaviour, walking and cycling infrastructure, and highway regulations
有争议的城市街道空间 - 探索道路使用者行为、步行和自行车基础设施以及高速公路法规之间的关系
- 批准号:
1938130 - 财政年份:2017
- 资助金额:
$ 48.31万 - 项目类别:
Studentship
CAREER: User-Space Protection Domains for Compositional Information Security
职业:组合信息安全的用户空间保护域
- 批准号:
1624124 - 财政年份:2016
- 资助金额:
$ 48.31万 - 项目类别:
Continuing Grant
SBIR Phase II: High-Speed TV-Band White Space Networks with Many-Antenna Multi-User Beamforming
SBIR 第二阶段:具有多天线多用户波束成形的高速电视频段空白空间网络
- 批准号:
1632565 - 财政年份:2016
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
SBIR Phase I: Tacet: High-Speed TV-Band White Space Networks with Implicit Multi-User Beamforming
SBIR 第一阶段:Tacet:具有隐式多用户波束成形的高速电视频段空白网络
- 批准号:
1520496 - 财政年份:2015
- 资助金额:
$ 48.31万 - 项目类别:
Standard Grant
Realization of information differentiation and user interest guidance in the information sharing virtual space that is information overload
在信息过载的信息共享虚拟空间中实现信息差异化和用户兴趣引导
- 批准号:
23700094 - 财政年份:2011
- 资助金额:
$ 48.31万 - 项目类别:
Grant-in-Aid for Young Scientists (B)
Improvement of usability and efficiency of user interface design by virtual manipulating space with tactile feedback
通过触觉反馈虚拟操纵空间提高用户界面设计的可用性和效率
- 批准号:
22300041 - 财政年份:2010
- 资助金额:
$ 48.31万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
A pervasive multi-user augmented space for mobile immersive interaction with sound and music
普遍存在的多用户增强空间,用于与声音和音乐进行移动沉浸式交互
- 批准号:
337999-2006 - 财政年份:2008
- 资助金额:
$ 48.31万 - 项目类别:
Strategic Projects - Group
A pervasive multi-user augmented space for mobile immersive interaction with sound and music
普遍存在的多用户增强空间,用于与声音和音乐进行移动沉浸式交互
- 批准号:
337999-2006 - 财政年份:2007
- 资助金额:
$ 48.31万 - 项目类别:
Strategic Projects - Group