课题基金 / 基金详情

TWC: Small: Caging Libraries To Control Software Faults

TWC: Small: Caging Libraries To Control Software Faults
TWC:小型:用笼子库来控制软件故障
批准号:
1223588
负责人:
Justin Cappos
金额:
$49.99万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-09-01 至 2016-08-31

项目摘要

项目成果

Justin Cappos的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The vast majority of the code in most applications comes from the libraries it imports, rather than the program itself. As a result, hackers often exploit flaws in libraries like glibc or openssl that are used across multiple applications instead of attacking individual flaws in code specific to the application. This makes it easier for an attacker to compromise many applications at once with a single exploit. This work isolates the impact of flaws in a deployed program into the smallest area possible. This will dramatically increase the security of applications in the cloud, on mobile phones, and everything in between.To achieve this goal, this research develops a new abstraction that acts as a lightweight and extremely efficient intra-process isolation mechanism that builds on recent advances from operating system virtualization and memory-safe code execution (such as SFI). This abstraction, called a cage, allows different pieces of code that execute in the same process to be isolated from each other. This means that a flaw within a piece of code can only be used to exploit the code within that cage. Each cage also conceptually is its own process from an resource accounting standpoint. In addition, calls between cages are extremely lightweight and do not require a context switch or OS intervention. The cage abstraction provides an isolation mechanism that is high-performance and with very low overhead while improving application security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: TTP: Medium: Defending the Supply Chain of Democracy: Towards a Cryptographically Verified and Authenticated Network of Laws
  • 批准号:
    2247829
  • 项目类别:
    Standard Grant
  • 资助金额:
    $68.76万
  • 财政年份:
    2023
  • 负责人:
    Justin Cappos
  • 依托单位:
SaTC: TTP: Medium: Securing Python's Software Supply Chain
  • 批准号:
    2054692
  • 项目类别:
    Standard Grant
  • 资助金额:
    $80.0万
  • 财政年份:
    2021
  • 负责人:
    Justin Cappos
  • 依托单位:
ASPIRE: An SFS Program for Interdisciplinary Research and Education (Renewal)
  • 批准号:
    1922291
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $483.05万
  • 财政年份:
    2019
  • 负责人:
    Justin Cappos
  • 依托单位:
SaTC: TTP: Medium: Collaborative: Securing the Software Supply Chain
  • 批准号:
    1801376
  • 项目类别:
    Standard Grant
  • 资助金额:
    $76.6万
  • 财政年份:
    2018
  • 负责人:
    Justin Cappos
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: