TWC: Small: Provably Enforcing Practical Multi-Layer Policies in Today's Extensible Software Platforms
TWC: Small: Provably Enforcing Practical Multi-Layer Policies in Today's Extensible Software Platforms
批准号:
1320470
负责人:
Limin Jia
金额:
$48.53万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-09-01 至 2018-08-31
中文摘要
现代个人计算的定义特征是朝向可扩展平台的趋势(例如,智能手机和平板电脑),运行大量的专业应用程序,许多质量或出处不确定。这些平台上可用的常见安全机制是应用程序隔离和权限系统。 不幸的是,事实一再表明,这些机制无法防止一系列不当行为,包括恶意升级攻击和信息流泄漏。 研究人员已经提出了对这些平台的信息流保护。然而,这样的机制很少被采用在实践中,部分原因是抽象的水平,他们允许政策被指定。我们开发了一个正式的,案例研究驱动的方法,将利用信息流研究的进展,开发新的政策规范语言和执法机制,为今天的可扩展环境。 首先,我们开发适当的策略规范语言,允许在抽象的中间级别指定策略。 策略规范将足够容易理解和制定,以便于大多数开发人员访问,同时具有足够的表达能力来支持丰富的策略。 第二,我们开发混合执行机制,以支持在抽象级别上指定的策略,这些抽象级别不会整齐地重叠平台提供的隔离边界。 第三,机制的正确性将得到形式化模型和证明的支持。 为了保持基础并确保实际相关性,我们将工作重点放在两个应用领域:Android操作系统和Chromium Web浏览器。
英文摘要
A defining characteristic of modern personal computing is the trend towards extensible platforms (e.g., smartphones and tablets) that run a large number of specialized applications, many of uncertain quality or provenance. The common security mechanisms available on these platforms are application isolation and permission systems. Unfortunately, it has been repeatedly shown that these mechanisms fail to prevent a range of misbehaviors, including privilege-escalation attacks and information-flow leakage. Researchers have proposed information-flow protections for these platforms. However, such mechanisms have rarely been adopted in practice, partly due to the level of abstraction at which they allow policies to be specified.We develop a formal, case-study-driven approach that will leverage advances in information-flow research to develop new policy-specification languages and enforcement mechanisms for today's extensible environments. First, we develop appropriate policy-specification languages that allow policies to be specified at an intermediate level of abstraction. Policy specification will be easy enough to understand and formulate to be accessible to most developers, yet sufficiently expressive to support rich policies. Second, we develop hybrid enforcement mechanisms to support policy that is specified at levels of abstraction that do not neatly overlap isolation boundaries provided by the platform. Third, the correctness of the mechanisms will be supported by formal models and proofs. To remain grounded and ensure practical relevance, we focus our work on two application domains: the Android operating system, and, secondarily, the Chromium web browser.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Student Travel Grant for the Programming Languages Mentoring Workshop at ACM SIGPLAN Conference on Programming Language Design and Implementation (PLMW@PLDI), 2023-2025
-
批准号:2310964
-
项目类别:Standard Grant
-
资助金额:$4.51万
-
财政年份:2023
-
负责人:Limin Jia
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Hyperproperty-based Enforcement of Information-flow Security
-
批准号:2245115
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2023
-
负责人:Limin Jia
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Toward safe, private, and secure home automation: from formal modeling to user evaluation
-
批准号:2114148
-
项目类别:Standard Grant
-
资助金额:$85.56万
-
财政年份:2021
-
负责人:Limin Jia
-
依托单位:
NSF Student Travel Grant for 2019 IEEE Computer Security Foundations Symposium (CSF19)
-
批准号:1901636
-
项目类别:Standard Grant
-
资助金额:$1.2万
-
财政年份:2019
-
负责人:Limin Jia
-
依托单位:
SaTC: CORE: Medium: Towards a Usable, Practical, and Provably Secure Browser Infrastructure
-
批准号:1704542
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2017
-
负责人:Limin Jia
-
依托单位:
NeTS: Medium: Collaborative Research: DEFIND: DEclarative Formal Interactive Network Design
-
批准号:1513961
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2015
-
负责人:Limin Jia
-
依托单位:
SHF:Small:Collaborative Research: Compositional Verification of Heterogeneous Software Protocol Stacks
-
批准号:1422705
-
项目类别:Standard Grant
-
资助金额:$24.7万
-
财政年份:2014
-
负责人:Limin Jia
-
依托单位:
TC: Small: Collaborative Research: Towards a Formal Framework for Analyzing and Implementing Secure Routing Protocols
-
批准号:1115706
-
项目类别:Standard Grant
-
资助金额:$29.93万
-
财政年份:2011
-
负责人:Limin Jia
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: