TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
TWC:中:协作:改进纵深防御软件
基本信息
- 批准号:1408880
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2014
- 资助国家:美国
- 起止时间:2014-09-01 至 2019-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The computer security community has long advocated the concept of building multiple layers of defense to protect a system. Unfortunately, it has been difficult to realize this vision in the practice of software development, and software often ships with inadequate defenses, typically developed in an ad hoc fashion.Developers face a number of challenges when protecting a software system with multiple layers of defense. They lack holistic frameworks in which to express policies and mechanisms for different software layers, automated tools to add these defenses, and tools to prove that software enhanced with defenses has an advertised level of assurance.This project develops new techniques to retrofit software for defense in depth. It takes a comprehensive view of the problem, with an emphasis on automated, interactive tools that developers can use to identify site-level security goals, explore the design space of adding security mechanisms, and retrofit legacy code to enforce security policies in a manner that can be machine-verified for assurance. The project develops theory and tools for formal policy language design and validation, static and dynamic code analyses, interactive tools for developers to explore the design space of security, functionality and performance tradeoffs, and methods to formally verify the correctness of program transformations to introduce defenses such as authorization, attacker containment, and auditing mechanisms.The broader impact stems from the improved security of systems and the reduced cost of achieving better security, also education activities in the form of summer schools for graduate, undergraduate and high-school students. The tools developed will be released to the public domain, benefiting software developers in the field.
计算机安全社区长期以来一直提倡构建多层防御来保护系统的概念。 不幸的是,在软件开发实践中很难实现这一愿景,并且软件通常没有足够的防御措施,通常是以临时方式开发的。开发人员在使用多层防御保护软件系统时面临着许多挑战。他们缺乏表达不同软件层的策略和机制的整体框架,缺乏添加这些防御的自动化工具,以及证明通过防御增强的软件具有宣传的保证水平的工具。该项目开发了新技术来改造软件以实现深度防御。它对问题进行了全面的审视,重点是自动化、交互式工具,开发人员可以使用这些工具来识别站点级安全目标,探索添加安全机制的设计空间,并改造遗留代码以通过机器验证的方式强制执行安全策略以确保安全。该项目开发用于正式策略语言设计和验证、静态和动态代码分析的理论和工具,供开发人员探索安全、功能和性能权衡设计空间的交互式工具,以及形式验证程序转换正确性的方法,以引入授权、攻击者遏制和审计机制等防御措施。更广泛的影响源于系统安全性的提高和实现更好安全性的成本的降低,以及夏季形式的教育活动 研究生、本科生和高中生的学校。开发的工具将发布到公共领域,使该领域的软件开发人员受益。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Trent Jaeger其他文献
Practical Integrity Validation in the Smart Home with HomeEndorser
使用 HomeEndorser 在智能家居中进行实用的完整性验证
- DOI:
10.1145/3643833.3656116 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Kaushal Kafle;Kirti Jagtap;Mansoor Ahmed;Trent Jaeger;Adwait Nadkarni - 通讯作者:
Adwait Nadkarni
Don’t Waste My Efforts: Pruning Redundant Sanitizer Checks of Developer-Implemented Type Checks
不要浪费我的努力:修剪开发人员实现的类型检查的冗余消毒剂检查
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
Yizhuo Zhai;Zhiyun Qian;Chengyu Song;Manu Sridharan;Trent Jaeger;Paul L. Yu;S. Krishnamurthy - 通讯作者:
S. Krishnamurthy
Countering unauthorized code execution on commodity kernels: A survey of common interfaces allowing kernel code modification
- DOI:
10.1016/j.cose.2011.09.003 - 发表时间:
2011-11-01 - 期刊:
- 影响因子:
- 作者:
Trent Jaeger;Paul C. van Oorschot;Glenn Wurster - 通讯作者:
Glenn Wurster
Trent Jaeger的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Trent Jaeger', 18)}}的其他基金
SaTC: CORE: Small: Information Flow Control Infrastructure for Single-Use Service Platforms
SaTC:核心:小型:一次性服务平台的信息流控制基础设施
- 批准号:
1816282 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
SaTC:核心:中:协作:威胁感知防御:评估威胁以持续改进
- 批准号:
1801534 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Trusted Infrastructure Workshop 2013
2013 年可信基础设施研讨会
- 批准号:
1313027 - 财政年份:2013
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TC: Small: Towards Customer-Centric Utility Computing
TC:小型:迈向以客户为中心的效用计算
- 批准号:
1117692 - 财政年份:2011
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
TC: Medium: Collaborative Research: Techniques to Retrofit Legacy Code with Security
TC:媒介:协作研究:安全改造遗留代码的技术
- 批准号:
0905343 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CPS:Small:Collaborative Research:Establishing Integrity in Dynamic Networks of Cyber Physical Devices
CPS:小型:协作研究:在信息物理设备动态网络中建立完整性
- 批准号:
0931914 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CT-IS: Shamon: Systems Approaches for Constructing Distributed Trust
CT-IS:Shamon:构建分布式信任的系统方法
- 批准号:
0627551 - 财政年份:2006
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
相似海外基金
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1840790 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
- 批准号:
1937622 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
- 批准号:
1855391 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
- 批准号:
1854000 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
- 批准号:
1929901 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
- 批准号:
1801986 - 财政年份:2017
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1564104 - 财政年份:2016
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
- 批准号:
1562888 - 财政年份:2016
- 资助金额:
$ 30万 - 项目类别:
Standard Grant














{{item.name}}会员




