课题基金 / 基金详情

TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software

TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software
TWC:媒介:协作:商品软件的自动逆向工程
批准号:
1409738
负责人:
Engin Kirda
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-09-01 至 2018-08-31

项目摘要

项目成果

Engin Kirda的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Software, including common examples such as commercial applications or embedded device firmware, is often delivered as closed-source binaries. While prior academic work has examined how to automatically discover vulnerabilities in binary software, and even how to automatically craft exploits for these vulnerabilities, the ability to answer basic security-relevant questions about closed-source software remains elusive.This project aims to provide algorithms and tools for answering these questions. Leveraging prior work on emulator-based dynamic analyses, we propose techniques for scaling this high-fidelity analysis to capture and extract whole-system behavior in the context of embedded device firmware and closed-source applications. Using a combination of dynamic execution traces collected from this analysis platform and binary code analysis techniques, we propose techniques for automated structural analysis of binary program artifacts, decomposing system and user-level programs into logical modules through inference of high-level semantic behavior. This decomposition provides as output an automatically learned description of the interfaces and information flows between each module at a sub-program granularity. Specific activities include: (a) developing software-guided whole-system emulator for supporting sophisticated dynamic analyses for real embedded systems; (b) developing advanced, automated techniques for structurally decomposing closed-source software into its constituent modules; (c) developing automated techniques for producing high-level summaries of whole system executions and software components; and (d) developing techniques for automating the reverse engineering and fuzz testing of encrypted network protocols. The research proposed herein will have a significant impact outside of the security research community. We will incorporate the research findings of our program into our undergraduate and graduate teaching curricula, as well as in extracurricular educational efforts such as Capture-the-Flag that have broad outreach in the greater Boston and Atlanta metropolitan areas.The close ties to industry that the collective PIs possess will facilitate transitioning the research into practical defensive tools that can be deployed into real-world systems and networks.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: EAGER: Understanding User Needs for Access Control Systems in Smart Settings
  • 批准号:
    2219921
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.0万
  • 财政年份:
    2022
  • 负责人:
    Engin Kirda
  • 依托单位:
Collaborative Research: SaTC: CORE: Small: Flanker: Automatically Detecting Lateral Movement in Organizations Using Heterogeneous Data and Graph Representation Learning
  • 批准号:
    2127200
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.99万
  • 财政年份:
    2021
  • 负责人:
    Engin Kirda
  • 依托单位:
Collaborative Research: SaTC: CORE: Medium: Rethinking Fuzzing for Security
  • 批准号:
    2031390
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.98万
  • 财政年份:
    2020
  • 负责人:
    Engin Kirda
  • 依托单位:
SaTC: CORE: Medium: Collaborative: Taming Web Content Through Automated Reduction in Browser Functionality
  • 批准号:
    1703454
  • 项目类别:
    Standard Grant
  • 资助金额:
    $38.71万
  • 财政年份:
    2017
  • 负责人:
    Engin Kirda
  • 依托单位:
海外基金