课题基金 / 基金详情

CRII: SaTC: Comprehensive and Automated Techniques for Evaluating Defenses Against Code Reuse Attacks

CRII: SaTC: Comprehensive and Automated Techniques for Evaluating Defenses Against Code Reuse Attacks
CRII:SaTC:用于评估代码重用攻击防御的综合自动化技术
批准号:
1463870
负责人:
John Criswell
金额:
$17.35万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-07-01 至 2019-06-30

项目摘要

项目成果

John Criswell的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Modern society relies on computers to manage and transmit sensitive data. These computers run our banks, provide our telecommunications services (such as phone, TV, and Internet), and operate critical systems found in automobiles and power grids. The software on these systems is vulnerable to automated attacks and, if attacked successfully, can be used to cause the loss of money, property, and life. While researchers have developed automated, easy-to-use countermeasures to thwart such attacks, it is unclear whether these countermeasures work. Existing evaluations of such countermeasures are typically expensive because they are done by hand. They are also often wrong; attackers are able to defeat such countermeasures by increasing the sophistication of their attacks. If we do not know how well our defenses work, we do not know if we are safe.One common type of automated attack is the code reuse attack. This research investigates techniques and develops a tool that automatically determines whether a given countermeasure prevents code reuse attacks from working. This tool uses comprehensive static analysis to automatically determine which program instructions a code reuse attack may employ, whether the malicious computations of an attack can be mapped to those instructions, and whether the defense being analyzed prevents those instructions from being executed in the required order. The tool is automated and its static analysis is designed to aggressively consider all potential ways in which an attacker can reuse code in an attack. With this tool, users can determine whether existing defenses suffice to protect our computers or whether additional defenses are necessary. The project is developing metrics to enable tool users to compare defenses and state the level of security that a defense provides to a given program.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Compiler-Assisted Embedded Security
  • 批准号:
    2154322
  • 项目类别:
    Standard Grant
  • 资助金额:
    $58.55万
  • 财政年份:
    2022
  • 负责人:
    John Criswell
  • 依托单位:
CAREER: Securing Applications From Compromised System Software
  • 批准号:
    1652280
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $51.24万
  • 财政年份:
    2017
  • 负责人:
    John Criswell
  • 依托单位:
TWC: Small: Thwarting Kernel-Level Malware with Secure Virtual Architecture
  • 批准号:
    1618213
  • 项目类别:
    Standard Grant
  • 资助金额:
    $47.51万
  • 财政年份:
    2016
  • 负责人:
    John Criswell
  • 依托单位:
II-EN: Enhancing Secure Virtual Architecture for Advanced Operating System Research
  • 批准号:
    1629770
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.32万
  • 财政年份:
    2016
  • 负责人:
    John Criswell
  • 依托单位:
海外基金