CRII: SaTC: Detecting Security Vulnerabilities in Instruction Set Architectures
CRII: SaTC: Detecting Security Vulnerabilities in Instruction Set Architectures
批准号:
1464209
负责人:
Cynthia Sturton
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-05-15 至 2017-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The interaction between computer processors -- the hardware at the heart of our computers, tablets, and phones -- and software -- apps, web browsers, and other applications -- is governed by an Instruction Set Architecture (ISA). The ISA is the specification that defines how the processor will respond to commands from the software. It is large and complex, too large for a person to understand and reason about all the interactions between different parts completely. As a result, security vulnerabilities exist in the ISA. These vulnerabilities can sometimes be exploited by attackers to steal data or take control of the machine. This research is about detecting security vulnerabilities that exist in the ISA. Finding and removing these vulnerabilities will create a more secure foundation for all our computing activities. This will benefit government agencies that require high assurance environments, cloud providers that rely on hardware features for the security for their service, and users who, more and more, are relying on diverse hardware components from a variety of hardware design companies to handle their private and sensitive data.The researchers posit that vulnerabilities in the ISA happen in one of two ways: 1) Erroneous specification: the ISA prescribes behavior that is dangerous; or 2) Nondeterminism in the specification: the ISA is incomplete and one of the possible behaviors allowed by the specification is dangerous. The hypothesis of this research is that it is possible to focus on a relatively small subset of the ISA for which these types of errors are likely to occur. The researchers are developing a practical methodology for discovering for which instructions vulnerabilities are most likely to occur. With that information, they are developing tools to detect and correct security-critical errors in the ISA. In addition to making a practical contribution, the research activities are improving understanding in the computer science community of what a vulnerability in an ISA looks like and where and under what conditions it is likely to occur. This will enable future verification efforts to concentrate on the most security-critical aspects of the ISA.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
-
批准号:2247754
-
项目类别:Continuing Grant
-
资助金额:$57.1万
-
财政年份:2023
-
负责人:Cynthia Sturton
-
依托单位:
SaTC: STARSS: Small: Tackling the Corner Cases: Finding Security Vulnerabilities in CPU Designs
-
批准号:1816637
-
项目类别:Standard Grant
-
资助金额:$33.33万
-
财政年份:2018
-
负责人:Cynthia Sturton
-
依托单位:
EAGER: Identifying Security Critical Properties of a Processor
-
批准号:1651276
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2016
-
负责人:Cynthia Sturton
-
依托单位:
CPS: Frontier: Collaborative Research: VeHICaL: Verified Human Interfaces, Control, and Learning for Semi-Autonomous Systems
-
批准号:1544924
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Cynthia Sturton
-
依托单位:
海外基金