TWC: Small: Collaborative: EVADE: Evidence-Assisted Detection and Elimination of Security Vulnerabilities
TWC: Small: Collaborative: EVADE: Evidence-Assisted Detection and Elimination of Security Vulnerabilities
批准号:
1525888
负责人:
Emery Berger
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2018-08-31
中文摘要
今天的软件仍然容易受到攻击。尽管从测试到静态分析和验证的领域已经取得了几十年的进步,但所有大型实际软件的部署都存在错误。因为这些软件要么是用不安全的语言编写的,要么是由不安全的语言支撑的,所以错误常常转化为安全漏洞。尽管现有技术可以防止或限制漏洞利用的风险,但高性能开销阻碍了它们的采用,使当今的系统容易受到攻击。为了解决这些问题,我们提出了一种新的方法:证据辅助检测和消除安全漏洞(EVADE)。EVADE将防止安全漏洞危及系统。挑战和目标是使其在时间和空间上有效,并使其可用于部署。EVADE将为开发人员生成详细的报告,以减少修复应用程序所需的时间和精力。通过阻止大范围的攻击和自动精确定位漏洞,EVADE将大大提高运行在服务器和桌面平台上的应用软件的安全性,并将启用一类新的攻击后安全分析。该技术方法是一种新颖的方法,它跨越了运行时系统、操作系统和虚拟机的传统研究边界。EVADE将在一个协调的框架中运行未经修改的应用程序,该框架将在提交任何输出之前执行选择性的取证分析,阻止攻击者危及其主机,并使其能够以低开销查明错误。EVADE运行时系统将在内存中的随机位置放置轻量级的绊网,可以快速验证以检测恶意行为。在应用程序中,它们以签名的形式放置在堆栈和堆中,而在管理程序级别的EVADE中,它们可以保护系统调用表或其他关键数据结构。逃避虚拟机将把执行划分为增量检查点时期。在每个epoch边界,在提交任何系统状态之前,逃避虚拟机将向逃避运行时系统指示哪些页面已被修改,让它执行检查以识别漏洞。因此,EVADE将以极低的运行时开销极大地提高易受攻击应用程序的安全性,并将帮助开发人员在漏洞确实发生时定位漏洞。
英文摘要
Today's software remains vulnerable to attack. Despite decades of advances in areas ranging from testing to static analysis and verification, all large real-world software is deployed with errors. Because this software is either written in or underpinned by unsafe languages, errors often translate to security vulnerabilities. Although techniques exist that could prevent or limit the risk of exploits, high performance overhead blocks their adoption, leaving today's systems open to attack. To address these problems, we propose a new approach: evidence-assisted detection and elimination of security vulnerabilities (EVADE). EVADE will prevent security vulnerabilities from compromising a system . The challenge, and the goal, is to make it efficient in time and space, and to make it practical for deployment. EVADE will produce detailed reports for developers to reduce the time and effort required to fix their applications. By blocking a wide range of attacks and automatically pinpointing vulnerabilities, EVADE will dramatically increase the security of application software running on servers and desktop platforms, and it will enable a new class of post-attack security analyses.The technical approach is a novel one that spans the traditional research boundaries of runtime systems, operating systems, and virtual machines. EVADE will run unmodified applications in a coordinated framework that will perform selective forensic analysis before any output is committed, blocking exploits from compromising their host and making it possible to pinpoint errors with low overhead. The EVADE runtime system will place lightweight tripwires at random locations in memory that can be quickly validated to detect malicious behavior. Within an application, these take the form of signatures placed on the stack and in the heap, while at the hypervisor-level EVADE they may protect the system call table or other crucial data structures. The EVADE VM will divide execution into incrementally-checkpointed epochs. At each epoch boundary, before any system state is committed, the EVADE virtual machine will indicate to the EVADE runtime system which pages have been modified, letting it perform checks to identify vulnerabilities. EVADE will thus dramatically increase the security of vulnerable applications with extremely low runtime overhead, and will assist developers in locating vulnerabilities when an exploit does occur.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research:SHF:Medium:Bringing Python Up to Speed
-
批准号:1954830
-
项目类别:Standard Grant
-
资助金额:$37.71万
-
财政年份:2020
-
负责人:Emery Berger
-
依托单位:
SHF: Small: S3: Statistical and Structural Analysis for Spreadsheets
-
批准号:1617892
-
项目类别:Standard Grant
-
资助金额:$34.74万
-
财政年份:2016
-
负责人:Emery Berger
-
依托单位:
XPS: FULL: SDA: Collaborative Research: SCORE: Scalability-Oriented Optimization
-
批准号:1439008
-
项目类别:Standard Grant
-
资助金额:$64.8万
-
财政年份:2014
-
负责人:Emery Berger
-
依托单位:
EAGER: Data Debugging
-
批准号:1349784
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2013
-
负责人:Emery Berger
-
依托单位:
EAGER: Programming the Crowd
-
批准号:1144520
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2012
-
负责人:Emery Berger
-
依托单位:
SHF: Large: Collaborative Research: Reliable Performance for Modern Systems
-
批准号:1012195
-
项目类别:Continuing Grant
-
资助金额:$34.63万
-
财政年份:2010
-
负责人:Emery Berger
-
依托单位:
SHF: Large:Collaborative Research: PASS: Perpetually Available Software Systems
-
批准号:0910883
-
项目类别:Standard Grant
-
资助金额:$63.94万
-
财政年份:2009
-
负责人:Emery Berger
-
依托单位:
Probabilistically Correct Execution: Hardening Applications Against Error and Attack
-
批准号:0615211
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Emery Berger
-
依托单位:
CAREER: Cooperative System Support for Robust High Performance
-
批准号:0347339
-
项目类别:Continuing Grant
-
资助金额:$47.11万
-
财政年份:2004
-
负责人:Emery Berger
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: