CAREER: Automated Analysis of Security Hyperproperties
CAREER: Automated Analysis of Security Hyperproperties
批准号:
1553548
负责人:
Rohit Chadha
金额:
$43.6万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-07-01 至 2023-06-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Computer programs and cryptographic protocols are increasingly being used to access confidential and private information on the Internet. Due to their complex nature, they often have subtle errors that can be exploited by malicious entities. As security flaws can have serious consequences, it is important to ensure that computer programs and cryptographic protocols achieve their security objectives. As such systems have a large (potentially infinite) number of states due to presence of malicious adversaries and the concurrent nature of Internet, `pen and paper' reasoning about their correctness is challenging. In addition to the state explosion, reasoning about correctness is also challenging within the context of security because standard security objectives such as confidentiality and privacy turn out to be hyperproperties. The challenge lies in the fact that when reasoning about hyperproperties, one has to reason about correctness of the set of all executions of a system as a whole instead of correctness of individual executions. Therefore, the development of techniques to automate this reasoning is of vital importance, and is the research focus of this project. Formally, hyperproperties generalize properties that are used to express safety and liveness guarantees in classical automated verification. A property is a set of allowable executions. A system violates a property if it exhibits an execution that is not allowed. In contrast, security objectives such as confidentiality, non-interference, privacy, and anonymity are hyperproperties. A hyperproperty is a collection of allowable sets of executions. A system violates a hyperproperty if the set of its executions is not in the collection specified by the hyperproperty. Current state-of-the art automated tools for verifying security guarantees do not scale very well as they are often aimed at certain security guarantees and often make restrictive assumptions on the systems. This project aims to develop new scalable state-of-the-art techniques in automated verification of hyperproperties by undertaking primarily three research tasks. First, we will develop and implement new symbolic algorithms for verifying finite-state systems against an expressive set of hyperproperties. The second task shall be devoted to scaling the analysis by a novel combination of automated analysis and automated counterexample generation designed specifically for hyperproperties. Finally, we shall establish theoretical results that shall reduce the problem of verifying cryptographic protocols in the presence of unbounded message sizes and nonces to the finite case. The research aims of the proposal will be paired with curriculum development at the University of Missouri where a new concentration in security will be introduced in the undergraduate curriculum that will integrate security design with software development. The results of this project will be integrated in the courses, and the project will support both undergraduate and graduate student research.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Modelchecking Safety Properties in Randomized Security Protocols. In: Nigam V. et al. (eds) Logic, Language, and Security.
随机安全协议中的模型检查安全属性。
DOI:
10.1007/978-3-030-62077-6_12
发表时间:
2020
期刊:
and Security (Lecture Notes in Computer Science
影响因子:
--
作者:
[Matt S. Bauer, Rohit Chadha]
通讯作者:
Matt S. Bauer, Rohit Chadha
DOI:
10.1109/lics52264.2021.9470708
发表时间:
2021-04
期刊:
2021 36th Annual ACM/IEEE Symposium on Logic in Computer Science (LICS)
影响因子:
--
作者:
[Rohit Chadha;A. Sistla;Mahesh Viswanathan]
通讯作者:
Rohit Chadha;A. Sistla;Mahesh Viswanathan
DOI:
10.1145/3406089.3409029
发表时间:
2020
期刊:
Proceedings of the 5th ACM SIGPLAN International Workshop on Type-Driven Development
影响因子:
--
作者:
[Reynolds, Thomas, Harrison, William L., Chadha, Rohit, Allwein, Gerard]
通讯作者:
Allwein, Gerard
DOI:
10.1145/3434289
发表时间:
2020-11
期刊:
Proceedings of the ACM on Programming Languages
影响因子:
--
作者:
[G. Barthe;Rohit Chadha;Paul Krogmeier;A. Sistla;Mahesh Viswanathan]
通讯作者:
G. Barthe;Rohit Chadha;Paul Krogmeier;A. Sistla;Mahesh Viswanathan
DOI:
10.1145/3343508
发表时间:
2019-10
期刊:
ACM Transactions on Computational Logic (TOCL)
影响因子:
--
作者:
[G. Bana;Rohit Chadha]
通讯作者:
G. Bana;Rohit Chadha
共 6 条
SHF: Medium: Collaborative Research: Verification of Differential Privacy Mechanisms
-
批准号:1900924
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2019
-
负责人:Rohit Chadha
-
依托单位:
Conference Support for Midwest Verification Day, UMC Oct 3-4, 2014
-
批准号:1450406
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2014
-
负责人:Rohit Chadha
-
依托单位:
TWC: Medium: Collaborative: Automated Formal Analysis of Security Protocols with Private Coin Tosses
-
批准号:1314338
-
项目类别:Standard Grant
-
资助金额:$24.48万
-
财政年份:2013
-
负责人:Rohit Chadha
-
依托单位:
海外基金