CAREER: Securing Applications From Compromised System Software
CAREER: Securing Applications From Compromised System Software
批准号:
1652280
负责人:
John Criswell
金额:
$51.24万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-04-01 至 2023-03-31
中文摘要
在理想的情况下,安全软件应该被构建为一组相互不信任的组件,这些组件协同工作以实现目标。然而,现代软件不是以这种方式构建的;相反,它非常信任称为操作系统内核的组件。幸运的是,有了新的方法来隔离程序之间以及与操作系统内核之间的隔离,以最大限度地减少攻击者破坏关键组件所造成的损害。然而,这样的解决方案速度太慢,而且容易受到复杂的隐式信息流攻击。此外,将使用正式验证技术来验证当前解决方案的有效性。该项目将开发新的技术来解决这些不足。它将调查新硬件机制的使用,这些机制将加快保护应用程序免受受危害的商用操作系统内核的影响。它将开发新的编译器转换,修改现有软件以不信任其他软件组件。它将设计新的静态信息流分析方法和运行时检查,以防止被攻击的操作系统内核窃取应用程序机密,并通过Iago攻击影响应用程序行为。最后,该项目将建立系统的正式模型,并证明它按预期保护软件。该项目将发布开源软件,以便这些技术和工具可以被其他研究人员使用,并能够找到实践的途径。在教育方面,操作系统设计人员的课程将包含设计人员正在构建操作系统时这类重要攻击的知识。
英文摘要
In an ideal world, secure software would be built as a set of mutually distrusting components that work together to accomplish goals. However, modern software is not built this way; rather, it heavily trusts a component called the operating system kernel. Fortunately, there are new methods of isolating programs from each other and from the OS kernel to minimize the damage caused if an attacker compromises a critical component. However, such solutions are too slow and are vulnerable to sophisticated implicit information flow attacks. Also, the effectiveness of current solutions will be verified using formal verification techniques.This project will develop new techniques to solve these deficiencies. It will investigate the use of new hardware mechanisms that will accelerate the protection of applications from compromised commodity operating system kernels. It will develop new compiler transformations that will modify existing software to distrust other software components. It will devise new static information flow analysis methods and run-time checks to keep compromised operating system kernels from stealing application secrets and influencing application behaviors through Iago attacks. Finally, the project will build a formal model of the system and prove that it protects software as intended. The project will release open source software so that the techniques and tools can be used by other researchers and can find their way into practice. Educationally, curriculum for OS designers will contain knowledge of this important class of attacks at the point that designers are building the OS.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Hardening Hypervisors with Ombro
使用 Ombro 强化虚拟机管理程序
DOI:
--
发表时间:
2022
期刊:
Usenix Security Symposium
影响因子:
--
作者:
[Johnson, Ethan, Pronovost, Colin, Criswell, John]
通讯作者:
Criswell, John
DOI:
--
发表时间:
2018
期刊:
ArXiv
影响因子:
--
作者:
[Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas]
通讯作者:
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas
DOI:
10.1145/3214292.3214297
发表时间:
2018-06
期刊:
Proceedings of the 7th International Workshop on Hardware and Architectural Support for Security and Privacy
影响因子:
--
作者:
[Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas]
通讯作者:
Xiaowan Dong;Zhuojia Shen;J. Criswell;A. Cox;S. Dwarkadas
DOI:
10.1145/3564625.3567970
发表时间:
2022-12
期刊:
Proceedings of the 38th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Zhuojia Shen;Komail Dharsee;J. Criswell]
通讯作者:
Zhuojia Shen;Komail Dharsee;J. Criswell
Collaborative Research: SaTC: CORE: Medium: Compiler-Assisted Embedded Security
-
批准号:2154322
-
项目类别:Standard Grant
-
资助金额:$58.55万
-
财政年份:2022
-
负责人:John Criswell
-
依托单位:
TWC: Small: Thwarting Kernel-Level Malware with Secure Virtual Architecture
-
批准号:1618213
-
项目类别:Standard Grant
-
资助金额:$47.51万
-
财政年份:2016
-
负责人:John Criswell
-
依托单位:
II-EN: Enhancing Secure Virtual Architecture for Advanced Operating System Research
-
批准号:1629770
-
项目类别:Standard Grant
-
资助金额:$49.32万
-
财政年份:2016
-
负责人:John Criswell
-
依托单位:
CRII: SaTC: Comprehensive and Automated Techniques for Evaluating Defenses Against Code Reuse Attacks
-
批准号:1463870
-
项目类别:Standard Grant
-
资助金额:$17.35万
-
财政年份:2015
-
负责人:John Criswell
-
依托单位:
海外基金