课题基金 / 基金详情

SaTC: CORE: Small: Practical Whole Kernel Memory Safety Enforcement

SaTC: CORE: Small: Practical Whole Kernel Memory Safety Enforcement
SaTC:CORE:小型:实用的整个内核内存安全实施
批准号:
1718997
负责人:
Chengyu Song
金额:
$47.44万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-01 至 2022-07-31

项目摘要

项目成果

Chengyu Song的其他基金

相似基金

相关文献

中文摘要
翻译
操作系统(OS)内核是计算机系统的安全关键基础。不幸的是,Windows和Linux等商用操作系统的内核软件中的错误可能会让恶意攻击者接管整个系统。该研究项目正在开发新的技术,以消除某些类型的关键错误,从商业操作系统内核的方式,是数学上可证明的和有效的。研究人员正在开发一种独特的静态和动态技术的组合,以提供实用的空间内存安全的商业操作系统内核。这些技术包括一个新的类型系统,该系统保证每个内核模块的所有内存访问都在边界内,并且模块的功能允许相应的访问类型(读,写,执行)。这是通过在编译期间自动插入必要的运行时检查来实现的。由于这些新的检查会引入性能开销,因此该项目包含了额外的技术来减少开销。第一种优化方法是利用软件划分和模型检查来消除冗余检查。第二个优化是采用英特尔MPX(内存保护扩展),这是一种新的商用硬件功能,可降低运行时检查的成本。
英文摘要
The operating system (OS) kernel is the security-critical foundation of a computer system. Unfortunately, errors in the kernel software of commodity operating systems like Windows and Linux can allow a malicious attacker to take over the whole system. This research project is developing new techniques to eliminate certain types of critical errors from commodity OS kernels in a way that is both mathematically provable and efficient.The researchers are developing a unique combination of static and dynamic techniques to provide practical spatial memory safety for commodity OS kernels. These techniques include a new type system which guarantees that for every kernel module all its memory accesses are within bounds and the corresponding access type (read, write, execute) is allowed by the module's capabilities. This is achieved by automatically inserting necessary runtime checks during compilation. Since these new checks introduce performance overhead, the project includes additional techniques to reduce the overhead. The first optimization approach is utilizing software compartmentalization and model checking to eliminate redundant checks. The second optimization is adopting Intel MPX (memory protection extension), a new and commercially available hardware feature to reduce the cost of runtime checks.
期刊论文(11)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3394450.3397467
发表时间: 2020
期刊: Proceedings of the 4th ACM SIGPLAN International Workshop on Machine Learning and Programming Languages
影响因子: --
作者: [Patil, Mayur, Houshmand, Farzin, Lesani, Mohsen]
通讯作者: Lesani, Mohsen
DOI: 10.1109/sp46214.2022.9833661
发表时间: 2022-05
期刊: 2022 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者: [Xiao Li;F. Houshmand;M. Lesani]
通讯作者: Xiao Li;F. Houshmand;M. Lesani
Brief Announcement: Brokering with Hashed Timelock Contracts is NP-Hard
简短公告:使用散列时间锁合约进行经纪是 NP 难的
DOI: 10.1145/3465084.3467952
发表时间: 2021
期刊: PODC'21: Proceedings of the 2021 ACM Symposium on Principles of Distributed Computing
影响因子: --
作者: [Chan, Eric, Lesani, Mohsen]
通讯作者: Lesani, Mohsen
DOI: 10.1145/3274694.3274713
发表时间: 2018-12
期刊: Proceedings of the 34th Annual Computer Security Applications Conference
影响因子: --
作者: [M. L. Rahman;Ajaya Neupane;Chengyu Song]
通讯作者: M. L. Rahman;Ajaya Neupane;Chengyu Song
8
    CAREER: Scalable Concolic Execution
    • 批准号:
      2046026
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $54.48万
    • 财政年份:
      2021
    • 负责人:
      Chengyu Song
    • 依托单位:
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: