CAREER: Rethinking Mobile Security in the New Age of App-As-A-Platform

职业:重新思考应用程序即平台新时代的移动安全

基本信息

  • 批准号:
    1748334
  • 负责人:
  • 金额:
    $ 50.05万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2017
  • 资助国家:
    美国
  • 起止时间:
    2017-08-01 至 2023-04-30
  • 项目状态:
    已结题

项目摘要

An ongoing evolution in the design of mobile applications (apps) and services, called "app-as-a-platform", is posing fundamental challenges to mobile security and privacy, exposing consumers, enterprises, and governments to new threats. Existing security technologies were not designed to address apps' emerging role as micro-platforms and are, therefore, incapable of providing sufficient protections. This research project is developing security foundations in three dimensions of app-as-a-platform architectures: (1) In-app Dimension, where modules within the same app can adversely affect or manipulate one another, (2) App-cloud Dimension, where apps may spy on or abuse integrated cloud services, and vice versa, and (3) App-IoT Dimension, where unauthorized apps can manipulate IoT (Internet-of-Things)-connected devices. This research project is investigating approaches to safeguard mobile apps' integration with third-party modules, cloud services, and IoT devices that are organized by app-as-a-platform architectures. The project is developing security foundations for these architectures by retrofitting mobile middleware and operating systems (OS) with new isolation, mediation, and attestation primitives and mechanisms. To establish a principled defense against threats to app-as-a-platform systems, the researchers are designing new OS abstractions for in-process memory isolation, language constructs for module-level security enforcement, trustworthy web integration mechanisms, remote attestation of mobile agents, and an IoT authorization and interoperation framework. The project also provides unique education and training opportunities for both graduate and undergraduate students.
移动应用程序(app)和服务的设计正在不断演变,被称为“应用程序即平台”(app-as-a-platform),这对移动安全和隐私构成了根本性的挑战,使消费者、企业和政府面临新的威胁。现有的安全技术并不是为了解决应用程序作为微平台的新兴角色而设计的,因此无法提供足够的保护。本研究项目在应用即平台架构的三个维度上开发安全基础:(1)应用内维度,同一应用内的模块可能会对彼此产生不利影响或操纵;(2)应用云维度,应用可能会监视或滥用集成的云服务,反之亦然;(3)应用物联网维度,未经授权的应用可以操纵物联网连接的设备。该研究项目旨在研究保护移动应用与第三方模块、云服务和物联网设备集成的方法,这些设备由应用即平台架构组织。该项目通过使用新的隔离、中介和认证原语和机制改造移动中间件和操作系统(OS),为这些体系结构开发安全基础。为了建立针对应用即平台系统威胁的原则性防御,研究人员正在设计新的操作系统抽象,用于进程内内存隔离,用于模块级安全执行的语言结构,可信赖的web集成机制,移动代理的远程认证以及物联网授权和互操作框架。该项目还为研究生和本科生提供了独特的教育和培训机会。

项目成果

期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface Modeling
P2IM:通过自动外设接口建模进行可扩展且独立于硬件的固件测试
OAT: Attesting Operation Integrity of Embedded Devices
SoK: Attacks on Industrial Control Logic and Formal Verification-Based Defenses
Secure Integration of Web Content and Applications on Commodity Mobile Operating Systems
D-Box: DMA-enabled Compartmentalization for Embedded Applications
  • DOI:
    10.14722/ndss.2022.24053
  • 发表时间:
    2022-01
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Alejandro Mera;Yi Hui Chen;Ruimin Sun;E. Kirda;Long Lu
  • 通讯作者:
    Alejandro Mera;Yi Hui Chen;Ruimin Sun;E. Kirda;Long Lu
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Long Lu其他文献

Atmospheric emission inventory of cadmium from anthropogenic sources. (SCI, IF=3.157(2011))
人为源镉的大气排放清单。
Effects of discharge power on the structural and optical properties of TGZO thin films prepared by RF magnetron sputtering technique
放电功率对射频磁控溅射TGZO薄膜结构和光学性能的影响
  • DOI:
    10.1007/s11801-016-5265-5
  • 发表时间:
    2016-05
  • 期刊:
  • 影响因子:
    0.9
  • 作者:
    Gu Jin-hua;Lu Zhou;Zhong Zhiyou;Long Lu;Long Hao
  • 通讯作者:
    Long Hao
Nanosized V-Ce Oxides Supported on TiO2 as a Superior Catalyst for the Selective Catalytic Reduction of NO
TiO2 负载的纳米 V-Ce 氧化物作为选择性催化还原 NO 的优异催化剂
  • DOI:
    10.3390/catal10020202
  • 发表时间:
    2020-02
  • 期刊:
  • 影响因子:
    3.9
  • 作者:
    Long Lu;Xueman Wang;Chunhua Hu;Ying Liu;Xiongbo Chen;Ping Fang;Dingsheng Chen;Chaoping Cen
  • 通讯作者:
    Chaoping Cen
Synthesis and Reactivity of a-Cumyl Bromodifluoromethanesulfenate: Application to the Radiosynthesis of [18F]ArylSCF3
α-溴二氟甲磺酸枯基酯的合成和反应性:在 [18F]ArylSCF3 放射合成中的应用
  • DOI:
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jiang Wu;Qunchao Zhao;Thomas C. Wilson;Stefan Verhoog;Long Lu;Veronique Gouverneur;Qilong Shen
  • 通讯作者:
    Qilong Shen
SCRUTINIZER: Detecting Code Reuse in Malware via Decompilation and Machine Learning
SCRUTINIZER:通过反编译和机器学习检测恶意软件中的代码重用

Long Lu的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Long Lu', 18)}}的其他基金

CAREER: Rethinking Mobile Security in the New Age of App-As-A-Platform
职业:重新思考应用程序即平台新时代的移动安全
  • 批准号:
    1652205
  • 财政年份:
    2017
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Continuing Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
  • 批准号:
    1748127
  • 财政年份:
    2017
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Standard Grant
TWC: Small: STRUCT: Enabling Secure and Trustworthy Compartments in Mobile Applications
TWC:小:STRUCT:在移动应用程序中启用安全且值得信赖的部分
  • 批准号:
    1800665
  • 财政年份:
    2017
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
  • 批准号:
    1514142
  • 财政年份:
    2015
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Standard Grant
TWC: Small: STRUCT: Enabling Secure and Trustworthy Compartments in Mobile Applications
TWC:小:STRUCT:在移动应用程序中启用安全且值得信赖的部分
  • 批准号:
    1421824
  • 财政年份:
    2014
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Standard Grant

相似海外基金

Care and Repair: Rethinking Contemporary Curation for Conditions of Crisis
护理与修复:重新思考危机条件下的当代策展
  • 批准号:
    DP240102206
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Discovery Projects
A Brave New World for Japanese Shakespeare Adaptations: Rethinking Shakespeare Studies through Adaptations
日本莎士比亚改编的美丽新世界:通过改编重新思考莎士比亚研究
  • 批准号:
    23K21920
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
PROTSENS Rethinking Alternative PROTein Extraction: Decoding SENsory-Protein Extraction Relationships
PROTSENS 重新思考替代性蛋白质提取:解码感觉-蛋白质提取关系
  • 批准号:
    EP/Z000785/1
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Fellowship
Caring Communities 1800-present: Rethinking Children's Social Care
关爱社区 1800 年至今:重新思考儿童的社会关怀
  • 批准号:
    MR/X034968/1
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Fellowship
Rethinking Mao’s China from a Global Economic Perspective: A History
从全球经济的角度重新思考毛泽东时代的中国:一段历史
  • 批准号:
    DE240100091
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Discovery Early Career Researcher Award
High-rise landscapes: The afterlives of tower block 'failure' and rethinking urban futures
高层景观:塔楼“失败”的后遗症和重新思考城市未来
  • 批准号:
    MR/Y003586/1
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Fellowship
CAREER: Rethinking Spiking Neural Networks from a Dynamical System Perspective
职业:从动态系统的角度重新思考尖峰神经网络
  • 批准号:
    2337646
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Continuing Grant
CAREER: A multimethod approach to rethinking the dynamics of inhibitory control under stress
职业生涯:重新思考压力下抑制控制动态的多种方法
  • 批准号:
    2338789
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Continuing Grant
CAREER: Rethinking System Stack for the Load-Store I/O Era
职业:重新思考加载-存储 I/O 时代的系统堆栈
  • 批准号:
    2339901
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Continuing Grant
Rethinking Antarctic Sea Level Projections (RASP)
重新思考南极海平面预测 (RASP)
  • 批准号:
    NE/Y001451/1
  • 财政年份:
    2024
  • 资助金额:
    $ 50.05万
  • 项目类别:
    Research Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了