CAREER: Principled and Practical Software Shielding against Advanced Exploits
CAREER: Principled and Practical Software Shielding against Advanced Exploits
批准号:
1749895
负责人:
Michail Polychronakis
金额:
$49.99万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-06-01 至 2024-11-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The exploitation of memory corruption vulnerabilities in popular software is among the leading causes of system compromise and malware infection. While there are several reasons behind this proliferation of exploitable bugs, the reliance on unsafe programming languages such as C and C++ and the complexity of modern software play a major role. The continuous discovery of previously unknown (zero-day) vulnerabilities in browsers, document viewers, and other widely used software, and the lack of effective defenses against recent exploitation techniques that leverage memory disclosure vulnerabilities, necessitate the development of additional defense mechanisms.The main objective of this project is the design of software shielding techniques and their practical applicability to commodity software and systems. The key innovative aspects of the investigated techniques include: i) principled design that considers the strong adversarial models imposed by the latest exploitation advancements, i.e., disclosure-aided exploitation and data-only attacks, against which effective countermeasures remain an open problem; ii) novel code specialization and data protection techniques, to introduce process-level unpredictability and limit the exposure of critical data; iii) hardware-assisted implementation by leveraging recent and upcoming processor features to minimize the performance impact of the applied protections; and iv) focus on practical considerations, such as operational compatibility and non-disruptive deployment. The outcomes of this research effort are expected to improve the state of the art in defenses against advanced exploits, and achieve substantial practical impact by shielding existing vulnerable applications against exploitation, benefiting both end users and security researchers. The project also provides students the opportunity to conduct research in cybersecurity, and fosters the integration of cybersecurity into high school education through hands-on workshops for students and seminars for science teachers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(14)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3321705.3329820
发表时间:
2019-07
期刊:
Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security
影响因子:
--
作者:
[Jan Werner;Joshua Mason;M. Antonakakis;M. Polychronakis;F. Monrose]
通讯作者:
Jan Werner;Joshua Mason;M. Antonakakis;M. Polychronakis;F. Monrose
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Seyedhamed Ghavamnia;Tapti Palit;Shachee Mishra;M. Polychronakis]
通讯作者:
Seyedhamed Ghavamnia;Tapti Palit;Shachee Mishra;M. Polychronakis
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Seyedhamed Ghavamnia;Tapti Palit;Azzedine Benameur;M. Polychronakis]
通讯作者:
Seyedhamed Ghavamnia;Tapti Palit;Azzedine Benameur;M. Polychronakis
DOI:
10.1145/3548606.3559366
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Seyedhamed Ghavamnia;Tapti Palit;M. Polychronakis]
通讯作者:
Seyedhamed Ghavamnia;Tapti Palit;M. Polychronakis
Decap: Deprivileging Programs by Reducing Their Capabilities
Decap:通过降低程序的能力来剥夺程序的特权
DOI:
10.1145/3545948.3545978
发表时间:
2022
期刊:
Intrusions and Defenses (RAID
影响因子:
--
作者:
[Hasan, Md Mehedi, Ghavamnia, Seyedhamed, Polychronakis, Michalis]
通讯作者:
Polychronakis, Michalis
共 12 条
SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks
-
批准号:2104148
-
项目类别:Standard Grant
-
资助金额:$49.91万
-
财政年份:2021
-
负责人:Michail Polychronakis
-
依托单位:
TWC: Small: Combating Environment-aware Malware
-
批准号:1617902
-
项目类别:Standard Grant
-
资助金额:$49.8万
-
财政年份:2016
-
负责人:Michail Polychronakis
-
依托单位:
CSR: Small: An Information Accountability Architecture for Distributed Enterprise Systems
-
批准号:0914312
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2009
-
负责人:Michail Polychronakis
-
依托单位:
海外基金