SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
批准号:
1814679
负责人:
Peng Liu
金额:
$16.55万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-10-01 至 2022-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
During the past decade, middleware on mobile platforms (such as the Application Framework in Android and the Core Services layer in iOS) has been flourishing, but the insecurity analysis of such middleware has been lagging behind. For example, while comprehensive studies have been conducted at the application layer of the Android system, there is very limited work analyzing the Android Application Framework (Android Framework, for short), a middleware layer in the Android system. The two billion Android mobile devices and the many Android Things devices all rely on the system services provided by Android Framework. Recently, many vulnerabilities of Android Framework are exposed, showing that Android Framework is vulnerable and exploitable. Given the critical role of Android Framework, a vulnerability in the framework can be exploited to launch large-scale cyber attacks and cause serious harms to user security and privacy. However, the insecurity analysis of Android Framework has been rather ad hoc, imprecise, and requires much manual effort, mainly because there is a severe lack of techniques and tools developed for insecurity analysis of such middleware on mobile platforms (MoMP). This research project seeks to fill the gap by developing new techniques and tools for insecurity analysis of MoMP like Android Framework and consequently lead to more secure and trustworthy computing environments for the huge number of smartphone and Internet-of-Things (IoT) device users. Educational resources developed in this project, including course modules on mobile computing security and vulnerability discovery, will be disseminated through a dedicated web site. Collaborations with the industry will be sought to transfer the technology to interested software companies and government entities that perform insecurity analysis of MoMP.The project will develop new architectural designs, algorithms and techniques for precise and automated insecurity analysis of MoMP. To make the research concrete, demonstrations will be created for the Android Framework for mobile smartphones, tablets and IoT devices, and the first platform for precise and automated insecurity analysis of Android Framework will be built, combining current software analysis techniques, such as symbolic execution, hybrid dynamic/static analysis, and cross-process and cross-layer software analysis, to make them capable of analyzing complex and large-sized MoMP like Android Framework. The platform will be evaluated and applied to discovering various types of zero-day vulnerabilities and generating proof-of-concept exploits.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(22)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3292006.3300041
发表时间:
2019-03
期刊:
Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy
影响因子:
--
作者:
[Peiying Wang;Shijie Jia;Bo Chen-;Luning Xia;Peng Liu]
通讯作者:
Peiying Wang;Shijie Jia;Bo Chen-;Luning Xia;Peng Liu
Automatic Firmware Emulation through Invalidity-guided Knowledge Inference
通过无效引导的知识推理进行自动固件仿真
DOI:
--
发表时间:
2021
期刊:
Usenix Security Symposium
影响因子:
--
作者:
[Zhou, Wei Zhou, Guan, Le, Liu, Peng, Zhang, Yuqing]
通讯作者:
Zhang, Yuqing
DOI:
10.1109/ithings-greencom-cpscom-smartdata-cybermatics55523.2022.00055
发表时间:
2022-08
期刊:
2022 IEEE International Conferences on Internet of Things (iThings) and IEEE Green Computing & Communications (GreenCom) and IEEE Cyber, Physical & Social Computing (CPSCom) and IEEE Smart Data (SmartData) and IEEE Congress on Cybermatics (Cybermatics)
影响因子:
--
作者:
[Devansh Rajgarhia;Peng Liu;S. Sural]
通讯作者:
Devansh Rajgarhia;Peng Liu;S. Sural
DOI:
10.1186/s42400-020-00055-5
发表时间:
2020-08-10
期刊:
CYBERSECURITY
影响因子:
3.1
作者:
[Choi, Yoon-Ho, Liu, Peng, Zou, Qingtian]
通讯作者:
Zou, Qingtian
DOI:
10.1109/sp46214.2022.9833563
发表时间:
2022-05
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Lei Zhang;Keke Lian;Haoyu Xiao;Zhibo Zhang;Peng Liu;Yuan Zhang;Min Yang;Haixin Duan]
通讯作者:
Lei Zhang;Keke Lian;Haoyu Xiao;Zhibo Zhang;Peng Liu;Yuan Zhang;Min Yang;Haixin Duan
共 21 条
Computational Studies of Selective C-H Functionalization Reactions
-
批准号:2247505
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2023
-
负责人:Peng Liu
-
依托单位:
Frontera Travel Grant: Computational Studies of Transition Metal-Catalyzed Reactions
-
批准号:2031953
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2020
-
负责人:Peng Liu
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Cyber-threat Detection and Diagnosis in Multistage Manufacturing Systems through Cyber and Physical Data Analytics
-
批准号:2019340
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2020
-
负责人:Peng Liu
-
依托单位:
CAREER: Computational Studies of Transition Metal Catalyzed Reactions in Organic Synthesis
-
批准号:1654122
-
项目类别:Standard Grant
-
资助金额:$62.5万
-
财政年份:2017
-
负责人:Peng Liu
-
依托单位:
TWC: Small: Collaborative: Towards Agile and Privacy-Preserving Cloud Computing
-
批准号:1422594
-
项目类别:Standard Grant
-
资助金额:$24.88万
-
财政年份:2014
-
负责人:Peng Liu
-
依托单位:
CAREER: Examining Users' Collective Privacy Management for Online Social Networks
-
批准号:0953749
-
项目类别:Standard Grant
-
资助金额:$47.86万
-
财政年份:2010
-
负责人:Peng Liu
-
依托单位:
NeTS: Small: Collaborative Research:Secure and Resilient Channel Allocation in Multi-Radio Wireless Networks
-
批准号:0916469
-
项目类别:Standard Grant
-
资助金额:$6.0万
-
财政年份:2009
-
负责人:Peng Liu
-
依托单位:
TC: Medium: Collaborative Research: Towards Self-Protecting Data Centers: A Systematic Approach
-
批准号:0905131
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2009
-
负责人:Peng Liu
-
依托单位:
Collaborative Research: CT-T: Transparent Damage Quarantine and Recovery in Transactional Applications and Web Services
-
批准号:0716479
-
项目类别:Standard Grant
-
资助金额:$6.13万
-
财政年份:2007
-
负责人:Peng Liu
-
依托单位:
Capacity Building in Information Assurance at Penn State University
-
批准号:0416827
-
项目类别:Standard Grant
-
资助金额:$29.65万
-
财政年份:2004
-
负责人:Peng Liu
-
依托单位:
QoIA-Aware Attack Resilient Database Systems
-
批准号:0233324
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2002
-
负责人:Peng Liu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: