SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
SaTC:STARSS:小型:用于检测和防御恶意固件的领域知情技术
基本信息
- 批准号:1815883
- 负责人:
- 金额:$ 33.33万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2018
- 资助国家:美国
- 起止时间:2018-08-15 至 2022-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Embedded systems play a large role in our daily lives. They are found in everything from computers and consumer electronics to appliances and automobiles, and represent a market estimated to be worth almost $160 billion. Many of them, however, use inexpensive microcontrollers that cannot easily be analyzed, so it is unclear how well they operate in practice. This work seeks improve the safety and security of these systems by developing techniques to analyze their firmware, particularly with regards to the popular Universal Serial Bus (USB) and Bluetooth protocols.This project will involve development of a platform for allowing firmware analysis of these common but overlooked microcontroller architectures. The goal is to validate the security of critical communications on these embedded devices. The project builds on three research thrusts: 1) Formal modeling of the USB and Bluetooth protocols and their sub-classes and automatic exploration of possible attack scenarios, 2) A firmware analysis framework with a novel query language and an analysis back-end, 3) A dynamic enforcement infrastructure that allows runtime vetting of devices prior to allowing machines to use them. This project will create techniques and systems that can be broadly deployed in consumer, enterprise, government and military environments. The lessons learned from building frameworks in the USB and Bluetooth environments can serve as a larger goal towards developing integrity frameworks for general-purpose embedded and internet-of-things (IoT) environments. The products of this project will be maintained for at least the duration of the project. Data and code from this project will be stored on the website www.firmware-analysis.org.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
嵌入式系统在我们的日常生活中扮演着重要的角色。从计算机和消费电子产品到家用电器和汽车,它们无处不在,并且代表了一个估计价值近1600亿美元的市场。然而,它们中的许多使用便宜的微控制器,不易分析,因此尚不清楚它们在实践中的运行情况。该项目旨在通过开发技术来分析这些系统的固件,特别是关于流行的通用串行总线(USB)和蓝牙协议,以提高这些系统的安全性和可靠性。该项目将涉及开发一个平台,用于对这些常见但被忽视的微控制器架构进行固件分析。目标是验证这些嵌入式设备上关键通信的安全性。该项目建立在三个研究重点之上:1)USB和蓝牙协议及其子类的形式化建模,以及对可能的攻击场景的自动探索,2)具有新颖查询语言和分析后端的固件分析框架,3)允许在允许机器使用设备之前对设备进行运行时审查的动态执行基础设施。 该项目将创建可广泛部署在消费者、企业、政府和军事环境中的技术和系统。在USB和蓝牙环境中构建框架的经验教训可以作为一个更大的目标,为通用嵌入式和物联网(IoT)环境开发完整性框架。 本项目的产品将至少在项目期间得到维护。该项目的数据和代码将存储在网站www.firmware-analysis.org上。该奖项反映了NSF的法定使命,并被认为值得通过使用基金会的知识价值和更广泛的影响审查标准进行评估来支持。
项目成果
期刊论文数量(9)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
ENCIDER: Detecting Timing and Cache Side Channels in SGX Enclaves and Cryptographic APIs
- DOI:10.1109/tdsc.2022.3160346
- 发表时间:2023-03
- 期刊:
- 影响因子:7.3
- 作者:Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian
- 通讯作者:Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian
Analyzing system software components using API model guided symbolic execution
使用 API 模型引导的符号执行分析系统软件组件
- DOI:10.1007/s10515-020-00276-5
- 发表时间:2020
- 期刊:
- 影响因子:3.4
- 作者:Yavuz, Tuba;Bai, Ken
- 通讯作者:Bai, Ken
BigMAC: Fine-Grained Policy Analysis of Android Firmware
BigMAC:Android 固件的细粒度策略分析
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Hernandez, Grant;Tian, Dave Jing;Yadav, Anurag Swarnim;Williams, Byron J.;Butler, Kevin R.B.
- 通讯作者:Butler, Kevin R.B.
ProXray: Protocol Model Learning and Guided Firmware Analysis
- DOI:10.1109/tse.2019.2939526
- 发表时间:2019-09
- 期刊:
- 影响因子:7.4
- 作者:Farhaan Fowze;D. Tian;Grant Hernandez;Kevin R. B. Butler;Tuba Yavuz
- 通讯作者:Farhaan Fowze;D. Tian;Grant Hernandez;Kevin R. B. Butler;Tuba Yavuz
FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware
- DOI:10.14722/ndss.2022.23136
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler
- 通讯作者:Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Kevin Butler其他文献
Use of a heat exchanger in liver transplantation
热交换器在肝移植中的应用
- DOI:
- 发表时间:
1991 - 期刊:
- 影响因子:0
- 作者:
Kevin Butler;S. Raskin;H. Whisennand;W. Lowell;Joseph R Gay;Gary Cornelius - 通讯作者:
Gary Cornelius
35. Investigating Endocannabinoid Metabolism in Opioid Treated Chronic Pain Patients With and Without Opioid Use Disorder: A PET Study With Fatty Acid Amide Hydrolase Radioligand [C-11]CURB
- DOI:
10.1016/j.biopsych.2024.02.270 - 发表时间:
2024-05-15 - 期刊:
- 影响因子:
- 作者:
Claire Shyu;Kevin Butler;Rachel F. Tyndale;Andrew Smith;Vitor S. Tardelli;Stefan Kloiber;Bernard Le Foll;Isabelle Boileau - 通讯作者:
Isabelle Boileau
Potential 2050 distributions of World Terrestrial Ecosystems from projections of changes in World Climate Regions and Global Land Cover
基于世界气候区域变化和全球土地覆盖变化预测的 2050 年世界陆地生态系统潜在分布
- DOI:
10.1016/j.gecco.2024.e03370 - 发表时间:
2025-01-01 - 期刊:
- 影响因子:3.400
- 作者:
Roger Sayre;Charlie Frye;Sean Breyer;Patrick R. Roehrdanz;Paul R. Elsen;Kevin Butler;Clint Brown;Jill Cress;Deniz Karagulle;Madeline Martin;Florencia Sangermano;Regan L. Smyth;Terry L. Sohl;Nicholas H. Wolff;Dawn J. Wright;Zhouting Wu - 通讯作者:
Zhouting Wu
Mechanistic investigations of the Fe(span class="small-caps"ii/span) mediated synthesis of squaraines
铁(Ⅱ)介导的方酸酯合成的机理研究
- DOI:
10.1039/d4sc01286k - 发表时间:
2024-06-26 - 期刊:
- 影响因子:7.400
- 作者:
Yu Liu;Nathan T. Coles;Nathalia Cajiao;Laurence J. Taylor;E. Stephen Davies;Alistair Barbour;Patrick J. Morgan;Kevin Butler;Ben Pointer-Gleadhill;Stephen P. Argent;Jonathan McMaster;Michael L. Neidig;David Robinson;Deborah L. Kays - 通讯作者:
Deborah L. Kays
Impact of Presenting Rhythm on Short- and Long-Term Neurologic Outcome in Comatose Survivors of Cardiac Arrest Treated With Therapeutic Hypothermia: Terman SW, Hume B, Meurer WJ, et al. Crit Care Med 2014;42:2225−34.
- DOI:
10.1016/j.jemermed.2015.02.031 - 发表时间:
2015-04-01 - 期刊:
- 影响因子:
- 作者:
Kevin Butler - 通讯作者:
Kevin Butler
Kevin Butler的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Kevin Butler', 18)}}的其他基金
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
协作研究:SaTC:核心:中:实现切实安全的蜂窝基础设施
- 批准号:
2055014 - 财政年份:2022
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
协作提案:SaTC:前沿:确保边缘化和弱势群体的计算未来
- 批准号:
2206950 - 财政年份:2022
- 资助金额:
$ 33.33万 - 项目类别:
Continuing Grant
Travel Grant Support for Association for Computing Machinery (AC) WiSec 2018
计算机协会 (AC) WiSec 2018 差旅补助金支持
- 批准号:
1823067 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
EAGER: Collaborative: Secure and Efficient Data Provenance
EAGER:协作:安全高效的数据来源
- 批准号:
1540216 - 财政年份:2014
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
EAGER: Collaborative: Secure and Efficient Data Provenance
EAGER:协作:安全高效的数据来源
- 批准号:
1445983 - 财政年份:2014
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
TC: Small: Protection Mechanisms for Portable Storage
TC:小型:便携式存储的保护机制
- 批准号:
1540218 - 财政年份:2014
- 资助金额:
$ 33.33万 - 项目类别:
Continuing Grant
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
职业:通过自主安全存储保护关键基础设施
- 批准号:
1540217 - 财政年份:2014
- 资助金额:
$ 33.33万 - 项目类别:
Continuing Grant
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
职业:通过自主安全存储保护关键基础设施
- 批准号:
1254198 - 财政年份:2013
- 资助金额:
$ 33.33万 - 项目类别:
Continuing Grant
TC: Small: Protection Mechanisms for Portable Storage
TC:小型:便携式存储的保护机制
- 批准号:
1118046 - 财政年份:2011
- 资助金额:
$ 33.33万 - 项目类别:
Continuing Grant
相似海外基金
SaTC: STARSS: Small: IoT Circuit Locking, Obfuscation & Authentication Kernel (CLOAK), A Compilable Architecture for Secure IoT Device Production, Testing, Activation & Ope
SaTC:STARSS:小型:物联网电路锁定、混淆
- 批准号:
2200446 - 财政年份:2021
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Combined Side-channel Attacks and Mathematical Foundations of Combined Countermeasures
SaTC:STARSS:小:组合侧信道攻击和组合对策的数学基础
- 批准号:
1929774 - 财政年份:2019
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Analysis of Security and Countermeasures for Split Manufacturing of Integrated Circuits
SaTC:STARSS:小型:集成电路分片制造的安全性及对策分析
- 批准号:
1812600 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors
SaTC:STARSS:小型:协作:下一代开源处理器的设计和安全验证
- 批准号:
1814190 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Assuring Security and Privacy of Emerging Non-Volatile Memories
SaTC:STARSS:小型:确保新兴非易失性存储器的安全性和隐私
- 批准号:
1814710 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Collaborative: Design and Security Verification of Next-Generation Open-Source Processors
SaTC:STARSS:小型:协作:下一代开源处理器的设计和安全验证
- 批准号:
1813797 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Tackling the Corner Cases: Finding Security Vulnerabilities in CPU Designs
SaTC:STARSS:小型:解决极端情况:查找 CPU 设计中的安全漏洞
- 批准号:
1816637 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Analog Hardware Trojans: Threats, Detection, and Mitigation
SaTC:STARSS:小型:模拟硬件木马:威胁、检测和缓解
- 批准号:
1814516 - 财政年份:2018
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Design of Low-Power True Random Number Generator based on Adaptive Post-Processing
SaTC:STARSS:小型:基于自适应后处理的低功耗真随机数生成器设计
- 批准号:
1714496 - 财政年份:2017
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant
SaTC: STARSS: Small: Wireless, Battery-less, Monolithic Tamper Detector for Semiconductor Chip Authenticity
SaTC:STARSS:小型:用于半导体芯片真伪的无线、无电池、单片篡改检测器
- 批准号:
1716953 - 财政年份:2017
- 资助金额:
$ 33.33万 - 项目类别:
Standard Grant