SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
批准号:
1815883
负责人:
Kevin Butler
金额:
$33.33万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-15 至 2022-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Embedded systems play a large role in our daily lives. They are found in everything from computers and consumer electronics to appliances and automobiles, and represent a market estimated to be worth almost $160 billion. Many of them, however, use inexpensive microcontrollers that cannot easily be analyzed, so it is unclear how well they operate in practice. This work seeks improve the safety and security of these systems by developing techniques to analyze their firmware, particularly with regards to the popular Universal Serial Bus (USB) and Bluetooth protocols.This project will involve development of a platform for allowing firmware analysis of these common but overlooked microcontroller architectures. The goal is to validate the security of critical communications on these embedded devices. The project builds on three research thrusts: 1) Formal modeling of the USB and Bluetooth protocols and their sub-classes and automatic exploration of possible attack scenarios, 2) A firmware analysis framework with a novel query language and an analysis back-end, 3) A dynamic enforcement infrastructure that allows runtime vetting of devices prior to allowing machines to use them. This project will create techniques and systems that can be broadly deployed in consumer, enterprise, government and military environments. The lessons learned from building frameworks in the USB and Bluetooth environments can serve as a larger goal towards developing integrity frameworks for general-purpose embedded and internet-of-things (IoT) environments. The products of this project will be maintained for at least the duration of the project. Data and code from this project will be stored on the website www.firmware-analysis.org.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/tdsc.2022.3160346
发表时间:
2023-03
期刊:
IEEE Transactions on Dependable and Secure Computing
影响因子:
7.3
作者:
[Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian]
通讯作者:
Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian
Analyzing system software components using API model guided symbolic execution
使用 API 模型引导的符号执行分析系统软件组件
DOI:
10.1007/s10515-020-00276-5
发表时间:
2020
期刊:
Automated Software Engineering
影响因子:
3.4
作者:
[Yavuz, Tuba, Bai, Ken]
通讯作者:
Bai, Ken
BigMAC: Fine-Grained Policy Analysis of Android Firmware
BigMAC:Android 固件的细粒度策略分析
DOI:
--
发表时间:
2020
期刊:
29th USENIX Security Symposium (USENIX Security'20
影响因子:
--
作者:
[Hernandez, Grant, Tian, Dave Jing, Yadav, Anurag Swarnim, Williams, Byron J., Butler, Kevin R.B.]
通讯作者:
Butler, Kevin R.B.
DOI:
10.1109/tse.2019.2939526
发表时间:
2019-09
期刊:
IEEE Transactions on Software Engineering
影响因子:
7.4
作者:
[Farhaan Fowze;D. Tian;Grant Hernandez;Kevin R. B. Butler;Tuba Yavuz]
通讯作者:
Farhaan Fowze;D. Tian;Grant Hernandez;Kevin R. B. Butler;Tuba Yavuz
DOI:
10.14722/ndss.2022.23136
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
作者:
[Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler]
通讯作者:
Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler
共 9 条
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
-
批准号:2055014
-
项目类别:Standard Grant
-
资助金额:$59.8万
-
财政年份:2022
-
负责人:Kevin Butler
-
依托单位:
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
-
批准号:2206950
-
项目类别:Continuing Grant
-
资助金额:$403.58万
-
财政年份:2022
-
负责人:Kevin Butler
-
依托单位:
Travel Grant Support for Association for Computing Machinery (AC) WiSec 2018
-
批准号:1823067
-
项目类别:Standard Grant
-
资助金额:$0.9万
-
财政年份:2018
-
负责人:Kevin Butler
-
依托单位:
EAGER: Collaborative: Secure and Efficient Data Provenance
-
批准号:1445983
-
项目类别:Standard Grant
-
资助金额:$11.01万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
EAGER: Collaborative: Secure and Efficient Data Provenance
-
批准号:1540216
-
项目类别:Standard Grant
-
资助金额:$11.01万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
TC: Small: Protection Mechanisms for Portable Storage
-
批准号:1540218
-
项目类别:Continuing Grant
-
资助金额:$20.78万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
-
批准号:1540217
-
项目类别:Continuing Grant
-
资助金额:$32.2万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
-
批准号:1254198
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2013
-
负责人:Kevin Butler
-
依托单位:
TC: Small: Protection Mechanisms for Portable Storage
-
批准号:1118046
-
项目类别:Continuing Grant
-
资助金额:$49.95万
-
财政年份:2011
-
负责人:Kevin Butler
-
依托单位:
海外基金