课题基金 / 基金详情

SaTC: CORE: Small: Information Flow Control Infrastructure for Single-Use Service Platforms

SaTC: CORE: Small: Information Flow Control Infrastructure for Single-Use Service Platforms
SaTC:核心:小型:一次性服务平台的信息流控制基础设施
批准号:
1816282
负责人:
Trent Jaeger
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-09-01 至 2023-08-31

项目摘要

项目成果

Trent Jaeger的其他基金

相似基金

相关文献

中文摘要
翻译
许多应用程序现在都部署在丰富的分布式平台上,例如云计算和物联网(IoT)。这样的平台可以帮助开发人员动态地启动他们的应用程序,使资源使用与无服务器平台中的需求保持一致,并通过将细粒度组件组合成微服务架构中的完整应用程序。即使有了这些先进的体系结构,系统平台本身仍然有大量的可信计算基础,其中单个漏洞可能威胁到整个平台的安全性。这是因为平台服务对所有应用程序都可用,并且通常受到其他平台服务的完全信任。因此,恶意应用程序可能危及易受攻击的服务,从而获得对另一个应用程序数据的访问和/或危及另一个应用程序计算的完整性。该项目将产生理论和技术来部署平台服务,以保护使用信息流控制的应用程序。首先,提倡将无状态平台服务部署为单用途服务:按需启动的服务,以代表单个命令执行操作,非常类似于无服务器应用程序。其次,通过对单用途服务实施信息流控制来保护应用程序数据,验证实施服务静态地执行信息流控制。第三,该项目试图通过开发将服务划分为强制服务和单一用途服务的方法来减少对复杂、单一服务的信任,这些服务可以使用信息流控制进行验证或治理。与当前强制访问控制以保护主机免受不可信应用程序攻击的平台相比,将开发基础设施来构建使用信息流控制保护应用程序免受潜在易受攻击服务攻击的平台。作为更广泛影响的一部分,本研究探讨了如何在新兴分布式平台中“构建安全”的方法。各种各样的商业努力都瞄准了基于容器的云和物联网平台,但是缺乏基础设施来帮助程序员构建既符合安全要求又能实现所需功能的平台。开发的开源工具和示例平台将用于课程作业,并积极向行业从业者推销,以获得反馈并增加采用率。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Many applications are now being deployed on rich, distributed platforms, such as those for cloud computing and Internet of Things (IoT). Such platforms can aid developers by launching their applications dynamically to align resource use with demand in serverless platforms and by composing fine-grained components into complete applications in microservice architectures. Even with these advanced architectures, the system platforms themselves still have large trusted computing bases, where a single vulnerability may threaten the security of the entire platform. This occurs because platform services are available to all applications and are typically fully trusted by other platform services. As a result, a malicious application may compromise a vulnerable service to gain access to another application's data and/or compromise the integrity of another application's computing.The project will produce theories and techniques to deploy platform services to protect applications using information flow control. First, it is advocated that stateless platform services be deployed as single-use services: services launched on demand to perform an operation on behalf of a single command, much like serverless applications. Second, application data is protected by enforcing information flow control over single-use services, validating that enforcement services perform information flow control statically. Third, the project seeks to reduce trust in complex, monolithic services by developing methods to partition services into enforcement services and single-use services, which can be either validated or governed using information flow control. In contrast to current platforms that enforce mandatory access control to protect hosts from untrusted applications, an infrastructure will be developed to build platforms that protect applications from potentially vulnerable services using information flow control. As part of broader impacts, this research examines methods for how to "build security in" to emerging distributed platforms. A wide variety of commercial efforts are targeting container-based cloud and IoT platforms, but there is a dearth of infrastructure to aid programmers in constructing platforms that adhere to security requirements while achieving desired functionality. The open-source tools and example platforms developed will be utilized in coursework and aggressively pitched to industry practitioners to gain feedback and increase adoption.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(18)
专著(0)
科研奖励(0)
会议论文
Demystifying Android’s Scoped Storage Defense
揭秘 Android 的分区存储防御
DOI: 10.1109/msec.2021.3090564
发表时间: 2021
期刊: IEEE Security & Privacy
影响因子: 1.9
作者: [Lee, Yu-Tsung, Chen, Haining, Jaeger, Trent]
通讯作者: Jaeger, Trent
PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems
PolyScope:用于计算 Android 系统中授权攻击操作的多策略访问控制分析
DOI: --
发表时间: 2021
期刊: 30th USENIX Security Symposium
影响因子: --
作者: [Yu-Tsung Lee, William Enck]
通讯作者: Yu-Tsung Lee, William Enck
DOI: 10.1109/csf54842.2022.9919639
发表时间: 2022
期刊: IEEE 35th Computer Security Foundations Symposium (CSF
影响因子: --
作者: [Li, Peixuan, Zhang, Danfeng]
通讯作者: Zhang, Danfeng
DOI: 10.1145/3593856.3595914
发表时间: 2023-06
期刊: Proceedings of the 19th Workshop on Hot Topics in Operating Systems
影响因子: --
作者: [A. Burtsev;Vikram Narayanan;Yongzhe Huang;Kaiming Huang;Gang Tan;T. Jaeger]
通讯作者: A. Burtsev;Vikram Narayanan;Yongzhe Huang;Kaiming Huang;Gang Tan;T. Jaeger
共 18 条
    SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
    TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
    Trusted Infrastructure Workshop 2013
    TC: Small: Towards Customer-Centric Utility Computing
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: