SaTC: STARSS: Small: Tackling the Corner Cases: Finding Security Vulnerabilities in CPU Designs
SaTC: STARSS: Small: Tackling the Corner Cases: Finding Security Vulnerabilities in CPU Designs
批准号:
1816637
负责人:
Cynthia Sturton
金额:
$33.33万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-10-01 至 2022-09-30
中文摘要
包括处理器、内存库和通信总线在内的计算硬件可能存在漏洞,使攻击者能够未经授权访问计算机上的程序和数据。硬件设计人员和安全专家花费大量时间和精力在设计阶段早期消除这些漏洞。这项研究的重点是支持这些活动,以提高效率和成果。在开发硬件安全漏洞的方法和工具的过程中,本研究将推动硬件设计安全验证领域的发展。本课题针对中央处理器在设计阶段的安全性验证进行研究。该项目有两个目标:1)识别处理器的安全关键属性。这些属性将在寄存器传输级设计的时序逻辑中声明。2)开发方法和工具来自动查找和上下文化违反这些属性的行为。本研究的一个关键创新将是符号执行在硬件设计中的应用。为了使通过多个时钟周期符号化执行复杂硬件设计可行,本研究将开发一种有针对性的向后搜索策略。如果成功,该项目有可能大大减少恶意行为者对硬件发起有效攻击的机会,从而提高计算机系统的安全性。这项研究的工具、试验台、论文和报告将在https://cs.unc.edu/~csturton.This链接的网站上提供,该网站反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Computing hardware including processors, memory banks, and communication busses can harbor vulnerabilities that allow an attacker to gain unauthorized access to the programs and data on a machine. Hardware designers and security experts expend considerable time and effort to eliminate these vulnerabilities early in the design stage. The focus of this research is to support these activities towards improving efficiency and outcomes. In developing the methodologies and tools to find and contextualize hardware security vulnerabilities, this research will move the field of security validation of hardware designs forward.The research targets the security validation of central processing units in the design stage. The project has two goals: 1) To identify security critical properties of a processor. These properties will be stated in a temporal logic over the register transfer level design. 2) To develop the methodology and tools to automatically find and contextualize violations of those properties. A key innovation of this research will be the application of symbolic execution to hardware designs. In order to make symbolically executing a complex hardware design through multiple clock cycles feasible, the research will develop a targeted, backward search strategy.If successful, the project has the potential to significantly reduce the opportunity for a malicious actor to launch an effective attack against hardware, improving the security of computer systems.The tools, testbenches, papers, and presentations resulting from this research will be available at a site linked from https://cs.unc.edu/~csturton.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Mining Security Critical Linear Temporal Logic Specifications for Processors
采矿安全关键的线性时态逻辑处理器规范
DOI:
10.1109/mtv.2018.00013
发表时间:
2018
期刊:
19th International Workshop on Microprocessor and SOC Test and Verification (MTV
影响因子:
--
作者:
[Deutschbein, Calvin, Sturton, Cynthia]
通讯作者:
Sturton, Cynthia
Evaluating Security Specification Mining for a CISC Architecture
评估 CISC 架构的安全规范挖掘
DOI:
10.1109/host45689.2020.9300291
发表时间:
2020
期刊:
2020 IEEE Hardware Oriented Security and Trust (HOST
影响因子:
--
作者:
[Deutschbein, Calvin, Sturton, Cynthia]
通讯作者:
Sturton, Cynthia
End-to-End Automated Exploit Generation for Processor Security Validation
用于处理器安全验证的端到端自动漏洞利用生成
DOI:
10.1109/mdat.2021.3063314
发表时间:
2021
期刊:
IEEE Design & Test
影响因子:
2
作者:
[Zhang, Rui, Deutschbein, Calvin, Huang, Peng, Sturton, Cynthia]
通讯作者:
Sturton, Cynthia
DOI:
10.1145/3474376.3487286
发表时间:
2021-06
期刊:
Proceedings of the 5th Workshop on Attacks and Solutions in Hardware Security
影响因子:
--
作者:
[Calvin Deutschbein;Andres Meza;Francesco Restuccia;R. Kastner;C. Sturton]
通讯作者:
Calvin Deutschbein;Andres Meza;Francesco Restuccia;R. Kastner;C. Sturton
DOI:
10.1109/micro.2018.00071
发表时间:
2018-10
期刊:
2018 51st Annual IEEE/ACM International Symposium on Microarchitecture (MICRO)
影响因子:
--
作者:
[Rui Zhang;Calvin Deutschbein;Peng Huang;C. Sturton]
通讯作者:
Rui Zhang;Calvin Deutschbein;Peng Huang;C. Sturton
共 6 条
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
-
批准号:2247754
-
项目类别:Continuing Grant
-
资助金额:$57.1万
-
财政年份:2023
-
负责人:Cynthia Sturton
-
依托单位:
CPS: Frontier: Collaborative Research: VeHICaL: Verified Human Interfaces, Control, and Learning for Semi-Autonomous Systems
-
批准号:1544924
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Cynthia Sturton
-
依托单位:
EAGER: Identifying Security Critical Properties of a Processor
-
批准号:1651276
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2016
-
负责人:Cynthia Sturton
-
依托单位:
CRII: SaTC: Detecting Security Vulnerabilities in Instruction Set Architectures
-
批准号:1464209
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2015
-
负责人:Cynthia Sturton
-
依托单位:
海外基金