SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
批准号:
1856380
负责人:
Qiang Zeng
金额:
$16.67万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-10-01 至 2022-09-30
中文摘要
在过去的十年中,移动平台上的中间件(如Android中的Application Framework和iOS中的Core Services层)蓬勃发展,但对这类中间件的不安全性分析却相对滞后。例如,虽然对Android系统的应用层进行了全面的研究,但对Android系统的中间件层Android application Framework(以下简称Android Framework)的分析却非常有限。20亿台安卓移动设备和众多安卓物联网设备都依赖于安卓框架提供的系统服务。最近,Android框架的许多漏洞被曝光,表明Android框架是脆弱和可利用的。鉴于Android框架的关键作用,框架中的漏洞可以被利用来发动大规模的网络攻击,对用户的安全和隐私造成严重的危害。然而,Android框架的不安全性分析一直是相当特别的,不精确的,并且需要大量的手工工作,主要是因为严重缺乏用于移动平台上这种中间件(MoMP)的不安全性分析的技术和工具。该研究项目旨在通过开发新的技术和工具来填补这一空白,用于像Android框架这样的MoMP的不安全性分析,从而为大量智能手机和物联网(IoT)设备用户带来更安全、更值得信赖的计算环境。在这个项目中开发的教育资源,包括移动计算安全和漏洞发现课程模块,将通过一个专门的网站分发。将寻求与业界合作,将技术转让给感兴趣的软件公司和执行MoMP不安全性分析的政府实体。该项目将开发新的架构设计、算法和技术,以精确和自动化地分析MoMP的不安全性。为使研究具体化,将针对移动智能手机、平板电脑和物联网设备的Android框架进行演示,并结合现有的符号执行、动态/静态混合分析、跨进程、跨层软件分析等软件分析技术,构建首个Android框架的精确自动化不安全分析平台,使其能够分析像Android框架这样复杂、大型的MoMP。该平台将被评估并应用于发现各种类型的零日漏洞并生成概念验证漏洞。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
During the past decade, middleware on mobile platforms (such as the Application Framework in Android and the Core Services layer in iOS) has been flourishing, but the insecurity analysis of such middleware has been lagging behind. For example, while comprehensive studies have been conducted at the application layer of the Android system, there is very limited work analyzing the Android Application Framework (Android Framework, for short), a middleware layer in the Android system. The two billion Android mobile devices and the many Android Things devices all rely on the system services provided by Android Framework. Recently, many vulnerabilities of Android Framework are exposed, showing that Android Framework is vulnerable and exploitable. Given the critical role of Android Framework, a vulnerability in the framework can be exploited to launch large-scale cyber attacks and cause serious harms to user security and privacy. However, the insecurity analysis of Android Framework has been rather ad hoc, imprecise, and requires much manual effort, mainly because there is a severe lack of techniques and tools developed for insecurity analysis of such middleware on mobile platforms (MoMP). This research project seeks to fill the gap by developing new techniques and tools for insecurity analysis of MoMP like Android Framework and consequently lead to more secure and trustworthy computing environments for the huge number of smartphone and Internet-of-Things (IoT) device users. Educational resources developed in this project, including course modules on mobile computing security and vulnerability discovery, will be disseminated through a dedicated web site. Collaborations with the industry will be sought to transfer the technology to interested software companies and government entities that perform insecurity analysis of MoMP.The project will develop new architectural designs, algorithms and techniques for precise and automated insecurity analysis of MoMP. To make the research concrete, demonstrations will be created for the Android Framework for mobile smartphones, tablets and IoT devices, and the first platform for precise and automated insecurity analysis of Android Framework will be built, combining current software analysis techniques, such as symbolic execution, hybrid dynamic/static analysis, and cross-process and cross-layer software analysis, to make them capable of analyzing complex and large-sized MoMP like Android Framework. The platform will be evaluated and applied to discovering various types of zero-day vulnerabilities and generating proof-of-concept exploits.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(21)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/dsn53405.2022.00050
发表时间:
2022-06
期刊:
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[Chenglong Fu;Qiang Zeng;Haotian Chi;Xiaojiang Du;Siva Likitha Valluru]
通讯作者:
Chenglong Fu;Qiang Zeng;Haotian Chi;Xiaojiang Du;Siva Likitha Valluru
DOI:
10.1109/dsn.2019.00019
发表时间:
2018-12
期刊:
2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[Qiang Zeng;Jianhai Su;Chenglong Fu;Golam Kayas;Lannan Luo]
通讯作者:
Qiang Zeng;Jianhai Su;Chenglong Fu;Golam Kayas;Lannan Luo
DOI:
10.1109/dsn48063.2020.00056
发表时间:
2018-08
期刊:
2020 50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
作者:
[Haotian Chi;Qiang Zeng;Xiaojiang Du;Jiaping Yu]
通讯作者:
Haotian Chi;Qiang Zeng;Xiaojiang Du;Jiaping Yu
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[Chenglong Fu;Qiang Zeng;Xiaojiang Du]
通讯作者:
Chenglong Fu;Qiang Zeng;Xiaojiang Du
DOI:
10.14722/ndss.2021.24464
发表时间:
2021-01
期刊:
ArXiv
影响因子:
--
作者:
[Haotian Chi;Qiang Zeng;Xiaojiang Du;Lannan Luo]
通讯作者:
Haotian Chi;Qiang Zeng;Xiaojiang Du;Lannan Luo
共 17 条
CAREER: Towards Secure and Usable IoT Authentication Under Constraints
-
批准号:2144669
-
项目类别:Continuing Grant
-
资助金额:$54.57万
-
财政年份:2022
-
负责人:Qiang Zeng
-
依托单位:
CCRI: Medium: Collaborative Research: Hardware-in-the-Loop and Remotely-Accessible/Configurable/Programmable Internet of Things (IoT) Testbeds
-
批准号:2309477
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2022
-
负责人:Qiang Zeng
-
依托单位:
CAREER: Towards Secure and Usable IoT Authentication Under Constraints
-
批准号:2309550
-
项目类别:Continuing Grant
-
资助金额:$54.57万
-
财政年份:2022
-
负责人:Qiang Zeng
-
依托单位:
Collaborative Research: CNS Core: Medium: Towards Understanding and Handling Problems Due to Coexistence of Multiple IoT Platforms
-
批准号:2310322
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2022
-
负责人:Qiang Zeng
-
依托单位:
Collaborative Research: CNS Core: Medium: Towards Understanding and Handling Problems Due to Coexistence of Multiple IoT Platforms
-
批准号:2107093
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2021
-
负责人:Qiang Zeng
-
依托单位:
CCRI: Medium: Collaborative Research: Hardware-in-the-Loop and Remotely-Accessible/Configurable/Programmable Internet of Things (IoT) Testbeds
-
批准号:2016415
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2020
-
负责人:Qiang Zeng
-
依托单位:
SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
-
批准号:1815045
-
项目类别:Standard Grant
-
资助金额:$16.67万
-
财政年份:2018
-
负责人:Qiang Zeng
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: