SaTC: CORE: Medium: Collaborative: Taming Memory Corruption with Security Monitors
SaTC: CORE: Medium: Collaborative: Taming Memory Corruption with Security Monitors
批准号:
1916393
负责人:
Manuel Egele
金额:
$80.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2024-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Modern computing systems are under constant attack by organized crime syndicates, nation-state adversaries, and regular cyber-criminals alike. Among the most damaging attacks are those that exploit so-called memory corruption vulnerabilities which often confer the attacker with access to sensitive information or allow the attacker to execute arbitrary code on the victim's machine. To counter the threat posed by memory corruption vulnerabilities, this project will research and develop new defensive capabilities realized through the joint design of hardware and software. Hardware and software co-design holds the promise to enable the introduction of rigorous, principled, and efficient protection against low-level exploitation.To defend computing systems against memory corruption attacks, this project will augment a RISC-V processor with an array of security policy engines (ASPEn). ASPEn will feature both specialized and programmable policy engines. Specialized engines will be optimized for performance, power, and area, and enforce static security policies that are known at design time. To accommodate for the constantly-changing nature of the security landscape, programmable engines will be programmed to enforce more flexible security policies. The project is structured into two thrusts; Thrust-1 will design the ASPEn Security Monitor System for the RISC-V processor and Thrust-2 will focus on software design and the various policy types.This project will result in a generic security-focused hardware/software co-design approach that can be leveraged to secure other processors than the RISC-V core used for this project. This broader impact will further be supported by the open-source release of the resulting hardware designs, as well as the new and modified software stack consisting of tool chains, libraries, and policy types. Furthermore, the project will include a variety of training and outreach activities through tutorials, workshops, and curricular development. The project will also continue existing successful efforts of involving undergraduate, high-school, and underrepresented minority and women students throughout its duration.The project's resources and results will be made available publicly. The main project page can be found at https://seclab.bu.edu/projects/aspen.html, and source code releases will be made available via the project's code repository at https://github.com/BUseclab/ASPEn.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
MPKAlloc: Efficient Heap Meta-data Integrity Through Hardware Memory Protection Keys
MPKAlloc:通过硬件内存保护密钥实现高效的堆元数据完整性
DOI:
--
发表时间:
2022
期刊:
and Vulnerability Assessment (DIMVA
影响因子:
--
作者:
[Blair, William, Robertson, William, Egele, Manuel]
通讯作者:
Egele, Manuel
DOI:
10.1145/3485832.3488019
发表时间:
2021-12
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Leila Delshadtehrani;Sadullah Canakci;William Blair;Manuel Egele;A. Joshi]
通讯作者:
Leila Delshadtehrani;Sadullah Canakci;William Blair;Manuel Egele;A. Joshi
SealPK: Sealable Protection Keys for RISC-V
SealPK:RISC-V 的可密封保护密钥
DOI:
--
发表时间:
2021
期刊:
and Test in Europe (DATE
影响因子:
--
作者:
[Delshadtehrani, Leila, Canakci, Sadullah, Egele, Manuel, Joshi, Ajay]
通讯作者:
Joshi, Ajay
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Leila Delshadtehrani;Sadullah Canakci;Boyou Zhou;Schuyler Eldridge;A. Joshi;Manuel Egele]
通讯作者:
Leila Delshadtehrani;Sadullah Canakci;Boyou Zhou;Schuyler Eldridge;A. Joshi;Manuel Egele
SIGFuzz: A Framework for Discovering Microarchitectural Timing Side Channels
SIGFuzz:用于发现微架构定时侧通道的框架
DOI:
10.23919/date56975.2023.10136966
发表时间:
2023
期刊:
Automation & Test in Europe Conference & Exhibition (DATE
影响因子:
--
作者:
[Rajapaksha, Chathura, Delshadtehrani, Leila, Egele, Manuel, Joshi, Ajay]
通讯作者:
Joshi, Ajay
共 6 条
Collaborative Research: SaTC: CORE: Medium: App-driven Web Browsing: Novel Risks, Vulnerabilities, and Defenses
-
批准号:2211576
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2022
-
负责人:Manuel Egele
-
依托单位:
CAREER: Toward Securing Emerging Computing Platforms via Large-Scale Dynamic Analysis
-
批准号:1942793
-
项目类别:Continuing Grant
-
资助金额:$55.9万
-
财政年份:2020
-
负责人:Manuel Egele
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: