SaTC: CORE: Medium: Collaborative: Taming Memory Corruption with Security Monitors
SaTC: CORE: Medium: Collaborative: Taming Memory Corruption with Security Monitors
批准号:
1916393
负责人:
Manuel Egele
金额:
$80.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2024-09-30
中文摘要
现代计算机系统不断受到有组织犯罪集团、民族国家对手和常规网络罪犯的攻击。最具破坏性的攻击是那些利用所谓的内存损坏漏洞的攻击,这些漏洞通常授予攻击者访问敏感信息的权限,或允许攻击者在受害者的计算机上执行任意代码。为了应对内存腐败漏洞带来的威胁,该项目将研发通过硬件和软件联合设计实现的新的防御能力。硬件和软件协同设计承诺能够引入严格、原则性和高效的保护,防止低级别攻击。为了保护计算系统免受内存崩溃攻击,该项目将使用一系列安全策略引擎(ASPEN)来增强RISC-V处理器。Aspen将采用专门的和可编程的策略引擎。专门的引擎将针对性能、功率和面积进行优化,并执行在设计时已知的静态安全策略。为了适应安全格局不断变化的性质,将对可编程引擎进行编程,以实施更灵活的安全策略。该项目分为两个阶段;Strust-1将为RISC-V处理器设计Aspen安全监控系统,而Strust-2将专注于软件设计和各种策略类型。该项目将产生一种通用的以安全为重点的硬件/软件协同设计方法,该方法可用于保护除用于该项目的RISC-V核心之外的其他处理器。这种更广泛的影响将进一步得到由此产生的硬件设计的开源版本以及由工具链、库和策略类型组成的新的和修改的软件堆栈的支持。此外,该项目还将通过辅导、讲习班和课程开发等形式开展各种培训和外展活动。该项目还将在整个过程中继续现有的成功努力,让本科生、高中生和代表性不足的少数民族和女性学生参与进来。项目的资源和成果将向公众公布。主要项目页面可以在https://seclab.bu.edu/projects/aspen.html,上找到,源代码发布将通过https://github.com/BUseclab/ASPEn.This上的项目代码库提供,该奖项反映了国家科学基金会的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Modern computing systems are under constant attack by organized crime syndicates, nation-state adversaries, and regular cyber-criminals alike. Among the most damaging attacks are those that exploit so-called memory corruption vulnerabilities which often confer the attacker with access to sensitive information or allow the attacker to execute arbitrary code on the victim's machine. To counter the threat posed by memory corruption vulnerabilities, this project will research and develop new defensive capabilities realized through the joint design of hardware and software. Hardware and software co-design holds the promise to enable the introduction of rigorous, principled, and efficient protection against low-level exploitation.To defend computing systems against memory corruption attacks, this project will augment a RISC-V processor with an array of security policy engines (ASPEn). ASPEn will feature both specialized and programmable policy engines. Specialized engines will be optimized for performance, power, and area, and enforce static security policies that are known at design time. To accommodate for the constantly-changing nature of the security landscape, programmable engines will be programmed to enforce more flexible security policies. The project is structured into two thrusts; Thrust-1 will design the ASPEn Security Monitor System for the RISC-V processor and Thrust-2 will focus on software design and the various policy types.This project will result in a generic security-focused hardware/software co-design approach that can be leveraged to secure other processors than the RISC-V core used for this project. This broader impact will further be supported by the open-source release of the resulting hardware designs, as well as the new and modified software stack consisting of tool chains, libraries, and policy types. Furthermore, the project will include a variety of training and outreach activities through tutorials, workshops, and curricular development. The project will also continue existing successful efforts of involving undergraduate, high-school, and underrepresented minority and women students throughout its duration.The project's resources and results will be made available publicly. The main project page can be found at https://seclab.bu.edu/projects/aspen.html, and source code releases will be made available via the project's code repository at https://github.com/BUseclab/ASPEn.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
MPKAlloc: Efficient Heap Meta-data Integrity Through Hardware Memory Protection Keys
MPKAlloc:通过硬件内存保护密钥实现高效的堆元数据完整性
DOI:
--
发表时间:
2022
期刊:
and Vulnerability Assessment (DIMVA
影响因子:
--
作者:
[Blair, William, Robertson, William, Egele, Manuel]
通讯作者:
Egele, Manuel
DOI:
10.1145/3485832.3488019
发表时间:
2021-12
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Leila Delshadtehrani;Sadullah Canakci;William Blair;Manuel Egele;A. Joshi]
通讯作者:
Leila Delshadtehrani;Sadullah Canakci;William Blair;Manuel Egele;A. Joshi
SealPK: Sealable Protection Keys for RISC-V
SealPK:RISC-V 的可密封保护密钥
DOI:
--
发表时间:
2021
期刊:
and Test in Europe (DATE
影响因子:
--
作者:
[Delshadtehrani, Leila, Canakci, Sadullah, Egele, Manuel, Joshi, Ajay]
通讯作者:
Joshi, Ajay
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Leila Delshadtehrani;Sadullah Canakci;Boyou Zhou;Schuyler Eldridge;A. Joshi;Manuel Egele]
通讯作者:
Leila Delshadtehrani;Sadullah Canakci;Boyou Zhou;Schuyler Eldridge;A. Joshi;Manuel Egele
SIGFuzz: A Framework for Discovering Microarchitectural Timing Side Channels
SIGFuzz:用于发现微架构定时侧通道的框架
DOI:
10.23919/date56975.2023.10136966
发表时间:
2023
期刊:
Automation & Test in Europe Conference & Exhibition (DATE
影响因子:
--
作者:
[Rajapaksha, Chathura, Delshadtehrani, Leila, Egele, Manuel, Joshi, Ajay]
通讯作者:
Joshi, Ajay
共 6 条
Collaborative Research: SaTC: CORE: Medium: App-driven Web Browsing: Novel Risks, Vulnerabilities, and Defenses
-
批准号:2211576
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2022
-
负责人:Manuel Egele
-
依托单位:
CAREER: Toward Securing Emerging Computing Platforms via Large-Scale Dynamic Analysis
-
批准号:1942793
-
项目类别:Continuing Grant
-
资助金额:$55.9万
-
财政年份:2020
-
负责人:Manuel Egele
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: