课题基金 / 基金详情

SaTC: CORE: Small: Checking Security Checks in OS Kernels

SaTC: CORE: Small: Checking Security Checks in OS Kernels
SaTC:核心:小:检查操作系统内核中的安全检查
批准号:
1931208
负责人:
Kangjie Lu
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2023-09-30

项目摘要

项目成果

Kangjie Lu的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Operating system (OS) kernels play a critical role in computer systems by virtually having complete control over the systems. OS kernels not only manage hardware and system resources, but also provide services and protection. Given these tasks, OS kernels have to process external untrusted inputs and perform complicated operations, both of which are error-prone. To avoid entering into erroneous states, OS kernels tend to enforce a large number of security checks---"if" and "switch" statements that are used to validate states. Unfortunately, security checks themselves are often buggy. In particular, a security check may be missing or incomplete, be placed in an improper location, target a wrong variable, etc. Buggy security checks often cause critical security impact because the intended validation for potential errors can be void. This project aims to systematically investigate security checks in OS kernels, to automatically identify security checks, and to develop a set of new techniques to detect the common classes of security-check bugs. This project is expected to effectively find a potentially large number of previously unknown security-check bugs in widely used OS kernels, and thus to significantly improve the security of computer systems with billions of users. The broader educational activities of this project include integrating research with outreach, organizing Capture The Flag competitions among universities and industries in Minnesota, and developing courses for training interdisciplinary and underrepresented students.The goal of this project is to systematically investigate security checks and effectively detect the common and critical security-check bugs in popular OS kernels, including the Linux kernel, the Android kernel, the FreeBSD kernel, Darwin-XNU (MacOS), and ReactOS (Windows-like). The project is comprised of two main research thrusts: (1) identifying security checks and (2) detecting security-check bugs. Both research thrusts are challenging because they require the understanding of code semantics and contexts, and even developer logic. Therefore, this project develops a set of semantic-and context-aware approaches. This project also enhances existing techniques such as fuzzing and symbolic execution to effectively and scalably detect security-check bugs. Multiple general techniques developed in this project, such as accurately finding indirect-call targets, identifying semantically-similar peer code paths, modeling OS-kernel boundary, would also advance future research on systems analysis and protection.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(22)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3460120.3485373
发表时间: 2021-11
期刊: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Dinghao Liu;Qiushi Wu;S. Ji;Kangjie Lu;Zhenguang Liu;Jianhai Chen;Qinming He]
通讯作者: Dinghao Liu;Qiushi Wu;S. Ji;Kangjie Lu;Zhenguang Liu;Jianhai Chen;Qinming He
DOI: 10.14722/ndss.2021.24416
发表时间: 2021
期刊: Proceedings 2021 Network and Distributed System Security Symposium
影响因子: --
作者: [Navid Emamdoost]
通讯作者: Navid Emamdoost
DOI: 10.14722/ndss.2022.24296
发表时间: 2022
期刊: Proceedings 2022 Network and Distributed System Security Symposium
影响因子: --
作者: [Zu-Ming Jiang;Jia-Ju Bai;Kangjie Lu;Shih-Min Hu]
通讯作者: Zu-Ming Jiang;Jia-Ju Bai;Kangjie Lu;Shih-Min Hu
On the Feasibility of Automated Built-in Function Modeling for PHP Symbolic Execution
论PHP符号执行的自动内置函数建模的可行性
DOI: 10.1145/3442381.3450002
发表时间: 2021
期刊: the 30th International World Wide Web Conference (WWW'21
影响因子: --
作者: [Li, Penghui, Meng, Wei, Lu, Kangjie, Luo, Changhua]
通讯作者: Luo, Changhua
18
    Travel: NSF Student Travel Grant for The 2nd International Workshop on Ethics in Computer Security (EthiCS 2023)
    • 批准号:
      2312705
    • 项目类别:
      Standard Grant
    • 资助金额:
      $0.84万
    • 财政年份:
      2023
    • 负责人:
      Kangjie Lu
    • 依托单位:
    SaTC: CORE: Small: Regulating and Leveraging Types for Security
    • 批准号:
      2247434
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $59.93万
    • 财政年份:
      2023
    • 负责人:
      Kangjie Lu
    • 依托单位:
    Collaborative Research: SaTC: CORE: Small: Improving Decentralized Kernel Patch Ecosystems
    • 批准号:
      2154989
    • 项目类别:
      Standard Grant
    • 资助金额:
      $25.0万
    • 财政年份:
      2022
    • 负责人:
      Kangjie Lu
    • 依托单位:
    CAREER: Whole-Kernel Analysis Against Developer- and Compiler-Introduced Errors
    • 批准号:
      2045478
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $49.3万
    • 财政年份:
      2021
    • 负责人:
      Kangjie Lu
    • 依托单位:
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: