CAREER: Whole-Kernel Analysis Against Developer- and Compiler-Introduced Errors
CAREER: Whole-Kernel Analysis Against Developer- and Compiler-Introduced Errors
批准号:
2045478
负责人:
Kangjie Lu
金额:
$49.3万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-10-01 至 2026-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
An operating system (OS) kernel is the heart of a computer system. It controls virtually everything in the system and thus is the most important part of the system. Modern OS kernels have become extremely large and complex, containing tens of millions of lines of code. As such, they tend to have a large number of errors that are introduced by not only developers but also compilers. Kernel errors are particularly security-critical because a single error in the kernel may break the whole system. Therefore, detecting and eliminating errors in OS kernels is imperative. This is however very challenging because OS kernels are full of hard-to-analyze code artifacts, and the errors take diverse forms and are hard to be specified for detection. This project aims to combat both developer- and compiler-introduced errors by proposing a set of new approaches and techniques, and by realizing them in a precise, whole-kernel analysis system. The project is expected to improve the security of widely used computer systems, to protect user data and privacy, and to advance the knowledge in the fields of security, systems, compilers, and software engineering. In addition, the resulting system will be integrated into educational tools to help raise student awareness of errors and also to improve their skills in writing secure and correct code.The project is structured into three research thrusts. (1) Enabling precise whole-kernel analysis with foundational techniques. This project first aims to tackle multiple important problems, such as the prevalent hand-written assembly and the monolithic nature, that have been impeding precise whole-kernel analysis. (2) Detecting semantic errors and even insecure function designs through multiple new peer-checking techniques. These techniques minimize the needs for the challenging semantic understanding and error specification in detection, and expect to turn peer-checking into a powerful and generic error-detection approach. (3) Discovering and eliminating compiler-introduced security errors. Compilers tend to focus on semantic correctness but overlook security states, leading to security errors. This thrust aims to create a new memory model to capture security states, and a new oracle to determine security errors introduced by compilers. In addition to detecting errors, the generic approaches and techniques of this project would also advance future research on the analysis and protection of computer systems.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[Qiushi Wu;Yue Xiao;Xiaojing Liao;Kangjie Lu]
通讯作者:
Qiushi Wu;Yue Xiao;Xiaojing Liao;Kangjie Lu
DOI:
10.14722/ndss.2022.24296
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
作者:
[Zu-Ming Jiang;Jia-Ju Bai;Kangjie Lu;Shih-Min Hu]
通讯作者:
Zu-Ming Jiang;Jia-Ju Bai;Kangjie Lu;Shih-Min Hu
DOI:
--
发表时间:
2023
期刊:
影响因子:
--
作者:
[Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna]
通讯作者:
Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna
DOI:
10.1145/3540250.3549080
发表时间:
2022-11
期刊:
Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering
影响因子:
--
作者:
[Penghui Li;W. Meng;Kangjie Lu]
通讯作者:
Penghui Li;W. Meng;Kangjie Lu
DOI:
10.1145/3548606.3560661
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Qingyang Zhou;Qiushi Wu;Dinghao Liu;S. Ji;Kangjie Lu]
通讯作者:
Qingyang Zhou;Qiushi Wu;Dinghao Liu;S. Ji;Kangjie Lu
共 7 条
Travel: NSF Student Travel Grant for The 2nd International Workshop on Ethics in Computer Security (EthiCS 2023)
-
批准号:2312705
-
项目类别:Standard Grant
-
资助金额:$0.84万
-
财政年份:2023
-
负责人:Kangjie Lu
-
依托单位:
SaTC: CORE: Small: Regulating and Leveraging Types for Security
-
批准号:2247434
-
项目类别:Continuing Grant
-
资助金额:$59.93万
-
财政年份:2023
-
负责人:Kangjie Lu
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Improving Decentralized Kernel Patch Ecosystems
-
批准号:2154989
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2022
-
负责人:Kangjie Lu
-
依托单位:
SaTC: CORE: Small: Checking Security Checks in OS Kernels
-
批准号:1931208
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2019
-
负责人:Kangjie Lu
-
依托单位:
SaTC: CORE: Small: MOSE: Automated Detection of Module-Specific Semantic Errors
-
批准号:1815621
-
项目类别:Standard Grant
-
资助金额:$49.53万
-
财政年份:2018
-
负责人:Kangjie Lu
-
依托单位:
国内基金
海外基金
全外显子组测序(Whole-Exome Sequencing,WES)检测NSCLC中难治性OCT4+循环肿瘤细胞的基因突变
-
批准号:81773273
-
项目类别:面上项目
-
资助金额:50.0万元
-
批准年份:2017
-
负责人:李榕
-
依托单位:
HBV whole-X 基因在HBV相关肝癌中的作用及机制的研究
-
批准号:81572435
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2015
-
负责人:刘红莉
-
依托单位: