CAREER: Binary-Level Security via ABI-Centric Semantic Inference
CAREER: Binary-Level Security via ABI-Centric Semantic Inference
批准号:
2047205
负责人:
Aravind Prakash
金额:
$49.99万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-10-01 至 2026-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Understanding the inner workings of software is essential to protect desktop and mobile computers. Lack of source code for most commercial software makes it necessary to analyze and defend software binaries. However, unlike source code, binaries are devoid of rich semantic information that is crucial for security. Traditional binary analysis and reverse engineering approaches are limited by factors such as obfuscation, choice of compiler and compilation flags, availability of debug information, and underlying instruction set architecture. This project bridges the semantic gap in binary analysis by leveraging the interface between a binary and its environment. Such interactions are mandated by the Application Binary Interface (ABI) specification. The project is based on the insight that ABI adherence confers certain properties to a binary that form a strong basis for reverse engineering. Because ABI adherence is necessary for interoperability, relying on ABI cues for reverse engineering offers an unprecedented level of robustness that is impervious to obfuscation and compilation environment (e.g., optimization). This project utilizes two independent yet complementary mechanisms that leverage language ABIs to vastly improve the state of the art in binary analysis and code-reuse attack detection. It employs a combination of static and dynamic binary analysis approaches in order to derive high-level design information (e.g., object-oriented language class diagrams) from binaries. Such information is central to solving problems in decompilation, software specialization, software similarity detection, etc. While the project evaluates binaries that adhere to Itanium and Microsoft’s MSVC ABIs, the discovered techniques will be applicable to more modern languages such as Rust. Additionally, this project leverages System V ABI, the most popular C language ABI to derive integrity policies for binaries that run on UN*X (unix like) operating systems, and addresses modern code-reuse attacks that operate within the confines of a statically recovered control-flow graph.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/sp46215.2023.10179416
发表时间:
2023-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
作者:
[Ravi Theja Gollapudi;Gokturk Yuksek;David Demicco;Matthew Cole;Gaurav Kothari;Rohit Kulkarni;Xin Z]
通讯作者:
Ravi Theja Gollapudi;Gokturk Yuksek;David Demicco;Matthew Cole;Gaurav Kothari;Rohit Kulkarni;Xin Z
DOI:
10.1145/3485832.3488017
发表时间:
2021-12
期刊:
Proceedings of the 37th Annual Computer Security Applications Conference
影响因子:
--
作者:
[David Demicco;R. Erinfolami;Aravind Prakash]
通讯作者:
David Demicco;R. Erinfolami;Aravind Prakash
DOI:
10.1109/hipcw57629.2022.00011
发表时间:
2022-12
期刊:
2022 IEEE 29th International Conference on High Performance Computing, Data and Analytics Workshop (HiPCW)
影响因子:
--
作者:
[David Demicco;Matthew Cole;Shengdun Wang;Aravind Prakash]
通讯作者:
David Demicco;Matthew Cole;Shengdun Wang;Aravind Prakash
Simplex: Repurposing Intel Memory Protection Extensions for Secure Storage
Simplex:重新利用英特尔内存保护扩展来实现安全存储
DOI:
--
发表时间:
2023
期刊:
NordSec 2022: Secure IT Systems
影响因子:
--
作者:
[Cole, Matthew, Prakash, Aravind]
通讯作者:
Prakash, Aravind
CRII: SaTC: Robust and Platform Independent Recovery of Design Features from C++ Binaries
-
批准号:1566532
-
项目类别:Standard Grant
-
资助金额:$17.5万
-
财政年份:2016
-
负责人:Aravind Prakash
-
依托单位:
国内基金
海外基金
Improving modelling of compact binary evolution.
-
批准号:10903001
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2009
-
负责人:史蒂芬
-
依托单位: