CAREER: Binary-Level Security via ABI-Centric Semantic Inference
职业:通过以 ABI 为中心的语义推理实现二进制级安全
基本信息
- 批准号:2047205
- 负责人:
- 金额:$ 49.99万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2021
- 资助国家:美国
- 起止时间:2021-10-01 至 2026-09-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Understanding the inner workings of software is essential to protect desktop and mobile computers. Lack of source code for most commercial software makes it necessary to analyze and defend software binaries. However, unlike source code, binaries are devoid of rich semantic information that is crucial for security. Traditional binary analysis and reverse engineering approaches are limited by factors such as obfuscation, choice of compiler and compilation flags, availability of debug information, and underlying instruction set architecture. This project bridges the semantic gap in binary analysis by leveraging the interface between a binary and its environment. Such interactions are mandated by the Application Binary Interface (ABI) specification. The project is based on the insight that ABI adherence confers certain properties to a binary that form a strong basis for reverse engineering. Because ABI adherence is necessary for interoperability, relying on ABI cues for reverse engineering offers an unprecedented level of robustness that is impervious to obfuscation and compilation environment (e.g., optimization). This project utilizes two independent yet complementary mechanisms that leverage language ABIs to vastly improve the state of the art in binary analysis and code-reuse attack detection. It employs a combination of static and dynamic binary analysis approaches in order to derive high-level design information (e.g., object-oriented language class diagrams) from binaries. Such information is central to solving problems in decompilation, software specialization, software similarity detection, etc. While the project evaluates binaries that adhere to Itanium and Microsoft’s MSVC ABIs, the discovered techniques will be applicable to more modern languages such as Rust. Additionally, this project leverages System V ABI, the most popular C language ABI to derive integrity policies for binaries that run on UN*X (unix like) operating systems, and addresses modern code-reuse attacks that operate within the confines of a statically recovered control-flow graph.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
了解软件的内部工作原理对于保护台式机和移动的计算机至关重要。由于大多数商业软件缺乏源代码,因此有必要分析和保护软件二进制文件。然而,与源代码不同,二进制文件缺乏对安全性至关重要的丰富语义信息。传统的二进制分析和逆向工程方法受到诸如混淆、编译器和编译标志的选择、调试信息的可用性以及底层指令集架构等因素的限制。这个项目通过利用二进制文件和它的环境之间的接口来弥合二进制分析中的语义鸿沟。这种交互是由应用程序二进制接口(ABI)规范规定的。该项目是基于这样的见解,即ABI的遵守赋予了某些属性的二进制文件,形成了一个强大的基础,逆向工程。因为遵循ABI对于互操作性是必要的,所以依赖于ABI线索进行逆向工程提供了前所未有的鲁棒性水平,其不受混淆和编译环境(例如,优化)。该项目利用两个独立但互补的机制,利用语言ABI来极大地改进二进制分析和代码重用攻击检测的最新技术水平。它采用静态和动态二进制分析方法的组合,以获得高级设计信息(例如,面向对象的语言类图)。这些信息是解决反编译、软件专业化、软件相似性检测等问题的核心。虽然该项目评估了遵循Itanium和微软MSVC ABI的二进制文件,但发现的技术将适用于更现代的语言,如Rust。此外,该项目利用System V ABI(最流行的C语言ABI)为UN*X上运行的二进制文件导出完整性策略(类Unix)操作系统,并解决了在静态恢复控件范围内操作的现代代码重用攻击,该奖项反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的评估被认为是值得支持的。影响审查标准。
项目成果
期刊论文数量(4)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture
- DOI:10.1109/sp46215.2023.10179416
- 发表时间:2023-05
- 期刊:
- 影响因子:0
- 作者:Ravi Theja Gollapudi;Gokturk Yuksek;David Demicco;Matthew Cole;Gaurav Kothari;Rohit Kulkarni;Xin Z
- 通讯作者:Ravi Theja Gollapudi;Gokturk Yuksek;David Demicco;Matthew Cole;Gaurav Kothari;Rohit Kulkarni;Xin Z
Program Obfuscation via ABI Debiasing
- DOI:10.1145/3485832.3488017
- 发表时间:2021-12
- 期刊:
- 影响因子:0
- 作者:David Demicco;R. Erinfolami;Aravind Prakash
- 通讯作者:David Demicco;R. Erinfolami;Aravind Prakash
A Security Analysis of Labeling-Based Control-Flow Integrity Schemes
- DOI:10.1109/hipcw57629.2022.00011
- 发表时间:2022-12
- 期刊:
- 影响因子:0
- 作者:David Demicco;Matthew Cole;Shengdun Wang;Aravind Prakash
- 通讯作者:David Demicco;Matthew Cole;Shengdun Wang;Aravind Prakash
Simplex: Repurposing Intel Memory Protection Extensions for Secure Storage
Simplex:重新利用英特尔内存保护扩展来实现安全存储
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Cole, Matthew;Prakash, Aravind
- 通讯作者:Prakash, Aravind
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Aravind Prakash其他文献
A Multi-OS Cross-Layer Study of Bloating in User Programs, Kernel and Managed Execution Environments
用户程序、内核和托管执行环境中膨胀的多操作系统跨层研究
- DOI:
10.1145/3141235.3141242 - 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Anh Quach;R. Erinfolami;David Demicco;Aravind Prakash - 通讯作者:
Aravind Prakash
On the Trustworthiness of Memory Analysis—An Empirical Study from the Perspective of Binary Execution
论内存分析的可信度——二进制执行视角的实证研究
- DOI:
- 发表时间:
2015 - 期刊:
- 影响因子:7.3
- 作者:
Aravind Prakash;Eknath Venkataramani;Heng Yin;Zhiqiang Lin - 通讯作者:
Zhiqiang Lin
Bloat Factors and Binary Specialization
膨胀因素和二元专业化
- DOI:
10.1145/3338502.3359765 - 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Anh Quach;Aravind Prakash - 通讯作者:
Aravind Prakash
871 Impact of Hydrogel Spacer on Quality of Life and Dosimetry in Hypofractionated External Beam Radiotherapy for Localized Prostate Cancer
水凝胶间隔物对局限性前列腺癌大分割外照射放疗的生活质量和剂量测定的影响871(此处“871”如果是完整标题的一部分,不太清楚其确切含义,可能是编号之类的)
- DOI:
10.1016/s0167-8140(25)04374-9 - 发表时间:
2025-05-01 - 期刊:
- 影响因子:5.300
- 作者:
Aravind Prakash;Samuel Worster;Meheli Chatterjee;Farasat Kazmi;Gaurav Kapur;Robert Wade;David Maskell;Helen Swannie;Jenny Nobes - 通讯作者:
Jenny Nobes
Blood transfusions in oncology patients: The NNUH experience
- DOI:
10.1016/j.clon.2022.09.013 - 发表时间:
2022-11-01 - 期刊:
- 影响因子:
- 作者:
Deirdre Lynskey;Aravind Prakash;Yasmine Karachiwala;ALK Ho - 通讯作者:
ALK Ho
Aravind Prakash的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Aravind Prakash', 18)}}的其他基金
CRII: SaTC: Robust and Platform Independent Recovery of Design Features from C++ Binaries
CRII:SaTC:从 C 二进制文件中稳健且独立于平台的设计功能恢复
- 批准号:
1566532 - 财政年份:2016
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
相似国自然基金
Improving modelling of compact binary evolution.
- 批准号:10903001
- 批准年份:2009
- 资助金额:20.0 万元
- 项目类别:青年科学基金项目
相似海外基金
CAREER: Dynamics of Binary Anisotropic Magnetic Colloids
职业:二元各向异性磁胶体动力学
- 批准号:
2338064 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Continuing Grant
GEOBEx: Geostatistical Binary Models For Extremes
GEOBEx:极值地统计二元模型
- 批准号:
EP/Y031229/1 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Research Grant
CSR: Small: Modernizing Dynamic Binary Translation Systems
CSR:小型:现代化动态二进制翻译系统
- 批准号:
2330752 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Standard Grant
Development of Efficient Black Hole Spectroscopy and a Desktop Cluster for Detecting Compact Binary Mergers
开发高效黑洞光谱和用于检测紧凑二元合并的桌面集群
- 批准号:
2412341 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Continuing Grant
Binary Vision Transformer の専用ハードウェアに関する研究
二元视觉Transformer专用硬件研究
- 批准号:
24K02912 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
Studying Magnetized Binary Star Formation with ALMA
使用 ALMA 研究磁化双星形成
- 批准号:
23K22542 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
GEOBEx: Geostatistical Binary Models For Extremes
GEOBEx:极值地统计二元模型
- 批准号:
EP/Y031954/1 - 财政年份:2024
- 资助金额:
$ 49.99万 - 项目类别:
Research Grant
Beyond the Binary: Gender diversity in cancer health services research
超越二元:癌症卫生服务研究中的性别多样性
- 批准号:
479685 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Operating Grants
Caught between the binary : Exploring dominant representations of detransitioned people across digital platforms and publications
夹在二元之间:探索数字平台和出版物中变性者的主导表现
- 批准号:
2873127 - 财政年份:2023
- 资助金额:
$ 49.99万 - 项目类别:
Studentship














{{item.name}}会员




