课题基金 / 基金详情

CAREER: Principled and practical secure compilation using WebAssembly

CAREER: Principled and practical secure compilation using WebAssembly
职业:使用 WebAssembly 进行原理性且实用的安全编译
批准号:
2048262
负责人:
Deian Stefan
金额:
$60.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-03-01 至 2026-02-28

项目摘要

项目成果

Deian Stefan的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Building secure computer systems today is hard: a single bug in the source code that programmers write or in the compilers they use to generate machine code could expose systems to attack. Secure compilation is a principled approach to building systems with end-to-end security guarantees from the start. When compiling code, secure compilers ensure that the security properties of high-level code are preserved down to the machine code level. Unfortunately, the gap between the theory of secure compilation and practice is huge. In particular, existing real-world industrial compilers are not secure compilers. The goal of this project is to bridge this gap by extending the industrial WebAssembly bytecode into a unifying principled and practical abstraction for secure compilation. To this end, this project will develop (1) novel techniques and principles which will serve as foundations for end-to-end secure systems and (2) new tools that will allow programmers to build new secure systems and verify the security of existing ones. The results of this project could make hundreds of millions of users safer: end-to-end security guarantees can prevent exploits in widely-used systems, from web browsers to next generation cloud platforms. The project will also contribute to the education of both college and high school students, and train the next generation engineers how to build end-to-end secure systems. This project takes a principled and practical approach to building secure systems by turning WebAssembly into a secure compilations intermediate representation (IR): a target IR for secure compilers from high-level languages and as a source IR for secure compilers to machine code. Turning WebAssembly into a secure compilation IR requires addressing research challenges on two fronts. First, WebAssembly currently does not expose any abstractions for reasoning about high-level security properties, like memory-safety or constant-time. This makes it hard to build secure compilers to WebAssembly. Second, existing compilers of WebAssembly are not proven to preserve any security properties at the machine code level; bugs in compilers and microarchitectural details could both undermine WebAssembly's security guarantees (and thus the security of the systems that rely on these guarantees). This project tackles these challenges by (1) developing secure compilers of WebAssembly to native platforms, (2) extending WebAssembly with new abstractions (e.g., for memory-safety and constant-time) that make it possible to build secure compilers to WebAssembly, and (3) building secure compilers from high-level languages to WebAssembly that preserve properties like memory-safety and constant-time end-to-end. The project will yield both new innovations in formal reasoning and advances in practical secure systems building.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2022
期刊: The 17th Workshop on Programming Languages and Analysis for Security
影响因子: --
作者: [Shravan Narayan, Tal Garfinkel]
通讯作者: Shravan Narayan, Tal Garfinkel
Isolation without taxation: near-zero-cost transitions for WebAssembly and SFI
无需纳税的隔离:WebAssembly 和 SFI 的近乎零成本转换
DOI: 10.1145/3498688
发表时间: 2022
期刊: Proceedings of the ACM on Programming Languages
影响因子: --
作者: [Kolosick, Matthew, Narayan, Shravan, Johnson, Evan, Watt, Conrad, LeMay, Michael, Garg, Deepak, Jhala, Ranjit, Stefan, Deian]
通讯作者: Stefan, Deian
DOI: 10.1109/sp46215.2023.10179357
发表时间: 2023-05
期刊: 2023 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者: [Evan Johnson;Evan Laufer;Zijie Zhao;D. Gohman;Shravan Narayan;S. Savage;D. Stefan;Fraser Brown-Fraser-Brow]
通讯作者: Evan Johnson;Evan Laufer;Zijie Zhao;D. Gohman;Shravan Narayan;S. Savage;D. Stefan;Fraser Brown-Fraser-Brow
SoK: Practical Foundations for Software Spectre Defenses
SoK:软件幽灵防御的实用基础
DOI: --
发表时间: 2022
期刊: 43rd IEEE Symposium on Security and Privacy
影响因子: --
作者: [Sunjay Cauligi, Craig Disselkoen]
通讯作者: Sunjay Cauligi, Craig Disselkoen
10
    Collaborative Research: SaTC: CORE: Medium: Refine the Gap: Establishing Safety for Modern Foreign Function Interfaces
    • 批准号:
      2327336
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $52.64万
    • 财政年份:
      2023
    • 负责人:
      Deian Stefan
    • 依托单位:
    Collaborative Research: SaTC: CORE: Medium: End-to-end Verified Secure Sandboxed Systems
    • 批准号:
      2155235
    • 项目类别:
      Standard Grant
    • 资助金额:
      $90.0万
    • 财政年份:
      2022
    • 负责人:
      Deian Stefan
    • 依托单位:
    Collaborative Research: SaTC: CORE: Large: Building and Deploying a Verified JavaScript Runtime
    • 批准号:
      2120642
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $127.0万
    • 财政年份:
      2021
    • 负责人:
      Deian Stefan
    • 依托单位:
    FMitF: Collaborative Research: Track I: Finding and Eliminating Bugs in Operating Systems
    • 批准号:
      1918573
    • 项目类别:
      Standard Grant
    • 资助金额:
      $50.0万
    • 财政年份:
      2019
    • 负责人:
      Deian Stefan
    • 依托单位:
    海外基金