课题基金 / 基金详情

SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks

SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks
SaTC:核心:小型:针对面向数据和瞬态执行攻击的选择性数据保护
批准号:
2104148
负责人:
Michail Polychronakis
金额:
$49.91万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-07-01 至 2025-06-30

项目摘要

项目成果

Michail Polychronakis的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The exploitation of software vulnerabilities caused by memory errors has become more challenging due to the deployment of numerous exploit mitigation technologies. Consequently, instead of striving to gain arbitrary code execution capabilities, attackers have turned their attention to the leakage of sensitive process data through memory disclosure vulnerabilities. To make matters worse, the threat of data leakage has been exacerbated by the recent spate of transient execution attacks, which can leak otherwise inaccessible process data through residual microarchitectural side effects. To defend against the emerging threat of data-oriented attacks, the project will investigate practical selective data protection techniques by focusing on i) enabling developers to protect sensitive data with minimal manual effort; ii) protecting sensitive data against both memory disclosure vulnerabilities and transient execution attacks; and iii) maintaining compatibility with large-scale real-world applications. The outcomes of the project are expected to improve the state of the art in defenses against data-oriented and transient execution attacks and achieve substantial practical impact by shielding existing vulnerable applications against exploitation, benefiting both end users and security researchers. The project will also provide students the opportunity to conduct research in cybersecurity, and will foster the integration of cybersecurity into high school education through hands-on workshops for students and seminars for science teachers.To defend against the emerging threats of memory disclosure vulnerabilities and transient execution attacks, the project will investigate selective data protection techniques based on in-memory data encryption, centered around three innovative aspects. First, elevating data protection as a core language feature will enable developers to effortlessly enable in-memory encryption of data they deem critical. Besides C/C++, the project will also focus on JavaScript and Rust, which, although immune against memory disclosure vulnerabilities, are still prone to transient execution attacks. Second, a hybrid approach that combines static pointer analysis with scoped dynamic data flow tracking will minimize the heavyweight instrumentation required for keeping sensitive data encrypted in memory. The key insight behind this technique is that the inherent over-approximation of pointer analysis can be ameliorated by relying on lightweight label lookups to determine if potentially sensitive data is actually sensitive. Third, the sensitivity of pointer analysis can be increased in a scalable way by i) introducing a summarization-based context-sensitive heap modeling approach tailored to the extensive use of memory wrappers in popular applications, and ii) selectively increasing sensitivity only at certain parts of the program where it is likely to be beneficial to the overall analysis precision.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Decap: Deprivileging Programs by Reducing Their Capabilities
Decap:通过降低程序的能力来剥夺程序的特权
DOI: 10.1145/3545948.3545978
发表时间: 2022
期刊: Intrusions and Defenses (RAID
影响因子: --
作者: [Hasan, Md Mehedi, Ghavamnia, Seyedhamed, Polychronakis, Michalis]
通讯作者: Polychronakis, Michalis
CAREER: Principled and Practical Software Shielding against Advanced Exploits
  • 批准号:
    1749895
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $49.99万
  • 财政年份:
    2018
  • 负责人:
    Michail Polychronakis
  • 依托单位:
TWC: Small: Combating Environment-aware Malware
  • 批准号:
    1617902
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.8万
  • 财政年份:
    2016
  • 负责人:
    Michail Polychronakis
  • 依托单位:
CSR: Small: An Information Accountability Architecture for Distributed Enterprise Systems
  • 批准号:
    0914312
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.0万
  • 财政年份:
    2009
  • 负责人:
    Michail Polychronakis
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: