SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks
SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks
批准号:
2104148
负责人:
Michail Polychronakis
金额:
$49.91万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-07-01 至 2025-06-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The exploitation of software vulnerabilities caused by memory errors has become more challenging due to the deployment of numerous exploit mitigation technologies. Consequently, instead of striving to gain arbitrary code execution capabilities, attackers have turned their attention to the leakage of sensitive process data through memory disclosure vulnerabilities. To make matters worse, the threat of data leakage has been exacerbated by the recent spate of transient execution attacks, which can leak otherwise inaccessible process data through residual microarchitectural side effects. To defend against the emerging threat of data-oriented attacks, the project will investigate practical selective data protection techniques by focusing on i) enabling developers to protect sensitive data with minimal manual effort; ii) protecting sensitive data against both memory disclosure vulnerabilities and transient execution attacks; and iii) maintaining compatibility with large-scale real-world applications. The outcomes of the project are expected to improve the state of the art in defenses against data-oriented and transient execution attacks and achieve substantial practical impact by shielding existing vulnerable applications against exploitation, benefiting both end users and security researchers. The project will also provide students the opportunity to conduct research in cybersecurity, and will foster the integration of cybersecurity into high school education through hands-on workshops for students and seminars for science teachers.To defend against the emerging threats of memory disclosure vulnerabilities and transient execution attacks, the project will investigate selective data protection techniques based on in-memory data encryption, centered around three innovative aspects. First, elevating data protection as a core language feature will enable developers to effortlessly enable in-memory encryption of data they deem critical. Besides C/C++, the project will also focus on JavaScript and Rust, which, although immune against memory disclosure vulnerabilities, are still prone to transient execution attacks. Second, a hybrid approach that combines static pointer analysis with scoped dynamic data flow tracking will minimize the heavyweight instrumentation required for keeping sensitive data encrypted in memory. The key insight behind this technique is that the inherent over-approximation of pointer analysis can be ameliorated by relying on lightweight label lookups to determine if potentially sensitive data is actually sensitive. Third, the sensitivity of pointer analysis can be increased in a scalable way by i) introducing a summarization-based context-sensitive heap modeling approach tailored to the extensive use of memory wrappers in popular applications, and ii) selectively increasing sensitivity only at certain parts of the program where it is likely to be beneficial to the overall analysis precision.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Decap: Deprivileging Programs by Reducing Their Capabilities
Decap:通过降低程序的能力来剥夺程序的特权
DOI:
10.1145/3545948.3545978
发表时间:
2022
期刊:
Intrusions and Defenses (RAID
影响因子:
--
作者:
[Hasan, Md Mehedi, Ghavamnia, Seyedhamed, Polychronakis, Michalis]
通讯作者:
Polychronakis, Michalis
CAREER: Principled and Practical Software Shielding against Advanced Exploits
-
批准号:1749895
-
项目类别:Continuing Grant
-
资助金额:$49.99万
-
财政年份:2018
-
负责人:Michail Polychronakis
-
依托单位:
TWC: Small: Combating Environment-aware Malware
-
批准号:1617902
-
项目类别:Standard Grant
-
资助金额:$49.8万
-
财政年份:2016
-
负责人:Michail Polychronakis
-
依托单位:
CSR: Small: An Information Accountability Architecture for Distributed Enterprise Systems
-
批准号:0914312
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2009
-
负责人:Michail Polychronakis
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: