ERI: ECCS: Concealing Side-Channels in Real-Time Schedulers
ERI: ECCS: Concealing Side-Channels in Real-Time Schedulers
批准号:
2138295
负责人:
Sergio Salinas Monroy
金额:
$20.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-03-01 至 2025-02-28
中文摘要
具有实时(即严格的时间和安全性)要求的系统通常被大量设计为可预测其正确操作。这种确定性允许攻击者发起侧通道攻击,推断敏感信息,甚至通过拒绝对关键资源的访问来破坏系统的稳定。因此,本项目探索了在当前和未来的实时系统中关闭侧通道的系统方法。在这项工作中提出的分析技术和系统级框架的发展将内在地使现代社会的关键实时系统(如飞机,汽车,电网,无人地面和空中飞行器,卫星,制造工厂,工业控制系统,医疗设备和关键基础设施,仅举几例)更加安全,因此更安全。这项工作的成果将使研究人员和系统工程师更接近于理解如何整合两个看似不同但必不可少的领域——实时系统和网络安全——同时更好地理解这两个领域。该奖项支持博士生的培训,本科生的研究机会,以及将研究成果整合到教育材料中,从而提高网络物理系统和网络安全领域下一代技术劳动力的知识。此外,该项目还为K-12学生的网络安全教育、培训和推广计划奠定了基础。本文研究了实时系统中基于调度的侧信道信息泄漏问题,并通过引入“调度随机化”的概念来缓解这种泄漏。提出的研究在三个方向上推进了安全实时系统的设计:(a)通过设计新的分析模型和一类新的调度程序来混淆任务执行顺序,(b)构成“指标”来评估系统的安全性,以及(c)将随机化技术集成到现有的实时操作系统中。作为该项目的一部分开发的调度器插件和框架将公开可用。课程材料和教学内容也将提供给教育工作者。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Systems with real-time (i.e., stringent temporal and safety) requirements are often heavily engineered to be predictable for their correct operation. Such determinism allows attackers to launch side-channel attacks, infer sensitive information, or even destabilize the system by denying access to critical resources. Hence, this project explores systematic methods to close side-channels in current and future real-time systems. The development of analysis techniques and system-level frameworks proposed in this work will inherently make critical real-time systems of modern society (such as aircraft, automobiles, power grid, unmanned ground and aerial vehicles, satellites, manufacturing plants, industrial control systems, medical devices, and critical infrastructures, to name a few) more secure, and hence, safer. The outcomes of this work will bring researchers and system engineers one step closer to understanding how to integrate two seemingly diverse yet essential fields -- real-time systems and cyber-security -- while gaining a better understanding of both areas. This award supports the training of Ph.D. students, research exposure to undergraduates, and the integration of research findings into educational materials, and hence, enhances the knowledge of the next-generation technological workforce in cyber-physical systems and cyber-security sectors. Further, the project serves as a foundation for cyber-security education, training, and outreach programs for the K-12 students. This proposal investigates the problem of schedule-based side-channel information leakage in real-time systems and aims to mitigate such leakage by introducing the concept of "schedule randomization". The proposed research advances the design of secure real-time systems in three directions: (a) by devising novel analytical models and a new class of schedulers to obfuscate task execution orders, (b) constituting "metrics" to evaluate the system's security, and (c) integrating randomization techniques into existing real-time operating systems. The scheduler plugins and frameworks developed as a part of this project will be publicly available. The curriculum materials and pedagogical contents will also be made available to the educators.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Work in Progress: Exploring Schedule-Based Side-Channels in TrustZone-Enabled Real-Time Systems
正在进行的工作:探索 TrustZone 实时系统中基于计划的侧通道
DOI:
10.1109/rtas54340.2022.00033
发表时间:
2022
期刊:
BP Track
影响因子:
--
作者:
[Aguida, Mohamed Anis, Hasan, Monowar]
通讯作者:
Hasan, Monowar
CyberCorps Scholarship for Service: Graduating Workforce-Ready Cybersecurity Professionals
-
批准号:2235135
-
项目类别:Continuing Grant
-
资助金额:$240.95万
-
财政年份:2023
-
负责人:Sergio Salinas Monroy
-
依托单位:
国内基金
海外基金
自愈合ECCs力学性能恢复(HIRMP)机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:DAS AVIK KUMAR
-
依托单位: