CAREER: A Model-Guided and Holistic Approach for Peripheral Security
职业:模型引导的整体外围安全方法
基本信息
- 批准号:2145744
- 负责人:
- 金额:$ 52.47万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2022
- 资助国家:美国
- 起止时间:2022-02-01 至 2027-01-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Modern peripherals devices such as USB keyboards and drives, Bluetooth speakers and headsets, complement users' computer systems with rich functionality and have become an integral part of daily life. While peripheral devices offer a "Plug'n'Play" solution to ease their usage in different scenarios, attacks from these devices are increasing due to their "Trust-by-default" treatment and direct interactions with the low-level parts of the target machines (e.g., operating systems). For instance, a USB drive found in the parking lot could take complete control of an industrial control system once plugged, while a Bluetooth speaker could intercept all the network traffic of a user's laptop once connected. This work aims to systematically improve peripheral security by discovering and reducing vulnerabilities that could enable peripheral attacks ahead of time, detecting malicious tampering within peripheral devices once connected, and responding to peripheral attacks timely with assurance.This project seeks to address the broad research challenge of enabling a trustworthy and formally-verified peripheral ecosystem and designing next-gen secure peripheral devices and operating systems. Rather than targeting a specific peripheral attack, this project focuses on developing a model-guided and holistic approach for peripheral security in general, including both USB and Bluetooth, leveraging “models” extracted from peripheral specifications and stack implementations as key prior knowledge, and covering the whole life cycle of peripheral security, including pre-attack, runtime, and post-attack stages. As such, model-guided fuzzing, debloating, and formal verification reduces the attack surface exposed to peripheral devices; model-based firmware analysis, fingerprinting, and authentication enables runtime integrity of peripheral devices; model-guided provenance, patching, and formal implementation allows for immediate and assured responding actions against peripheral attacks. This project will assess all these considerations within a combination of real-world applications (e.g., Android USB security) and specification enhancements (e.g., Bluetooth security and privacy), and generalize the knowledge for securing both peripheral devices and host machines across hardware, firmware, and software stacks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
USB键盘和驱动器、蓝牙扬声器和耳机等现代外围设备为用户的计算机系统提供了丰富的功能,并已成为日常生活中不可或缺的一部分。虽然外围设备提供“即插即用”解决方案以简化它们在不同场景中的使用,但由于它们的“默认信任”处理以及与目标机器的低级部分(例如,操作系统)。例如,在停车场找到的USB驱动器一旦插入就可以完全控制工业控制系统,而蓝牙扬声器一旦连接就可以拦截用户笔记本电脑的所有网络流量。该项目旨在通过提前发现和减少可能导致外围设备攻击的漏洞,检测连接后外围设备中的恶意篡改,并及时可靠地响应外围设备攻击,从而系统地提高外围设备的安全性。该项目旨在解决实现可信赖和正式验证的外围设备生态系统以及设计下一代安全外围设备和操作系统的广泛研究挑战。该项目不是针对特定的外围设备攻击,而是专注于为一般的外围设备安全(包括USB和蓝牙)开发一种模型指导和整体方法,利用从外围设备规范和堆栈实现中提取的“模型”作为关键先验知识,并涵盖外围设备安全的整个生命周期,包括攻击前,运行时和攻击后阶段。因此,模型引导的模糊化、去浮动化和形式化验证减少了暴露于外围设备的攻击面;基于模型的固件分析、指纹识别和身份验证实现了外围设备的运行时完整性;模型引导的起源、修补和形式化实现允许针对外围设备攻击的即时且有保证的响应动作。该项目将在实际应用的组合中评估所有这些考虑因素(例如,Android USB安全性)和规范增强(例如,该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(5)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
GLeeFuzz: Fuzzing WebGL Through Error Message Guided Mutation
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Hui Peng;Zhihao Yao;A. A. Sani-A.;D. Tian;Mathias Payer
- 通讯作者:Hui Peng;Zhihao Yao;A. A. Sani-A.;D. Tian;Mathias Payer
Building GPU TEEs using CPU Secure Enclaves with GEVisor
- DOI:10.1145/3620678.3624659
- 发表时间:2023-10
- 期刊:
- 影响因子:0
- 作者:Xiaolong Wu;Dave Jing Tian;Chung Hwan Kim
- 通讯作者:Xiaolong Wu;Dave Jing Tian;Chung Hwan Kim
TruEMU: an extensible, open-source, whole-system iOS emulator
TruEMU:可扩展、开源、全系统 iOS 模拟器
- DOI:
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Nguyen, Trung;Kim, Kyungtae;Bianchi, Antonio;Tian, Dave
- 通讯作者:Tian, Dave
ShadowAuth: Backward-Compatible Automatic CAN Authentication for Legacy ECUs
- DOI:10.1145/3488932.3523263
- 发表时间:2022-05
- 期刊:
- 影响因子:0
- 作者:Sungwoo Kim;Gisu Yeo;Taegyu Kim;J. Rhee;Yuseok Jeon;Antonio Bianchi;Dongyan Xu;D. Tian
- 通讯作者:Sungwoo Kim;Gisu Yeo;Taegyu Kim;J. Rhee;Yuseok Jeon;Antonio Bianchi;Dongyan Xu;D. Tian
Fuzz The Power: Dual-role State Guided Black-box Fuzzing for USB Power Delivery
- DOI:
- 发表时间:2023
- 期刊:
- 影响因子:0
- 作者:Kyungtae Kim;Sungwoo Kim;Kevin R. B. Butler;Antonio Bianchi;R. Kennell;D. Tian
- 通讯作者:Kyungtae Kim;Sungwoo Kim;Kevin R. B. Butler;Antonio Bianchi;R. Kennell;D. Tian
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Jing Tian其他文献
To what extent are postgraduate students from China prepared for academic writing needed on UK master's courses?
中国研究生在多大程度上为英国硕士课程所需的学术写作做好了准备?
- DOI:
- 发表时间:
2012 - 期刊:
- 影响因子:0
- 作者:
Jing Tian;G. Low - 通讯作者:
G. Low
Quorum-Sensing Signal DSF Inhibits the Proliferation of Intestinal Pathogenic Bacteria and Alleviates Inflammatory Response to Suppress DSS-Induced Colitis in Zebrafish
群体感应信号 DSF 抑制斑马鱼肠道致病菌的增殖并减轻炎症反应,从而抑制 DSS 诱导的结肠炎
- DOI:
- 发表时间:
2024 - 期刊:
- 影响因子:5.9
- 作者:
Ruiya Yi;Bo Yang;Hongjie Zhu;Yu Sun;Hailan Wu;Zhihao Wang;Yongbo Lu;Ya;Jing Tian - 通讯作者:
Jing Tian
An Ontology-based Knowledge Management System for Software Testing
基于本体的软件测试知识管理系统
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
S. Vasanthapriyan;Jing Tian;Dongdong Zhao;Shengwu Xiong;Jianwen Xiang - 通讯作者:
Jianwen Xiang
Utility of Sonazoid-Enhanced Ultrasound for the Macroscopic Classification of Hepatocellular Carcinoma: A Meta-analysis
Sonazoid 增强超声在肝细胞癌宏观分类中的应用:荟萃分析
- DOI:
10.1016/j.ultrasmedbio.2022.06.015 - 发表时间:
2022 - 期刊:
- 影响因子:2.9
- 作者:
Zijie Zheng;Wei Xie;Jing Tian;Jiayi Wu;Baoming Luo;Xiaolin Xu - 通讯作者:
Xiaolin Xu
Prevalence and incidence of skin tear in older adults:A systematic review and meta-analysis.
老年人皮肤撕裂的患病率和发生率:系统评价和荟萃分析。
- DOI:
10.1016/j.jtv.2024.06.010 - 发表时间:
2024 - 期刊:
- 影响因子:2.5
- 作者:
Shenbi Yang;XiaoLi Liang;Jian She;Jing Tian;Zhifei Wen;Yanmin Tao;Hongyan Wang;Xiangeng Zhang - 通讯作者:
Xiangeng Zhang
Jing Tian的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Jing Tian', 18)}}的其他基金
Pathways to Conceptual Knowledge of Decimals
小数概念知识的途径
- 批准号:
2300947 - 财政年份:2023
- 资助金额:
$ 52.47万 - 项目类别:
Continuing Grant
LEAPS-MPS: Exploring various subgrid scale turbulence models via convergence analysis, data assimilation and deep learning
LEAPS-MPS:通过收敛分析、数据同化和深度学习探索各种亚网格尺度湍流模型
- 批准号:
2316894 - 财政年份:2023
- 资助金额:
$ 52.47万 - 项目类别:
Standard Grant
Pathways to Conceptual Knowledge of Decimals
小数概念知识的途径
- 批准号:
2347386 - 财政年份:2023
- 资助金额:
$ 52.47万 - 项目类别:
Continuing Grant
相似国自然基金
基于术中实时影像的SAM(Segment anything model)开发AI指导房间隔穿刺位置决策的增强现实模型
- 批准号:
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Development of a Linear Stochastic Model for Wind Field Reconstruction from Limited Measurement Data
- 批准号:
- 批准年份:2020
- 资助金额:40 万元
- 项目类别:
应用Agent-Based-Model研究围术期单剂量地塞米松对手术切口愈合的影响及机制
- 批准号:81771933
- 批准年份:2017
- 资助金额:50.0 万元
- 项目类别:面上项目
基于Multilevel Model的雷公藤多苷致育龄女性闭经预测模型研究
- 批准号:81503449
- 批准年份:2015
- 资助金额:18.0 万元
- 项目类别:青年科学基金项目
基于非齐性 Makov model 建立病证结合的绝经后骨质疏松症早期风险评估模型
- 批准号:30873339
- 批准年份:2008
- 资助金额:32.0 万元
- 项目类别:面上项目
相似海外基金
CRII: CPS: FAICYS: Model-Based Verification for AI-Enabled Cyber-Physical Systems Through Guided Falsification of Temporal Logic Properties
CRII:CPS:FAICYS:通过时态逻辑属性的引导伪造,对支持人工智能的网络物理系统进行基于模型的验证
- 批准号:
2347294 - 财政年份:2024
- 资助金额:
$ 52.47万 - 项目类别:
Standard Grant
Enhancing the Accuracy and Interpretability of Global Flood Models with AI: Development of a Physics-Guided Deep Learning Model Considering River Network Topology
利用人工智能提高全球洪水模型的准确性和可解释性:考虑河网拓扑的物理引导深度学习模型的开发
- 批准号:
24K17353 - 财政年份:2024
- 资助金额:
$ 52.47万 - 项目类别:
Grant-in-Aid for Early-Career Scientists
Mapping the functional topography in the human visual cortex with model-guided functional imaging
通过模型引导的功能成像绘制人类视觉皮层的功能地形图
- 批准号:
489611 - 财政年份:2023
- 资助金额:
$ 52.47万 - 项目类别:
Operating Grants
Geometric structures guided learning model and algorithms for bulk RNAseq data analysis
用于批量 RNAseq 数据分析的几何结构引导学习模型和算法
- 批准号:
10592460 - 财政年份:2022
- 资助金额:
$ 52.47万 - 项目类别:
Collaborative Research: Model-guided design of bacterial interspecies interactions and trans-organismic communication in living intercellular circuits
合作研究:活体细胞间回路中细菌种间相互作用和跨有机体通讯的模型引导设计
- 批准号:
2211040 - 财政年份:2022
- 资助金额:
$ 52.47万 - 项目类别:
Standard Grant
Collaborative Research: Model-guided design of bacterial interspecies interactions and trans-organismic communication in living intercellular circuits
合作研究:活体细胞间回路中细菌种间相互作用和跨有机体通讯的模型引导设计
- 批准号:
2211039 - 财政年份:2022
- 资助金额:
$ 52.47万 - 项目类别:
Standard Grant
Model-guided design of RNA stabilizing elements for improved coronavirus diagnostics
用于改进冠状病毒诊断的 RNA 稳定元件的模型引导设计
- 批准号:
10562816 - 财政年份:2022
- 资助金额:
$ 52.47万 - 项目类别:
Geometric structures guided learning model and algorithms for bulk RNAseq data analysis
用于批量 RNAseq 数据分析的几何结构引导学习模型和算法
- 批准号:
10710214 - 财政年份:2022
- 资助金额:
$ 52.47万 - 项目类别:
Comprehensive mapping of trafficking and functional robustness in Inward Rectifier K+ channels for variant pathogenicity prediction and model-guided engineering of chemogenetic reagents
全面绘制内向整流器 K 通道中的运输和功能鲁棒性,用于化学遗传学试剂的变异致病性预测和模型引导工程
- 批准号:
10297049 - 财政年份:2021
- 资助金额:
$ 52.47万 - 项目类别:
Machine Learning Guided Biophysical Model Development of Amino Acid and tRNA Effects on Translation-Elongation Speed
机器学习引导的氨基酸和 tRNA 对翻译延伸速度影响的生物物理模型开发
- 批准号:
2031584 - 财政年份:2021
- 资助金额:
$ 52.47万 - 项目类别:
Standard Grant