Collaborative Research: SaTC: CORE: Small: Improving Decentralized Kernel Patch Ecosystems
Collaborative Research: SaTC: CORE: Small: Improving Decentralized Kernel Patch Ecosystems
批准号:
2155213
负责人:
Zhiyun Qian
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2025-06-30
中文摘要
该项目的目标是从供应链的角度提高开源操作系统(OS)内核的安全性。由于开发全新的OS成本极高,因此大量下游OS内核是从上游OS内核(例如,Linux)以节省开发成本。然而,这也意味着下游内核的安全性取决于从上游到下游的及时补丁传播。下游的多样性和分散性会导致延迟,甚至完全错过上游补丁。更糟糕的是,由于下游的定制,推断哪些bug适用于下游并值得修补是非常耗时的。最后,即使他们知道上游漏洞存在于下游并且补丁可用,也可能需要额外的努力来移植和测试上游补丁-这对于许多下游供应商来说是一个重大的障碍,他们担心破坏东西。本项目旨在开发一系列自动化和新颖的分析,以推理补丁,错误行为及其影响。更具体地说,该项目将包括对上游补丁的分析,并推断哪些补丁修复了关键漏洞;它将自动推断哪些下游受到上游漏洞的影响,以及它所带来的安全影响;它将了解相应的上游补丁是否可以安全正确地应用。该项目的结果将减轻分析、审查和采用补丁程序的人力负担。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The objective of this project is to improve the security of open-source operating system (OS) kernels from the supply chain's perspective. As it is extremely costly to develop a brand new OS, a large number of downstream OS kernels are derived from an upstream OS kernel (e.g., Linux) to save development costs. However, this also means that the security of the downstream kernels are dependent on timely patch propagation from the upstream to downstream. The diversity and decentralized nature of downstreams causes delays or even missed upstream patches altogether. Even worse, due to customizations in the downstreams, it is time-consuming to infer which bugs are applicable to downstream and worth patching. Finally, even if they know an upstream vulnerability exists in a downstream and a patch is available, it may require additional efforts to port and test upstream patches --- a significant hurdle for many downstream vendors who are wary of breaking things.This project aims to develop a series of automated and novel analyses to reason about patches, bug behaviors, and their impacts. More specifically, the project will include an analysis of upstream patches and infer which ones fix critical bugs; it will automatically infer which downstreams are affected by an upstream bug and what security impact it bears; it will understand whether the corresponding upstream patch can be applied safely and correctly. The results of the project will alleviate the human burden in analyzing, reviewing, and adopting patches. Ultimately, they will improve the security of the entire open-source OS ecosystem.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Small: Self-Driving Continuous Fuzzing
-
批准号:2247881
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2023
-
负责人:Zhiyun Qian
-
依托单位:
SaTC: CORE: Small: Collaborative: Deep and Efficient Dynamic Analysis of Operating System Kernels
-
批准号:1953933
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2020
-
负责人:Zhiyun Qian
-
依托单位:
SaTC: CORE: Small: Collaborative: The Web Ad Technology Arms Race: Measurement, Analysis, and Countermeasures
-
批准号:1719147
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2017
-
负责人:Zhiyun Qian
-
依托单位:
CAREER: Empowering Attacker-Centric Security Analysis of Network Protocols
-
批准号:1652954
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2017
-
负责人:Zhiyun Qian
-
依托单位:
NeTS: Small: Collaborative Research: Practical HTTPS Traffic Manipulation At Middleboxes
-
批准号:1619391
-
项目类别:Standard Grant
-
资助金额:$14.0万
-
财政年份:2016
-
负责人:Zhiyun Qian
-
依托单位:
TWC: Small: Cache-based Side Channel Attacks on Smartphone Graphics Buffers: New Vulnerabilities and Defenses
-
批准号:1619450
-
项目类别:Standard Grant
-
资助金额:$51.6万
-
财政年份:2016
-
负责人:Zhiyun Qian
-
依托单位:
CSR: Small: Collaborative Research: Taming Mobile Hardware & OS Diversity for Comprehensive Software Analysis
-
批准号:1617573
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2016
-
负责人:Zhiyun Qian
-
依托单位:
CRII: SaTC: Analyzing and verifying the security of TCP stacks under multi-entity interactions
-
批准号:1464410
-
项目类别:Standard Grant
-
资助金额:$17.25万
-
财政年份:2015
-
负责人:Zhiyun Qian
-
依托单位:
TWC: Small: Collaborative: Multipath TCP Side Channel Vulnerabilities and Defenses
-
批准号:1528114
-
项目类别:Standard Grant
-
资助金额:$16.7万
-
财政年份:2015
-
负责人:Zhiyun Qian
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: