CAREER: Improving the Lifecycle Security of Microcontroller Devices

职业:提高微控制器设备的生命周期安全性

基本信息

  • 批准号:
    2238264
  • 负责人:
  • 金额:
    $ 53.26万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2023
  • 资助国家:
    美国
  • 起止时间:
    2023-03-15 至 2028-02-29
  • 项目状态:
    未结题

项目摘要

Microcontroller units (MCUs) drive many security- and safety-critical embedded applications. However, they inherit software bugs present in all computing systems. Firmware vulnerabilities have thus become one of the main targets of real-world exploitation. Successful exploitation can cause disastrous consequences to critical infrastructures (e.g., power outages and plant damage) and endanger human lives (e.g., by disabling a pacemaker). In the software community, there has been a rich body of knowledge regarding bug discovery and attack mitigation. However, it is notoriously difficult to apply these results to MCU firmware. Indeed, MCU firmware runs on resource-constrained hardware with heterogeneous architectures, integrates custom runtime environments, and makes unpredictable interactions with the physical world. This renders existing dynamic analysis techniques incompatible, expensive, and ineffective. The proposed research will cross the technical barriers imposed by the aforementioned challenges and greatly enrich the arsenal of MCU firmware security with new knowledge, frameworks, analysis tools, and supporting techniques. Due to the critical roles that MCU devices take in real life, this project will make huge progress towards securing the cyberspace and enhancing national security. A key observation of this project is that MCU devices usually cannot operate by themselves. Rather, they have to rely on certain external computers in their entire life cycles. Therefore, around a unifying theme of offloading security analysis from the original application workload to more capable nearby workstations or hubs, this project will deliver a series of new methodologies and theories to significantly improve the lifetime security of MCU devices. With the decoupled design, three research thrusts will be investigated. The first thrust focuses on new techniques to automatically discover firmware vulnerabilities, such as bugs lurking deeply in the program space. The second thrust targets run-time monitoring of firmware execution in the production environment, allowing the stakeholders to detect ongoing attacks and catch bugs that never happen during in-house testing. The third thrust, cooperating with the second thrust, investigates vulnerability remediation techniques, in particular, how to efficiently diagnose production bugs without leaking privacy. The outcomes of this research will be freely distributed to the community. This research will also be integrated into the investigator’s education plan to develop a set of Virtual Machine-based labs to educate young minds and future embedded system developers and architects about MCU security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
微控制器单元(MCU)驱动着许多对安全和安全至关重要的嵌入式应用。然而,它们继承了所有计算系统中存在的软件错误。固件漏洞因此成为现实世界利用的主要目标之一。成功利用漏洞可能会对关键基础设施造成灾难性后果(例如,停电和工厂损坏)并危及人的生命(例如,通过禁用起搏器)。在软件社区中,已经有了关于缺陷发现和攻击缓解的丰富知识。然而,将这些结果应用于MCU固件是非常困难的。事实上,MCU固件在具有异构架构的资源受限硬件上运行,集成自定义运行时环境,并与物理世界进行不可预测的交互。这使得现有的动态分析技术不兼容、昂贵且无效。拟议的研究将跨越上述挑战所带来的技术障碍,并通过新的知识,框架,分析工具和支持技术极大地丰富MCU固件安全性。由于MCU设备在真实的生活中发挥的关键作用,该项目将在保护网络空间和增强国家安全方面取得巨大进展。该项目的一个关键观察结果是,MCU设备通常不能自行操作。相反,它们在整个生命周期中必须依赖某些外部计算机。因此,围绕将安全分析从原始应用工作负载卸载到附近功能更强大的工作站或集线器的统一主题,该项目将提供一系列新的方法和理论,以显着提高MCU设备的生命周期安全性。通过解耦设计,将研究三个研究重点。第一个重点是自动发现固件漏洞的新技术,比如潜伏在程序空间深处的bug。第二个目标是对生产环境中的固件执行进行运行时监控,允许利益相关者检测正在进行的攻击并捕获内部测试期间从未发生的错误。第三个重点与第二个重点合作,研究漏洞修复技术,特别是如何在不泄露隐私的情况下有效地诊断生产错误。这项研究的成果将免费分发给社区。这项研究也将被整合到研究者的教育计划中,开发一套基于虚拟机的实验室,以教育年轻人和未来的嵌入式系统开发人员和架构师关于MCU安全的知识。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Le Guan其他文献

Reviewing IoT Security via Logic Bugs in IoT Platforms and Systems
  • DOI:
    DOI 10.1109/JIOT.2021.3059457
  • 发表时间:
  • 期刊:
  • 影响因子:
    10.6
  • 作者:
    Wei Zhou;Chen Cao;Dongdong Huo;Kai Cheng;Lan Zhang;Le Guan;Tao Liu;Yan Jia;Yaowen Zheng;Yuqing Zhang;Limin Sun;Yazhe Wang;Peng Liu
  • 通讯作者:
    Peng Liu
Inheritance patterns of anthocyanins in berry skin and flesh of the interspecific population derived from teinturier grape
  • DOI:
    https://doi.org/10.1007/s10681-019-2342-4(0123456789().,-volV) (0123456789().,-volV)
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
  • 作者:
    Le Guan;Peige Fan;Shao-Hua Li;Zhenchang Liang;Ben-Hong Wu
  • 通讯作者:
    Ben-Hong Wu
Enhancement of antimicrobial properties of plasma electrolytic oxidation coatings on aluminum alloy surfaces with CuO nanoparticles
  • DOI:
    10.1016/j.ceramint.2024.10.404
  • 发表时间:
    2024-12-15
  • 期刊:
  • 影响因子:
  • 作者:
    Pengxiang Lv;XingRui Xu;WenPing Zhou;Qi Dong;Le Guan;ZhaoWei Li;ShenXia Sun;Lu Li
  • 通讯作者:
    Lu Li
Vulnerable Region-Aware Greybox Fuzzing
易受攻击区域感知的灰盒模糊测试
  • DOI:
    10.1007/s11390-021-1196-0
  • 发表时间:
    2021-09
  • 期刊:
  • 影响因子:
    0.7
  • 作者:
    Ling-Yun Situ;Zhi-Qiang Zuo;Le Guan;Lin-Zhang Wang;Xuan-Dong Li;Jin Shi;Peng Liu
  • 通讯作者:
    Peng Liu
Reviewing IoT Security via Logic Bugs in IoT Platforms and Systems
通过物联网平台和系统中的逻辑错误审查物联网安全
  • DOI:
    10.1109/jiot.2021.3059457
  • 发表时间:
    2021-02
  • 期刊:
  • 影响因子:
    10.6
  • 作者:
    Wei Zhou;Chen Cao;Dongdong Huo;Kai Cheng;Lan Zhang;Le Guan;Tao Liu;Yan Jia;Yaowen Zheng;Yuqing Zhang;Limin Sun;Yazhe Wang;Peng Liu
  • 通讯作者:
    Peng Liu

Le Guan的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

相似国自然基金

Improving modelling of compact binary evolution.
  • 批准号:
    10903001
  • 批准年份:
    2009
  • 资助金额:
    20.0 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

CAREER: Balancing the global alkalinity cycle by improving models of river chemistry
职业:通过改进河流化学模型平衡全球碱度循环
  • 批准号:
    2338139
  • 财政年份:
    2025
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Continuing Grant
Understanding and Improving Electrochemical Carbon Dioxide Capture
了解和改进电化学二氧化碳捕获
  • 批准号:
    MR/Y034244/1
  • 财政年份:
    2025
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Fellowship
RII Track-4:NSF: Improving subseasonal-to-seasonal forecasts of Central Pacific extreme hydrometeorological events and their impacts in Hawaii
RII Track-4:NSF:改进中太平洋极端水文气象事件的次季节到季节预报及其对夏威夷的影响
  • 批准号:
    2327232
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Standard Grant
CAREER: Improving Real-world Performance of AI Biosignal Algorithms
职业:提高人工智能生物信号算法的实际性能
  • 批准号:
    2339669
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Continuing Grant
Improving Resilience of MCDI for Water Supply in Remote Communities
提高偏远社区供水的 MCDI 弹性
  • 批准号:
    DP240101469
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Discovery Projects
Improving efficacy of biopesticides through understanding mode of action
通过了解作用方式提高生物农药的功效
  • 批准号:
    IE230100103
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Early Career Industry Fellowships
TRUST2 - Improving TRUST in artificial intelligence and machine learning for critical building management
TRUST2 - 提高关键建筑管理的人工智能和机器学习的信任度
  • 批准号:
    10093095
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Collaborative R&D
mPatch: a rapid test for improving diagnosis and triage of melanoma patients in primary care
mPatch:一种快速测试,用于改善初级保健中黑色素瘤患者的诊断和分诊
  • 批准号:
    MR/Y503381/1
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Research Grant
Multi-agent Self-improving of Large Language Models (LLMs)
大型语言模型 (LLM) 的多智能体自我改进
  • 批准号:
    2903811
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Studentship
Improving females' health and performance by mitigating heat strain
通过缓解热应激改善女性的健康和表现
  • 批准号:
    MR/X036235/1
  • 财政年份:
    2024
  • 资助金额:
    $ 53.26万
  • 项目类别:
    Fellowship
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了