课题基金 / 基金详情

Collaborative Research: SaTC: EDU: Creating Windows Advanced Memory Corruption Attack and Defense Teaching Modules

Collaborative Research: SaTC: EDU: Creating Windows Advanced Memory Corruption Attack and Defense Teaching Modules
协作研究:SaTC:EDU:创建 Windows 高级内存损坏攻击和防御教学模块
批准号:
2325451
负责人:
Xinwen Fu
金额:
$33.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-10-01 至 2026-09-30

项目摘要

项目成果

Xinwen Fu的其他基金

相似基金

相关文献

中文摘要
翻译
微软的Windows操作系统占有很大的市场份额,被广泛使用。因此,它们也是恶意软件等网络攻击的主要目标。在最新的Windows版本上教授软件安全主题是至关重要的。但是,针对最新的Windows系统,目前还没有系统的高级软件安全教育模块。该项目的目标是开发先进的软件安全教学模块,特别是针对最新系统的内存损坏攻击和防御。内存损坏攻击通过恶意和微妙的输入触发内存错误,通常是高级网络攻击的一部分。开发的教学模块将帮助学生了解如何使用Windows编译器和链接器的各种安全特性来对抗各种内存损坏攻击及其局限性。这将帮助学生为现实世界的bug搜索和软件安全做好准备。该项目将实现六个目标。1. innovative Armitage是Metasploit的开源图形用户界面前端,用于识别安全漏洞。由于易于使用,Armitage是一个理想的开源工具,用于演示攻击并提高安全意识。2. 基于Windows最新版本的Exploit Protection特性开发防御模块。将各种内存损坏漏洞整合到易受攻击的聊天服务器(VChat)中,该聊天服务器将作为Visual c++项目开发,并在Python中开发相应的攻击教材。在Ruby中开发Metasploit模块以应对所有内存损坏攻击,这可以与Armitage一起使用。Metasploit模块的目的是轻松演示这些攻击,并激励学生学习原理。5. 在马萨诸塞大学洛厄尔分校和中佛罗里达大学这两所参与院校,将开发好的教学模块整合到相关课程中。通过教师发展研讨会、项目网站、GitHub知识库、视频教程、CLARK(网络安全课程托管平台)、学术出版物和实地考察,向K-12学生传播开发的教学模块、软件和系统。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Microsoft Windows operating systems have a large market share and are pervasively used. As such, they are also major targets for cyberattacks, such as malware. It is critical to teach software security topics on the latest Windows versions. However, there are currently no systematic advanced software security education modules for the latest Windows system. The goal of this project is to develop advanced teaching modules on software security, particularly memory corruption attack and defense for the latest systems. A memory corruption attack triggers memory errors through malicious and delicate inputs and is often part of an advanced cyberattack. The developed teaching modules will help students understand how various security features of Windows compilers and linkers are used to fight against miscellaneous memory corruption attacks and their limitations. This will help prepare students for real-world bug hunting and software security.This project will achieve six objectives. 1. Innovating Armitage, an open-source graphical user interface front end of Metasploit, which is a tool used to identify security vulnerabilities. Armitage is an ideal open-source tool to demonstrate attacks and raise security awareness given its ease of use. 2. Developing defense modules on Exploit Protection features of the latest Windows. 3. Incorporating a variety of memory corruption vulnerabilities into a vulnerable chat server (VChat), which will be developed as a Visual C++ project, and developing corresponding attack teaching materials in Python. 4. Developing Metasploit modules in Ruby for all memory corruption attacks, which can be used with Armitage. The purpose of Metasploit modules is to demonstrate those attacks easily and motivate students to learn the principles. 5. Integrating developed teaching modules into related courses at the two participating institutions, University of Massachusetts Lowell and University of Central Florida. 6. Disseminating developed teaching modules, software and systems through a faculty development workshop, project websites, GitHub repositories, video tutorials, CLARK (a cybersecurity curriculum hosting platform), academic publications, and field trips as outreach venues to K-12 students.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: Regional: New England Cybersecurity Operation and Research Center (CORE)
  • 批准号:
    1642124
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2017
  • 负责人:
    Xinwen Fu
  • 依托单位:
REU Site: HCISec - Enhancing Undergraduate Research in Modern Human Computer Interaction Security and Privacy
  • 批准号:
    1461060
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.97万
  • 财政年份:
    2015
  • 负责人:
    Xinwen Fu
  • 依托单位:
I-Corps: Commercialization Feasibility Research and Demonstration Preparation for Third-Party Localization Toolkits
  • 批准号:
    1264047
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2012
  • 负责人:
    Xinwen Fu
  • 依托单位:
TC: Small: Collaborative Research: Membership Inference in a Differentially Private World and Beyond
  • 批准号:
    1116644
  • 项目类别:
    Standard Grant
  • 资助金额:
    $16.61万
  • 财政年份:
    2011
  • 负责人:
    Xinwen Fu
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)