课题基金 / 基金详情

Automatically Detecting and Surviving Exploitable Compiler Bugs

Automatically Detecting and Surviving Exploitable Compiler Bugs
自动检测并避免可利用的编译器错误
批准号:
EP/R011605/1
负责人:
Cristian Cadar
金额:
$85.64万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --

项目摘要

项目成果

Cristian Cadar的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The focus of this proposal is on the detection and survival of wrong code compiler defects, which we argue present a cyber-security threat that has been largely ignored to date. First, incorrectly compiled code can introduce exploitable vulnerabilities that are not visible at the source code level, and thus cannot be detected by source-level static analysers. Second, incorrectly compiled code can undermine the reliability of the application, which can have dramatic repercussions in the context of safety-critical systems. Third, wrong code compiler defects can also be the target of some of the most insidious security attacks. A crafty attacker posing as an open source developer can introduce a compiler-bug-based backdoor into a security-critical application by adding a patch that looks perfectly innocent but which, when compiled with a certain compiler, yields binary code that allows the attacker to compromise the software.In this project, we aim to explore automated techniques that can detect and prevent such problems. In particular, we plan to investigate techniques for automatically finding compiler-induced vulnerabilities in real software, approaches for understanding the extent to which an attacker could maliciously modify an application to create a compiler-induced vulnerability, and methods for preventing against such vulnerabilities at runtime.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/ms.2020.3016773
发表时间: 2021-05-01
期刊: IEEE SOFTWARE
影响因子: 3.3
作者: [Bohme, Marcel, Cadar, Cristian, Roychoudhury, Abhik]
通讯作者: Roychoudhury, Abhik
Fine-Grain Memory Object Representation in Symbolic Execution
符号执行中的细粒度内存对象表示
DOI: 10.1109/ase.2019.00089
发表时间: 2019
期刊:
影响因子: --
作者: [Nowack M]
通讯作者: Nowack M
Artifact of GrayC: Greybox Fuzzing of Compilers and Analysers for C
GrayC 的神器:C 编译器和分析器的灰盒模糊测试
DOI: 10.5281/zenodo.7948109
发表时间: 2023
期刊:
影响因子: --
作者: [Even-Mendoza K]
通讯作者: Even-Mendoza K
Closer to the edge
离边缘更近
DOI: 10.1145/3324884.3418933
发表时间: 2020
期刊:
影响因子: --
作者: [Even-Mendoza K]
通讯作者: Even-Mendoza K
10
    Automated Patch Impact Analysis (PATCH)
    • 批准号:
      EP/X040836/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $16.47万
    • 财政年份:
      2023
    • 负责人:
      Cristian Cadar
    • 依托单位:
    Improving Symbolic Execution via Targeted Program Transformations
    • 批准号:
      EP/N007166/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $36.5万
    • 财政年份:
      2016
    • 负责人:
      Cristian Cadar
    • 依托单位:
    Multi-version Execution Techniques for Increasing the Reliability and Security of Evolving Software
    • 批准号:
      EP/L002795/1
    • 项目类别:
      Fellowship
    • 资助金额:
      $124.68万
    • 财政年份:
      2014
    • 负责人:
      Cristian Cadar
    • 依托单位:
    Testing, Verifying, and Generating Software Patches Using Dynamic Symbolic Execution
    • 批准号:
      EP/J00636X/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $36.59万
    • 财政年份:
      2012
    • 负责人:
      Cristian Cadar
    • 依托单位:
    海外基金