AppControl: Enforcing Application Behaviour through Type-Based Constraints
AppControl: Enforcing Application Behaviour through Type-Based Constraints
批准号:
EP/V000462/1
负责人:
Wim Vanderbauwhede
金额:
$188.97万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2020
资助国家:
英国
项目状态:
未结题
起止时间:
2020 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Background: The ProblemWith the current state of the art, it is possible to limit the access privileges of a third-party program running on a computer system. The addition of architectural capabilities such as provided by CHERI enable unprecedented fine-grained memory protection and isolation. These mechanisms are however not sufficient to control the behaviour of a program so that it follows the intended specification. For example, if a program performs network access, it is not possible to ensure that the network location accessed is intended by the developer, or the result of a backdoor in the system. In general, this is the case for any system call performed by the program. As a result, malicious programs can e.g. participate in DDoS attacks, or send information about the system to a Command and Control server, etc. It is also the case for library calls, which could perform unspecified actions within the memory space of a process.Project AimThe aim of this project is to enhance the provision of Digital Security By Design for mission-critical Systems-on-Chip through Capability hardware-enabled Design-by-Specification. What this means is that the Systems-on-Chip has a formal, executable specification (typically created by the system architect), and every software component of the SoC is forced to adhere to this specification. Programs with incompatible specifications cannot run; unspecified run-time behaviour will raise an exception. For the above example, the specification could govern the network access and also the access to system information. The practical realisation of this aim is through the extension of programming languages to supports expressive specifications and a toolchain which ensures that the specifications are enforced at run time on Capability hardware. Key Ideas in a NutshellOur vision of how to achieve this goal is through the use of behavioural type systems, i.e. the specification of the SoC and each of its individual components are expressed as a type, which effectively and formally describes the allowed interfaces and interactions of each component. This type-based specification will be an integral component of the program executable, and be validated against an overall system specification by the operating system.This proposal focuses on software components, and will build on the capability hardware for enforcement of the type-based specifications. The type-based Design-by-Specification of hardware components is the topic of the EPSRC Border Patrol project (EP/N028201/1), which will run until 2023 and therefore present great potential for synergies with the current proposal.Prior WorkIn our current EPSRC project Border Patrol (EP/N028201/1) we investigate digital security by design for the design of hardware IP-core based SoCs. The key mechanism is the use of type-driven design-by-specification. A design's specification is encoded in the type system, so that the implementation must follow the specification. Adherence to the spec can be enforced at design time for trusted modules, and at run time for untrusted modules by patrolling the untrusted module's borders with FSM-based run-time type checkers.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/lra.2023.3280749
发表时间:
2023-07-01
期刊:
IEEE ROBOTICS AND AUTOMATION LETTERS
影响因子:
5.2
作者:
[Abolfathi,Kiana, Rosales-Medina,Jose A., Hoshiar,Ali Kafash]
通讯作者:
Hoshiar,Ali Kafash
Book review
书评
DOI:
10.1016/j.artint.2019.103175
发表时间:
2019
期刊:
Artificial Intelligence
影响因子:
14.4
作者:
[Halpern, Joseph Y.]
通讯作者:
Halpern, Joseph Y.
Designing Asynchronous Multiparty Protocols with Crash-Stop Failures
设计具有紧急停止故障的异步多方协议
DOI:
10.48550/arxiv.2305.06238
发表时间:
2023
期刊:
影响因子:
--
作者:
[Barwell A]
通讯作者:
Barwell A
DOI:
10.1145/3610612.3610614
发表时间:
2023
期刊:
影响因子:
--
作者:
[Barbanera F]
通讯作者:
Barbanera F
Task Mapping and Scheduling in FPGA-based Heterogeneous Real-time Systems: A RISC-V Case-Study
基于 FPGA 的异构实时系统中的任务映射和调度:RISC-V 案例研究
DOI:
10.1109/dsd57027.2022.00027
发表时间:
2022
期刊:
影响因子:
--
作者:
[Ahmadi-Pour S]
通讯作者:
Ahmadi-Pour S
共 8 条
Morello-HAT: Morello High-Level API and Tooling
-
批准号:EP/X015955/1
-
项目类别:Research Grant
-
资助金额:$143.81万
-
财政年份:2022
-
负责人:Wim Vanderbauwhede
-
依托单位:
Border Patrol: Improving Smart Device Security through Type-Aware Systems Design
-
批准号:EP/N028201/1
-
项目类别:Research Grant
-
资助金额:$224.99万
-
财政年份:2017
-
负责人:Wim Vanderbauwhede
-
依托单位:
Exploiting Parallelism through Type Transformations for Hybrid Manycore Systems
-
批准号:EP/L00058X/1
-
项目类别:Research Grant
-
资助金额:$196.18万
-
财政年份:2014
-
负责人:Wim Vanderbauwhede
-
依托单位:
Hardware Acceleration of Co-Simulation for the Study of Extreme Weather Events
-
批准号:EP/L026201/1
-
项目类别:Research Grant
-
资助金额:$2.82万
-
财政年份:2014
-
负责人:Wim Vanderbauwhede
-
依托单位:
Hardware Acceleration of Simulations of Extreme Weather Events
-
批准号:EP/K000802/1
-
项目类别:Research Grant
-
资助金额:$3.23万
-
财政年份:2012
-
负责人:Wim Vanderbauwhede
-
依托单位:
海外基金