Tools and trade-offs for security adaptation
Tools and trade-offs for security adaptation
批准号:
RGPIN-2015-06048
负责人:
Anderson, Jonathan
金额:
$2.11万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2016
资助国家:
加拿大
项目状态:
已结题
起止时间:
2016-01-01 至 2017-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
From Web browsers to industrial control systems, software is increasingly subject to attacks it was not designed to defend against. As the complexity of application requirements increases, developers incorporate modules with different provenance from their own code into hostile, Internet-connected environments, introducing new attack vectors into widely-deployed systems. For instance, the open-source FFmpeg project allows users to manipulate and convert various formats of audio/video content. Users have trusted FFmpeg on their own computers for years, but when integrated into the Chrome Web browser and exposed to arbitrary content on the Internet, over a thousand previously-undetected security vulnerabilities were brought to light. Industrial control systems (ICSs) incorporate third-party software to provide modern functionality such as Web interfaces, but this software can introduce security vulnerabilities such as Heartbleed.
The risks introduced by software composition cannot be simply eliminated by purging all untrustworthy code. First, much “risky” code — such as media codecs in Web browsers — provides essential functionality and cannot be expunged, so re-writing would be required (causing extreme duplication of effort). Second, re-writing software may itself introduce vulnerabilities: a performant codec requires low-level, inherently risky code, so a new version might simply introduce different vulnerabilities than the first. For this reason, the US Department of Homeland Security advises ICS vendors to employ third-party Web servers rather than write their own: the third parties are better at sanitizing network inputs.
Modern operating systems, programming languages and — increasingly — processors provide us with tools for securing software, but most existing software cannot benefit from them without substantial re-writing. Since we have determined that we cannot purge or re-write this software, we must instead adapt it. This research program will develop tools and technique for adapting existing software to use new security features. The goal is to turn current asymmetries on their heads: whereas today a minority of applications are protected, we will seek to enable the majority to use modern security features to protect users. This will give defenders, rather than attackers, the position of natural superiority and give users a chance at protecting their data well by default.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Tools and trade-offs for security adaptation
-
批准号:RGPIN-2015-06048
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2021
-
负责人:Anderson, Jonathan
-
依托单位:
Tools and trade-offs for security adaptation
-
批准号:RGPIN-2015-06048
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2020
-
负责人:Anderson, Jonathan
-
依托单位:
Tools and trade-offs for security adaptation
-
批准号:RGPIN-2015-06048
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2019
-
负责人:Anderson, Jonathan
-
依托单位:
Tools and trade-offs for security adaptation
-
批准号:RGPIN-2015-06048
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2018
-
负责人:Anderson, Jonathan
-
依托单位:
Tools and trade-offs for security adaptation
-
批准号:RGPIN-2015-06048
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2017
-
负责人:Anderson, Jonathan
-
依托单位:
Efficient Modeling of Microwave Circuits for Applications in Imaging Systems
-
批准号:497949-2016
-
项目类别:University Undergraduate Student Research Awards
-
资助金额:$0.33万
-
财政年份:2016
-
负责人:Anderson, Jonathan
-
依托单位:
Tools and trade-offs for security adaptation
-
批准号:RGPIN-2015-06048
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2015
-
负责人:Anderson, Jonathan
-
依托单位:
Noise Characterization for Side Channel Attacks on Stream Cipher Hardware
-
批准号:332401-2008
-
项目类别:Postgraduate Scholarships - Doctoral
-
资助金额:$0.76万
-
财政年份:2010
-
负责人:Anderson, Jonathan
-
依托单位:
Noise Characterization for Side Channel Attacks on Stream Cipher Hardware
-
批准号:332401-2008
-
项目类别:Postgraduate Scholarships - Doctoral
-
资助金额:$1.53万
-
财政年份:2009
-
负责人:Anderson, Jonathan
-
依托单位:
Noise Characterization for Side Channel Attacks on Stream Cipher Hardware
-
批准号:332401-2008
-
项目类别:Postgraduate Scholarships - Doctoral
-
资助金额:$0.76万
-
财政年份:2008
-
负责人:Anderson, Jonathan
-
依托单位:
Hardware evaluation of several self-synchronizing stream ciphers
-
批准号:332401-2007
-
项目类别:Postgraduate Scholarships - Master's
-
资助金额:$1.26万
-
财政年份:2007
-
负责人:Anderson, Jonathan
-
依托单位:
Hardware evaluation of several self-synchronizing stream ciphers
-
批准号:332401-2006
-
项目类别:Alexander Graham Bell Canada Graduate Scholarships - Master's
-
资助金额:$1.27万
-
财政年份:2006
-
负责人:Anderson, Jonathan
-
依托单位:
国内基金
海外基金
登录
查看更多内容
亚纳米COF界面自组装镶嵌膜突破离子膜传导性和选择性trade-off效应
-
批准号:--
-
项目类别:面上项目
-
资助金额:60万元
-
批准年份:2021
-
负责人:焉晓明
-
依托单位:
金属功能基元序构的新型有序多孔材料及突破气体分离trade-off的新机制研究
-
批准号:92163110
-
项目类别:重大研究计划
-
资助金额:65.0万元
-
批准年份:2021
-
负责人:温慧敏
-
依托单位:
基于精准孔道分区突破Trade-off效应实现金属-有机框架高效气体吸附分离性能研究
-
批准号:--
-
项目类别:--
-
资助金额:63万元
-
批准年份:2020
-
负责人:翟全国
-
依托单位:
基于精准孔道分区突破Trade-off效应实现金属-有机框架高效气体吸附分离性能研究
-
批准号:22071140
-
项目类别:面上项目
-
资助金额:63.0万元
-
批准年份:2020
-
负责人:翟全国
-
依托单位:
一株海洋细菌的抗噬菌体突变及对自身代谢的trade-off效应
-
批准号:42006093
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:孙越超
-
依托单位:
“疏松”复合纳滤膜的构筑及其结构与性能调控
-
批准号:21808094
-
项目类别:青年科学基金项目
-
资助金额:28.0万元
-
批准年份:2018
-
负责人:神领弟
-
依托单位:
在线和离线折衷排序研究
-
批准号:11271338
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2012
-
负责人:原晋江
-
依托单位:
长颚斗蟋的翅二型:地理变异、进化意义及内分泌控制机理
-
批准号:31070586
-
项目类别:面上项目
-
资助金额:32.0万元
-
批准年份:2010
-
负责人:朱道弘
-
依托单位: