Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
基本信息
- 批准号:RGPIN-2015-04461
- 负责人:
- 金额:$ 1.31万
- 依托单位:
- 依托单位国家:加拿大
- 项目类别:Discovery Grants Program - Individual
- 财政年份:2019
- 资助国家:加拿大
- 起止时间:2019-01-01 至 2020-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
In our highly connected and highly computerized world, security issues are of major importance. ***Trusted systems need to communicate with untrustworthy parties exposing the users to a risk of information leakage or data corruption. It is urgent to find effective solutions to protect users. Despite major research efforts that have been devised, there still are many challenging problems to be explored.***My broad research aim is to contribute to the design of provably sound techniques, methods and enforcement mechanisms that enforce security policies at the level of applications. ***Mechanisms such as access control, encryption, firewalls, digital signatures, and antivirus scanning are either too restrictive, causing loss of flexibility, or unable to protect from newly introduced threats or malicious attacks. One of the underlying reasons is that they do not address the fundamental problem, which is tracking information flow in a fine-grained application-specific way. To do this one needs to analyze the code of an application; this research trend is known as "language-based security". In this research program, I will address information flow enforcement mechanisms that prevent information from flowing from a higher security level to a lower one or in a dual way to prevent lower security level data from corrupting higher ones. The main idea is to inspect the code of an application and control its execution in order to apply the policy. ***I will adopt the following objectives and methodological lines. ******1. Introducing the least overhead possible while reducing false positives. A hybrid approach combining static and dynamic analysis in an effective way is to be adopted. ***2. Dealing with declassification. Declassification means an intentional leak from higher security levels to lower ones. ***Information flow policy is very restrictive; real-world applications release information as part of their intended function. For instance, login procedures, communication of encrypted data, or voting systems do not comply with information-flow policy. Release of some information must be allowed but controlled to prevent non-intended leaks. ******3. Designing mechanisms that target more expressive languages such as concurrent languages. More challenging issues may appear such as timing channels, which cause leaks due to attackers' capacity to observe time. Extensive data-flow analysis and semantic models suitable to concurrency will be adopted. ***4. Quantifying the amount of leakage in a probabilistic framework. The aim is to relax non-interference and tolerate some quantified leaks. ***5. Leveraging all these techniques to a real world language. *********The results will provide practical and theoretical foundations for the development of effective and robust mechanisms to preserve the confidentiality and the integrity of their data. *** **
在我们这个高度互联和高度计算机化的世界中,安全问题至关重要。 * 可信系统需要与不可信方通信,使用户面临信息泄露或数据损坏的风险。迫切需要找到有效的解决方案来保护用户。尽管已经做出了重大的研究努力,但仍有许多具有挑战性的问题有待探索。我广泛的研究目标是有助于设计可证明的合理技术,方法和执行机制,在应用程序级别执行安全策略。* 访问控制、加密、防火墙、数字签名和防病毒扫描等机制要么限制性太强,导致灵活性丧失,要么无法抵御新引入的威胁或恶意攻击。其中一个根本原因是它们没有解决根本问题,即以细粒度的特定于应用程序的方式跟踪信息流。要做到这一点,需要分析应用程序的代码;这种研究趋势被称为“基于语言的安全性”。在这项研究计划中,我将解决信息流执行机制,防止信息从较高的安全级别流向较低的安全级别,或者以双重方式防止较低安全级别的数据损坏较高的安全级别。其主要思想是检查应用程序的代码并控制其执行以应用策略。* 我将采用以下目标和方法。*1.引入尽可能少的开销,同时减少误报。 将采用一种有效的静态和动态分析相结合的混合方法。***2。处理解密。解密意味着从更高的安全级别到更低的安全级别的故意泄漏。*** 信息流政策非常严格;实际应用程序发布信息是其预期功能的一部分。例如,登录程序、加密数据通信或投票系统不符合信息流动政策。必须允许发布某些信息,但要加以控制,以防止非预期的泄露。3.设计面向更具表达力的语言(如并发语言)的机制。可能会出现更具挑战性的问题,例如时间通道,由于攻击者观察时间的能力,这会导致泄漏。将采用广泛的数据流分析和适用于并发的语义模型。*4。在概率框架内量化泄漏量。其目的是放松不干涉和容忍一些量化的泄漏。*5。将所有这些技术应用于真实的世界语言。* 研究结果将为制定有效和强有力的机制以保护其数据的机密性和完整性提供实践和理论基础。*** **
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Tawbi, Nadia其他文献
Tawbi, Nadia的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Tawbi, Nadia', 18)}}的其他基金
Enforcing security and safety policies in IoT applications
在物联网应用中执行安全策略
- 批准号:
RGPIN-2020-04283 - 财政年份:2022
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Enforcing security and safety policies in IoT applications
在物联网应用中执行安全策略
- 批准号:
RGPIN-2020-04283 - 财政年份:2021
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Enforcing security and safety policies in IoT applications
在物联网应用中执行安全策略
- 批准号:
RGPIN-2020-04283 - 财政年份:2020
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
- 批准号:
RGPIN-2015-04461 - 财政年份:2018
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
- 批准号:
RGPIN-2015-04461 - 财政年份:2017
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
- 批准号:
RGPIN-2015-04461 - 财政年份:2016
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Hybrid approaches for enforcing security policies.
执行安全策略的混合方法。
- 批准号:
RGPIN-2015-04461 - 财政年份:2015
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Security policy enforcement mechanisms
安全策略执行机制
- 批准号:
194380-2010 - 财政年份:2014
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Security policy enforcement mechanisms
安全策略执行机制
- 批准号:
194380-2010 - 财政年份:2013
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
Security policy enforcement mechanisms
安全策略执行机制
- 批准号:
194380-2010 - 财政年份:2012
- 资助金额:
$ 1.31万 - 项目类别:
Discovery Grants Program - Individual
相似国自然基金
Lagrangian origin of geometric approaches to scattering amplitudes
- 批准号:24ZR1450600
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
相似海外基金
Investigating bioengineering approaches to produce immuno-modulatory mesenchymal stromal cells and their extracellular vesicle
研究生产免疫调节间充质基质细胞及其细胞外囊泡的生物工程方法
- 批准号:
2608627 - 财政年份:2025
- 资助金额:
$ 1.31万 - 项目类别:
Studentship
New approaches to training deep probabilistic models
训练深度概率模型的新方法
- 批准号:
2613115 - 财政年份:2025
- 资助金额:
$ 1.31万 - 项目类别:
Studentship
Collaborative Research: BoCP-Implementation: Alpine plants as a model system for biodiversity dynamics in a warming world: Integrating genetic, functional, and community approaches
合作研究:BoCP-实施:高山植物作为变暖世界中生物多样性动态的模型系统:整合遗传、功能和社区方法
- 批准号:
2326020 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
Continuing Grant
Collaborative Research: BoCP-Implementation: Alpine plants as a model system for biodiversity dynamics in a warming world: Integrating genetic, functional, and community approaches
合作研究:BoCP-实施:高山植物作为变暖世界中生物多样性动态的模型系统:整合遗传、功能和社区方法
- 批准号:
2326021 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
Standard Grant
Multiscale Approaches And Scalability Within Climate Change-heritage Risk Assessments
气候变化遗产风险评估中的多尺度方法和可扩展性
- 批准号:
AH/Z000084/1 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
Research Grant
Dynamical Approaches to Number Theory and Additive Combinatorics
数论和加法组合学的动态方法
- 批准号:
EP/Y014030/1 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
Research Grant
C-NEWTRAL: smart CompreheNsive training to mainstrEam neW approaches for climaTe-neutRal cities through citizen engAgement and decision-making support
C-NEWTRAL:智能综合培训,通过公民参与和决策支持将气候中和城市的新方法纳入主流
- 批准号:
EP/Y032640/1 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
Research Grant
NEM-EMERGE: An integrated set of novel approaches to counter the emergence and proliferation of invasive and virulent soil-borne nematodes
NEM-EMERGE:一套综合的新方法来对抗入侵性和剧毒土传线虫的出现和扩散
- 批准号:
10080598 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
EU-Funded
PINK - Provision of Integrated Computational Approaches for Addressing New Markets Goals for the Introduction of Safe-and-Sustainable-by-Design Chemicals and Materials
PINK - 提供综合计算方法来解决引入安全和可持续设计化学品和材料的新市场目标
- 批准号:
10097944 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
EU-Funded
Stuck in the mud: addressing the fine sediment conundrum with multiscale and interdisciplinary approaches to support global freshwater biodiversity
陷入困境:采用多尺度和跨学科方法解决细小沉积物难题,支持全球淡水生物多样性
- 批准号:
MR/Y020200/1 - 财政年份:2024
- 资助金额:
$ 1.31万 - 项目类别:
Fellowship