Hardware-assisted Security
Hardware-assisted Security
批准号:
RGPIN-2020-04744
负责人:
Asokan, Nadarajah
金额:
$4.01万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2021
资助国家:
加拿大
项目状态:
已结题
起止时间:
2021-01-01 至 2022-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Exploiting memory errors is a popular tactic used by remote adversaries attempting to break into computer systems. Many recent high-profile attacks for ransomware (eg, WannaCry) and disruption of daily life (eg, NotPetya) exploited memory errors and caused billions of dollars in damages. Memory errors are also routinely exploited in targeted attacks against individuals, as in the recent WhatsApp hack, which exploited a common type of memory error (buffer overflows) altering the normal program flow in order to let the attacker control the phone just by making a WhatsApp call to the phone's owner. Software-only solutions against such "run-time attacks" are easier to deploy but incur high costs if they are to ensure sufficient security. Hardware-based solutions are more difficult to deploy. Recently, major processor vendors have started to roll out hardware-based defenses (e.g., ARM Pointer Authentication (PA)), against specific classes of run-time attacks. Leveraging such defenses to design broadly applicable solutions for run-time protection is attractive because these solutions can provide effective protections without incurring high deployment costs. However, doing so involves two major challenges: (1) understanding the limitations inherent in the current designs of these defenses (e.g., ARM PA is susceptible to "reuse attacks" where an authenticated pointer taken from one location in the code is reused in another), and (2) building on these insights to design effective run-time protection mechanisms that are simultaneously more efficient and more secure than the state-of-the art. Approach: My long term objective is to design effective hardware-assisted approaches to protect software. To this end, I seek to understand how to use emerging commercial off-the-shelf (COTS) hardware-security defenses to achieve effective run-time protection with a low-barrier for real-world deployment. To address the challenges above, I aim for three short- to medium-term objectives O1-O3: (O1) to systematically analyze these COTS defenses to understand their limitations and to develop effective techniques for run-time protection by using these defenses in new ways (individually or in conjunction), (O2) develop a rigorous framework to compare techniques, and (O3) use the experience gained to identify and realize a set of optimal hardware-security building blocks ("primitives") on RISC-V, an open-source hardware platform. Anticipated outcomes and benefits: The program will result in: software artifacts that allow developers to easily afford run-time protection for their software on commodity hardware, an open-source hardware implementation of selected primitives that can be used for technology transfer or further research, and train highly-qualified personnel with deep understanding of the intricacies of run-time attacks and equipped to develop effective defenses. If successful, this program will significantly strengthen security for software in the real world.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Hardware-assisted Security
-
批准号:RGPIN-2020-04744
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$4.01万
-
财政年份:2022
-
负责人:Asokan, Nadarajah
-
依托单位:
Hardware-assisted Security
-
批准号:RGPIN-2020-04744
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$4.01万
-
财政年份:2020
-
负责人:Asokan, Nadarajah
-
依托单位:
国内基金
海外基金
光辅助MOCVD法制备多层结构提高厚YBCO 外延膜电流承载能力的研究
-
批准号:51002063
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2010
-
负责人:李国兴
-
依托单位:
控制厚皮甜瓜花性型基因“A“的精细构图及标记辅助育种
-
批准号:30471113
-
项目类别:面上项目
-
资助金额:21.0万元
-
批准年份:2004
-
负责人:王志民
-
依托单位: