课题基金 / 基金详情

Practical Language-Based Security, From The Ground Up

Practical Language-Based Security, From The Ground Up
实用的基于语言的安全性,从头开始
批准号:
0209163
负责人:
Michael Franz
金额:
$30.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-08-01 至 2005-07-31

项目摘要

项目成果

Michael Franz的其他基金

相似基金

相关文献

中文摘要
翻译
提出了一种综合的安全体系结构,它使用基于语言的机制来消除由于规避类型安全而导致的错误,无论这些错误是故意的还是错误的,并另外使用安全策略机制来遏制恶意行为。该方法扩展了先前应用于移动代码的技术,并且基于a)在任何软件运行之前机械地验证在任何软件中不存在此类错误,使用可首先检查此类错误或首先排除错误的代码表示,以及b)监视执行软件的恶意活动。解决方案的关键是提供一个类型化硬件抽象层(THAL),该抽象层能够“从头开始”构建类型安全的系统,一直到防篡改的硬件。因此,我们的目标是建立一个实用的系统,我们可以在这个系统上从硬件上保证安全,而不仅仅是从操作系统上。
英文摘要
A comprehensive security architecture is proposed that uses language-based mechanisms to eliminate errors due to circumvention of type safety, be they intentional or erroneous, and that additionally uses security policy mechanisms to contain malicious behavior. This approach extends techniques previously applied to mobile code and is based on a combination of a) mechanically verifying the absence of such errors in any software before it is run, using code representations that can be checked for such errors or that rule out errors in the first place, and b) monitoring executing software for malicious activity.The proposed system consists of multiple layers, each of which is secured by the layer below it, the lowest of which can be provided in tamper-resistant hardware. Key to the solution is to provide a typed hardware abstraction layer (THAL) that enables the construction of a type-safe system "from the ground up", all the way down to the tamper-proof hardware. Hence, the goal is to build a practical system about which we can make security guarantees from the hardware up, and not just "from the operating system up".
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: EAGER: Cross-platform Election Advertising Transparency Initiative
  • 批准号:
    2235007
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.99万
  • 财政年份:
    2022
  • 负责人:
    Michael Franz
  • 依托单位:
TWC: Small: Hydra - Hybrid Defenses for Resilient Applications: Practical Approaches Towards Defense In Depth
  • 批准号:
    1619211
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2016
  • 负责人:
    Michael Franz
  • 依托单位:
TWC: TTP Option: Medium: Collaborative: ENCORE - ENhanced program protection through COmpiler-REwriter cooperation
  • 批准号:
    1513837
  • 项目类别:
    Standard Grant
  • 资助金额:
    $61.93万
  • 财政年份:
    2015
  • 负责人:
    Michael Franz
  • 依托单位:
I-Corps: Hardening Programs Against Cyber Attacks
  • 批准号:
    1439439
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2014
  • 负责人:
    Michael Franz
  • 依托单位:
海外基金