课题基金 / 基金详情

End-to-end source-to-object verification of interface safety

End-to-end source-to-object verification of interface safety
接口安全的端到端源到对象验证
批准号:
0540914
负责人:
Andrew Appel
金额:
$32.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-02-15 至 2009-01-31

项目摘要

项目成果

Andrew Appel的其他基金

相似基金

相关文献

中文摘要
翻译
appel, AndrewPrinceton大学端到端接口安全的源到对象验证本研究的目的是加强由组件构建的软件的内部保护屏障,并在软件虚拟机(如Sun的Java和Microsoft的。net)中运行。在这样的软件中,程序员可以使用抽象、面向对象和信息隐藏等标准技术来设计组件之间的接口,以限制恶意组件可能造成的损害。流氓组件是那些被恶意设计的组件,或者更常见的是那些有漏洞的组件,使它们容易受到攻击和接管。但是,Java和。Net(限制一个组件访问属于另一个组件的数据的类型系统)本身很容易受到攻击,如果实现它们的类型检查器和编译器有错误。为了确保没有编译器错误会导致安全漏洞,研究人员将开发正式的模型,将源语言的类型系统(程序员在其中推断它们以设计其保护接口)与实际执行的机器语言联系起来。研究人员将构建机器可检查的规范,并设计方法来构建具有机器可检查安全性证明的编译器。
英文摘要
ABSTRACT0540914Appel, AndrewPrinceton UniversityEnd-to-End Souce-to-Object Verification of Interface SafetyThe purpose of this research is to strengthen the internal protection barriers in software built from components and run in software virtual machines such as Sun's Java and Microsoft's .Net. In such software, programmers can design the interfaces between components--using standard techniques such as abstraction, object orientation, and information hiding--to limit the damage that rogue components can do. Rogue components are those that are designed maliciously or, more commonly, that have bugs making them vulnerable to attack and take-over. However, the protection barriers in Java and .Net (type systems that limit access by one component to data belonging to another component) are themselves vulnerable to attack if the type-checkers and compilers that implement them have bugs. In order to ensure that no compiler bugs can cause security vulnerabilies, the researchers will develop formal models to relate type systems at the source language--where programmers reason about them to design their protection interfaces--to the machine language that actually executes. The researchers will construct machine-checkable specifications and design ways to construct compilers with machine-checkable proofs of security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: FMitF: Track I: Formally Verified Numerical Methods
  • 批准号:
    2219757
  • 项目类别:
    Standard Grant
  • 资助金额:
    $55.95万
  • 财政年份:
    2022
  • 负责人:
    Andrew Appel
  • 依托单位:
SHF: Small: VeriFFI -- Formally Verified Functional+C programs
  • 批准号:
    2005545
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2020
  • 负责人:
    Andrew Appel
  • 依托单位:
Collaborative Research: Expeditions in Computing: The Science of Deep Specification
  • 批准号:
    1521602
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $345.34万
  • 财政年份:
    2015
  • 负责人:
    Andrew Appel
  • 依托单位:
SHF: Medium: Collaborative Research: Principled Optimizing Compilation of Dependently Typed Languages
  • 批准号:
    1407794
  • 项目类别:
    Standard Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2014
  • 负责人:
    Andrew Appel
  • 依托单位:
国内基金
海外基金
真菌特异的内吞作用相关蛋白End3发挥作用的结构研究
  • 批准号:
    32000859
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2020
  • 负责人:
    王冬立
  • 依托单位:
峨眉山玄武岩喷发持续时间的研究:来自古地磁学的约束
  • 批准号:
    41804068
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    26.0万元
  • 批准年份:
    2018
  • 负责人:
    徐颖超
  • 依托单位:
从PBMC-β-END-μ-阿片受体途径探讨华蟾素治疗癌痛的外周机制
  • 批准号:
    81173612
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2011
  • 负责人:
    陈涛
  • 依托单位:
晚期糖基化终产物受体与视网膜母细胞瘤蛋白在前列腺癌细胞中的相互作用及意义
  • 批准号:
    30700835
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    16.0万元
  • 批准年份:
    2007
  • 负责人:
    赵善超
  • 依托单位: