CT-ISG: Automatic Generation of Vaccine Exploits to Protect Commodity Software
CT-ISG: Automatic Generation of Vaccine Exploits to Protect Commodity Software
批准号:
0716292
负责人:
XiaoFeng Wang
金额:
$32.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2007
资助国家:
美国
项目状态:
已结题
起止时间:
2007-09-01 至 2011-08-31
中文摘要
在生物学上,疫苗是一种被故意注射到体内以刺激抗体产生的减弱的病毒或细菌株。以这种方式产生的免疫力将在未来保护人体免受同类病毒的侵袭。受这一想法的启发,本研究旨在开发自动生成疫苗漏洞的技术,以检测和诊断商品软件中的漏洞,并通过特定漏洞的签名保护它们免受潜在漏洞的攻击。这种疫苗的一个例子是其跳转地址被扰乱的“弱化”缓冲区溢出利用:当试图劫持程序的控制流时,它会导致易受攻击的程序出现异常,法医分析可以从中发现潜在的漏洞。疫苗的想法提供了一种创新的途径,以解决软件安全漏洞构成的严重威胁,而软件安全漏洞从根本上阻碍了互联网的进步。该项目开发疫苗技术,以被动和主动的方式保护易受攻击的软件。反应性疫苗可以快速检测零日漏洞并生成签名,而不依赖源代码或二进制代码。该项目的重点是应用该技术来保护互联网服务。主动疫苗用于自动从软件补丁等来源发现软件漏洞,并创建试探性补救措施。这项技术甚至可以在攻击者发现漏洞之前及时保护易受攻击的软件。这项研究也为培养安全信息学领域的教育使命提供了一个很好的机会。
英文摘要
In biology, a vaccine is a weakened strain of viruses or bacteria which is intentionally injected into the body for the purpose of stimulating antibody production. The immunity generated in this way will protect the body from the same type of viruses in the future. Inspired by this idea, this research aims at developing techniques that automatically generate vaccine exploits to detect and diagnose vulnerabilities inside commodity software, and protect them from potential exploits through vulnerability-specific signatures. An example of such a vaccine is a "weakened" buffer-overflow exploit with its jump address scrambled: it causes an exception to a vulnerable program when attempting to hijack the program's control flow, from which a forensic analysis can uncover the underlying vulnerability.The idea of vaccines offers an innovative avenue to address the grave threat posed by software security flaws, which has been fundamentally hampering the progress of the Internet. This project develops vaccine techniques to protect vulnerable software in both reactive and proactive fashions. Reactive vaccines can quickly detect zero-day exploits and generate signatures without reliance on source or binary code. The project focuses on applying the technique to protect Internet services. Proactive vaccines are used for automatically discovering software vulnerabilities from the sources such as software patches and creating tentative remedies. This technique enables timely protection of vulnerable software even before the attacker can figure out an exploit. This research also provides a great opportunity to foster the education missions in the area of Security Informatics.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Audacity of Exploration: Toward Automated Discovery of Security Flaws in Networked Systems through Intelligent Documentation Analysis
-
批准号:2154199
-
项目类别:Standard Grant
-
资助金额:$55.0万
-
财政年份:2022
-
负责人:XiaoFeng Wang
-
依托单位:
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
-
批准号:2207231
-
项目类别:Continuing Grant
-
资助金额:$294.0万
-
财政年份:2022
-
负责人:XiaoFeng Wang
-
依托单位:
BIGDATA: IA: Enabling Large-Scale, Privacy-Preserving Genomic Computing with a Hardware-Assisted Secure Big-Data Analytics Framework
-
批准号:1838083
-
项目类别:Standard Grant
-
资助金额:$100.0万
-
财政年份:2019
-
负责人:XiaoFeng Wang
-
依托单位:
SaTC: CORE: Medium: Collaborative: Understanding and Discovering Illicit Online Business Through Automatic Analysis of Online Text Traces
-
批准号:1801432
-
项目类别:Continuing Grant
-
资助金额:$46.97万
-
财政年份:2018
-
负责人:XiaoFeng Wang
-
依托单位:
TWC: Small: Safeguarding Mobile Cloud Services: New Challenges and Solutions
-
批准号:1618493
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:XiaoFeng Wang
-
依托单位:
TWC: Small: Understanding and Mitigating the Security Hazards of Mobile Fragmentation
-
批准号:1527141
-
项目类别:Continuing Grant
-
资助金额:$49.89万
-
财政年份:2015
-
负责人:XiaoFeng Wang
-
依托单位:
TWC: Medium: Collaborative: Broker Leads for Privacy-Preserving Discovery in Health Information Exchange
-
批准号:1408874
-
项目类别:Standard Grant
-
资助金额:$36.0万
-
财政年份:2014
-
负责人:XiaoFeng Wang
-
依托单位:
TWC: Small: Knowing Your Enemy: Understanding and Counteracting Web Malvertising
-
批准号:1223477
-
项目类别:Standard Grant
-
资助金额:$47.82万
-
财政年份:2012
-
负责人:XiaoFeng Wang
-
依托单位:
TWC: Small: Secure Data-Intensive Computing on Hybrid Clouds
-
批准号:1223495
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2012
-
负责人:XiaoFeng Wang
-
依托单位:
TC: Small: Plugging Logic Loopholes in Hybrid Web Applications to Secure Web Commerce
-
批准号:1117106
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2011
-
负责人:XiaoFeng Wang
-
依托单位:
TC: Small: Reining in Side-Channel Information Leaks in the Software-as-a-Service Era
-
批准号:1017782
-
项目类别:Standard Grant
-
资助金额:$49.41万
-
财政年份:2010
-
负责人:XiaoFeng Wang
-
依托单位:
国内基金
海外基金
登录
查看更多内容
甘草苷通过IFN-I/ISG15信号通路促进卵巢颗粒细胞外泌体分泌延缓卵巢衰老的作用机制
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:李璐邑
-
依托单位:
ISG15/LFA-1调控肿瘤相关巨噬细胞浸润促进胆囊癌免疫逃逸的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:蔡炜龙
-
依托单位:
ISG15类泛素化修饰多囊泡小体介导KNG1-PI3K/Akt信号轴在葡萄膜炎内皮屏障损伤中的作用机制研究
-
批准号:JCZRQN202500743
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:
-
依托单位:
ISG15下调lncRNA RP11-5407.3介导细胞自噬促进子宫内膜癌进展的
作用及机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
肾周脂肪M2 巨噬细胞通过ISG15/LFA-1轴调控传入神经活性在肥
胖相关高血压中的作用及机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:郭静
-
依托单位:
ISG58 调控草鱼呼肠孤病毒复制的分子机制
-
批准号:2024JJ6247
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:胡旭东
-
依托单位:
STING/IFN-I/ISG15 在肝硬化内皮细胞损伤中的机制研究
-
批准号:2024JJ5610
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:汤参娥
-
依托单位:
ISG15介导西达苯胺对B细胞肿瘤靶点外排的抑制作用从而增强CAR-T疗效的研究
-
批准号:82300199
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:徐皓
-
依托单位:
骨髓ISG+NAMPT+中性粒细胞介导抗磷脂综合征B细胞异常活化的机制研究
-
批准号:82371799
-
项目类别:面上项目
-
资助金额:47.00万元
-
批准年份:2023
-
负责人:杨程德
-
依托单位:
黑色素瘤BRAF抑制剂耐药新机制:USP18去ISG化cGAS促进自噬
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2023
-
负责人:
-
依托单位: