课题基金 / 基金详情

CT-ISG: Memory Safety for Legacy Software, A Quantitative Approach

CT-ISG: Memory Safety for Legacy Software, A Quantitative Approach
CT-ISG:遗留软件的内存安全,一种定量方法
批准号:
0831532
负责人:
Hovav Shacham
金额:
$40.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-09-01 至 2012-08-31

项目摘要

项目成果

Hovav Shacham的其他基金

相似基金

相关文献

中文摘要
翻译
程序员无法编写无漏洞代码是实际计算机系统安全中最紧迫的问题。 最严重的一类漏洞是内存漏洞,通常允许攻击者破坏程序的控制流。 为了解决这个问题,通用缓解措施已经被广泛部署,通过改变操作系统和处理器,寻求使攻击者无法利用程序中的错误。考虑部署这种缓解措施的实施者必须知道多少(如果有的话)通用缓解措施提高了安全性,以及如果他们要明智地分配研发资源,其成本是什么。不幸的是,直到最近,通用缓解措施的好处只是肤浅地研究。 最近采取的初步措施已经揭示了一些情况,例如,广泛部署的“W-xor-X“缓解措施没有提供任何安全益处。该项目将不完善的临时缓解措施置于科学基础之上。 它提供了一个正式的,全面的分析,以确定成本效益方程是通用的缓解。该项目首先产生当前的缓解技术和攻击的定量分析;这些分析有助于创建新的缓解措施,抵御攻击,挫败当前的缓解措施;这些新的缓解措施的实施,评估和传播。 此外,该项目还开发了一个沙箱环境,用于试验软件漏洞和恶意代码,以及一个用于教授系统安全的课程。其结果将是更好地利用供应商的实施资源;为用户提供更安全的遗留软件环境;并为下一代程序员提供更好的安全教育,使他们不会犯早期程序员所犯的错误。
英文摘要
The inability of programmers to write vulnerability free code is the most pressing problem in practical computer systems security. The most serious class of vulnerabilities is memory vulnerabilities, which generally allow an attacker to subvert the program's control flow. In response to this problem, generic mitigations have been widely deployed that, through changes to the operating system and processor, seek to make it impossible for attackers to exploit errors in programs.Implementers considering deploying such mitigations must know how much (if at all) a generic mitigation improves security and what its costs are if they are to allocate R&D resources wisely.Unfortunately, until recently, the benefits of generic mitigations were studied only superficially. Recent first steps have already shed some light, showing, e.g., that the widely deployed "W-xor-X"mitigation provides no security benefit whatsoever.This project puts imperfect, ad-hoc mitigation on a scientific footing. It provides a formal, comprehensive analysis to determine the cost-benefit equation is for generic mitigations.The project begins by producing quantitative analyses of current mitigation techniques and of attacks; these analyses facilitate the creation of new mitigations that resist attacks that foil current mitigations; these new mitigations are implemented, evaluated, and disseminated. In addition, the project develops a sandboxed environment for experimenting with software vulnerabilities and malicious code, and a curriculum for teaching systems security.The results will be better use of implementation resources for vendors; a more secure legacy software environment for users; and better security education for the next generation of programmers, so they will not make the mistakes earlier ones did.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Large: Building and Deploying a Verified JavaScript Runtime
  • 批准号:
    2120696
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $172.99万
  • 财政年份:
    2021
  • 负责人:
    Hovav Shacham
  • 依托单位:
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
  • 批准号:
    1937622
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.36万
  • 财政年份:
    2018
  • 负责人:
    Hovav Shacham
  • 依托单位:
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
  • 批准号:
    1410031
  • 项目类别:
    Standard Grant
  • 资助金额:
    $38.4万
  • 财政年份:
    2014
  • 负责人:
    Hovav Shacham
  • 依托单位:
InfoSec Scholars: Scholarship for Service
  • 批准号:
    1303328
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $213.6万
  • 财政年份:
    2013
  • 负责人:
    Hovav Shacham
  • 依托单位:
国内基金
海外基金
甘草苷通过IFN-I/ISG15信号通路促进卵巢颗粒细胞外泌体分泌延缓卵巢衰老的作用机制
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李璐邑
  • 依托单位:
ISG15/LFA-1调控肿瘤相关巨噬细胞浸润促进胆囊癌免疫逃逸的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    蔡炜龙
  • 依托单位:
ISG15类泛素化修饰多囊泡小体介导KNG1-PI3K/Akt信号轴在葡萄膜炎内皮屏障损伤中的作用机制研究
  • 批准号:
    JCZRQN202500743
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
  • 依托单位:
ISG15下调lncRNA RP11-5407.3介导细胞自噬促进子宫内膜癌进展的 作用及机制研究