TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems
TC: Medium: Collaborative Research: Securing Concurrency in Modern Systems
批准号:
0905602
负责人:
Emmett Witchel
金额:
$80.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2013-08-31
中文摘要
该奖项是根据2009年美国复苏和再投资法案(公法111-5)资助的。与并发相关的漏洞在现代计算系统中普遍存在。并发性攻击包括文件系统中的检查时间到使用时间(TOCTTOU)竞争条件、对信号处理程序的攻击,以及利用并发性逃避沙箱机制的规避恶意软件。随着处理器具有越来越多的并行性,计算机处理越来越多的敏感数据,防御并发攻击是未来十年的一个关键挑战。第一个目标是保护合法的应用程序在访问系统资源时免受并发性攻击(例如,防止对文件访问的tocttou攻击和信号处理程序中可利用的竞争条件)。目标是为应用程序程序员提供同步访问系统资源的机制和策略,以便他们可以避免无意的漏洞。第二个目标是在并发情况下对不受信任的代码提供强大的限制,即阻止故意的恶意行为。今天的恶意软件滥用并发机制来绕过和规避包含机制,如引用监视器和系统调用包装器。为包含恶意代码的系统提供强大的支持是入侵检测和防御的关键挑战。现代计算系统的性能和功能从根本上依赖于并发性。确保并发的安全使用对于构建可信的网络基础设施至关重要。这项研究将对安全软件的实际开发产生重大影响,并使安全关键应用程序能够实现当今高度并行系统的性能优势。
英文摘要
This award is funded under the American Recovery and Reinvestment Act of 2009 (Public Law 111-5).Concurrency-related vulnerabilities are pervasive in modern computingsystems. Concurrency exploits include time-of-check-to-time-of-use(TOCTTOU) race conditions in file systems, attacks on signal handlers,and evasive malware that uses concurrency to escape sandboxingmechanisms. As processors feature ever more parallelism, andcomputers process more of our sensitive data, defending againstconcurrency attacks is a key challenge for the coming decade.The first goal is to protect legitimate applications from concurrencyattacks when they access system resources (e.g., prevent TOCTTOUattacks on file accesses and exploitable race conditions in signalhandlers). The objective is to provide application programmers withmechanisms and policies for synchronizing access to system resourcesso they can avoid unintentional vulnerabilities.The second goal is to provide strong confinement of untrusted code inthe presence of concurrency, i.e., blocking intentionally maliciousbehavior. Today's malware abuses concurrency mechanisms to bypass andcircumvent containment mechanisms like reference monitors and systemcall wrappers. Providing robust system support for containingmalicious code is a critical challenge in intrusion detection andprevention.Modern computing systems fundamentally depend on concurrency for theirperformance and functionality. Making sure that concurrency is usedsecurely is essential for building a trusted cyber infrastructure.This research will have a significant impact on the practicaldevelopment of secure software, and enable security-criticalapplications to realize the performance benefits of today's highlyparallel systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CNS Core: Small: Operating Systems Abstractions for Serverless Computing
-
批准号:2008321
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2020
-
负责人:Emmett Witchel
-
依托单位:
XPS:CLCCA:Collaborative Research:Harnessing Highly Threaded Hardware for Server Workloads
-
批准号:1333594
-
项目类别:Standard Grant
-
资助金额:$34.16万
-
财政年份:2013
-
负责人:Emmett Witchel
-
依托单位:
TWC: Medium: Collaborative: Trustworthy Programs Without A Trustworthy Operating System
-
批准号:1228843
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2012
-
负责人:Emmett Witchel
-
依托单位:
CSR: Small: Operating System Abstractions for GPU-Accelerated Interactive Applications
-
批准号:1017785
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2010
-
负责人:Emmett Witchel
-
依托单位:
CAREER: Operating System Support For Transactional Memory: Construction and Performance Scalability of Parallel Programs
-
批准号:0644205
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2007
-
负责人:Emmett Witchel
-
依托单位:
CSR--PDOS: Autonomic Systems: Integrating Machine Learning with Computer Systems
-
批准号:0615104
-
项目类别:Standard Grant
-
资助金额:$88.0万
-
财政年份:2006
-
负责人:Emmett Witchel
-
依托单位:
海外基金