TC: Small: Collaborative Research: Securing Multilingual Software Systems
TC: Small: Collaborative Research: Securing Multilingual Software Systems
批准号:
0915157
负责人:
Gang Tan
金额:
$26.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2013-08-31
中文摘要
大多数真实的软件系统都由用多种编程语言开发的模块组成。不同的语言在他们的安全假设和保证上有所不同。因此,即使单个模块在某些语言模型中是安全的,并且在某些安全策略方面是安全的,但在整个多语言系统中通常没有统一的安全保证。 本项目的重点是为Java等类型安全语言与本机代码互操作的软件系统提供安全保证的低开销技术。本机代码是用低级语言开发的,包括C、C++和汇编语言。 尽管经常在软件项目中使用,但本机代码是出了名的不安全,并且是安全漏洞的丰富来源。 PI正在开发一种两层的方法来减轻本地代码对类型安全语言构成的安全威胁:(1)二进制重写工具及其验证器正在被纳入Java虚拟机(JVM)中,用于在机器指令级重写和验证本地模块,以执行安全策略;(2)正在设计一种安全的C语言方言,用于与Java的互操作;在程序员注释的帮助下,可以静态地验证这种方言中的程序。 该项目的成果将使流行的平台,如JVM和.NET和其他主要的编程语言(例如,Python、OCaml等)安全地整合本地模块。 所开发的原则也将适用于Web浏览器和操作系统,其中需要在不包含主机安全性的情况下使用不可信的低级模块对其进行扩展。
英文摘要
Most real software systems consist of modules developed inmultiple programming languages. Different languages differ in theirsecurity assumptions and guarantees. Consequently, even if singlemodules are secure in some language model and with respect to somesecurity policy, there is usually no uniform security guarantee on awhole multilingual system. This project focuses on low-overheadtechniques for providing security guarantees to software systems inwhich type-safe languages such as Java interoperate with native code.Native code is developed in low-level languages including C, C++, andassembly languages. Although often used in software projects, nativecode is notoriously insecure and is a rich source of securityvulnerabilities. The PIs are developing a two-layered approach toalleviating security threats posed by native code to type-safelanguages: (1) Binary rewriting tools and their verifiers are beingincorporated into the Java Virtual Machine (JVM) for rewriting andverifying native modules at the machine-instruction level to enforcesecurity policies; (2) A safe dialect of C for interoperation withJava is being designed; with the help of programmer annotations, thesafety of programs in this dialect can be statically verified. Theoutcome of this project will enable popular platforms such as the JVMand .NET and other major programming languages (e.g., Python, OCaml,etc.) to incorporate native modules safely. The developed principleswill also be applicable to web browsers and operating systems in whichthere is a need of extending them with untrusted low-level moduleswithout comprising host security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Small: Detecting and Localizing Non-Functional Vulnerabilities in Machine Learning Libraries
-
批准号:2230061
-
项目类别:Standard Grant
-
资助金额:$24.66万
-
财政年份:2023
-
负责人:Gang Tan
-
依托单位:
SaTC: CORE: Small: Precise and Robust Binary Reverse Engineering and its Applications
-
批准号:2243632
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Gang Tan
-
依托单位:
CAPA: Collaborative Research: Lightweight Abstract Memory Features
-
批准号:1723571
-
项目类别:Continuing Grant
-
资助金额:$25.0万
-
财政年份:2017
-
负责人:Gang Tan
-
依托单位:
CAREER: User-Space Protection Domains for Compositional Information Security
-
批准号:1624124
-
项目类别:Continuing Grant
-
资助金额:$27.66万
-
财政年份:2016
-
负责人:Gang Tan
-
依托单位:
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
-
批准号:1624125
-
项目类别:Standard Grant
-
资助金额:$1.39万
-
财政年份:2016
-
负责人:Gang Tan
-
依托单位:
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
-
批准号:1624126
-
项目类别:Standard Grant
-
资助金额:$27.33万
-
财政年份:2016
-
负责人:Gang Tan
-
依托单位:
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
-
批准号:1408826
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2014
-
负责人:Gang Tan
-
依托单位:
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
-
批准号:1217710
-
项目类别:Standard Grant
-
资助金额:$25.88万
-
财政年份:2012
-
负责人:Gang Tan
-
依托单位:
CAREER: User-Space Protection Domains for Compositional Information Security
-
批准号:1149211
-
项目类别:Continuing Grant
-
资助金额:$48.31万
-
财政年份:2012
-
负责人:Gang Tan
-
依托单位:
III-CXT-Small: Collaborative Research: Structuring, Reasoning, and Querying in a Very Large Medical Image Database
-
批准号:0812073
-
项目类别:Continuing Grant
-
资助金额:$5.45万
-
财政年份:2008
-
负责人:Gang Tan
-
依托单位:
III-CXT-Small: Collaborative Research: Structuring, Reasoning, and Querying in a Very Large Medical Image Database
-
批准号:0854606
-
项目类别:Continuing Grant
-
资助金额:$5.45万
-
财政年份:2008
-
负责人:Gang Tan
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: