课题基金 / 基金详情

CAREER: Improving Software Assurance Using Transactions

CAREER: Improving Software Assurance Using Transactions
职业:使用事务改进软件保障
批准号:
0952128
负责人:
Vinod Ganapathy
金额:
$36.67万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-09-01 至 2016-08-31

项目摘要

项目成果

Vinod Ganapathy的其他基金

相似基金

相关文献

中文摘要
翻译
这个CAREER项目的目标是开发使用事务来改进软件保证的新机制。这个项目正在开发事务性内存内省(transactional Memory Introspection,简称TMI),这是一种通过利用硬件和软件事务性内存的最新进展来构建软件安全机制的方法。基于TMI的安全机制建立在事务性内存系统用来确保性能和功能的相同机制之上。因此,TMI承诺使安全机制高效且易于与软件集成。本项目研究的基于tmi的安全机制包括:(1)TxAuth:一种参考监控架构,可以更好地确保安全敏感操作的完成,并允许更容易地与遗留系统集成;(2) TxInt:数据结构完整性监视器,保护可扩展的软件系统,如操作系统和浏览器,不受不受信任的扩展;(3) TMWatch:一个数据观察点框架,为恶意软件分析工具和调试器配备了新的功能,以逆向工程恶意软件行为。更广泛地说,这个项目试图证明在事务性内存系统中实现的并发控制机制也可以用于改进软件保证。这些额外的好处可能会导致对事务进行更多的研究,并最终被硬件和软件供应商采用。这个项目的成果正在通过开发新的课程材料进行传播,这些材料将使学生和软件供应商了解安全编程的注意事项。在这个项目中开发的合适的课程材料也被包括在针对K-12和本科生的课程中,以吸引他们学习计算机科学课程。
英文摘要
he goal of this CAREER project is to develop novel mechanisms that usetransactions to improve software assurance. This project is developingTransactional Memory Introspection---or TMI, which is an approach to building software security mechanisms by leveraging recent advances in hardware and software transactional memory. Security mechanisms based on TMI build upon the same machinery that transactional memory systems use to ensure performance and functionality. TMI therefore promises to make security mechanisms efficient and easy to integrate with software.TMI-based security mechanisms being researched in this project include:(1) TxAuth: a reference monitor architecture to better ensure completemediation of security-sensitive operations and allow easier integration with legacy systems;(2) TxInt: a data structure integrity monitor to protect extensible software systems, such as operating systems and browsers, from untrusted extensions; and(3) TMWatch: a data watchpoint framework that equips malware analysis tools and debuggers with new capabilities to reverse-engineer malware behavior.More broadly, this project seeks to demonstrate that concurrency controlmachinery implemented in transactional memory systems can also be used to improve software assurance. These additional benefits may lead to more research on transactions and their ultimate adoption by hardware and software vendors. The results from this project are being disseminated via the development of new course material that will expose students and software vendors to the dos and don'ts of secure programming. Suitable course material developed in this project is also being included in courses targeted towards K-12 and undergraduate students to attractthem to computer science programs.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: Small: Self-Service Cloud Computing
  • 批准号:
    1420815
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.99万
  • 财政年份:
    2014
  • 负责人:
    Vinod Ganapathy
  • 依托单位:
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
  • 批准号:
    1408803
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2014
  • 负责人:
    Vinod Ganapathy
  • 依托单位:
CPS: Small: Collaborative Research: Establishing Integrity in Dynamic Networks of Cyber Physical Devices
  • 批准号:
    0931992
  • 项目类别:
    Standard Grant
  • 资助金额:
    $35.5万
  • 财政年份:
    2009
  • 负责人:
    Vinod Ganapathy
  • 依托单位:
TC: Small: Collaborative Research: Protecting Commodity Operating Systems from Vulnerable Device Drivers
  • 批准号:
    0915394
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2009
  • 负责人:
    Vinod Ganapathy
  • 依托单位:
国内基金
海外基金
Improving modelling of compact binary evolution.
  • 批准号:
    10903001
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2009
  • 负责人:
    史蒂芬
  • 依托单位: