课题基金 / 基金详情

TC: Small: Mining Operating System Semantics: Techniques and Applications

TC: Small: Mining Operating System Semantics: Techniques and Applications
TC:小型:挖矿操作系统语义:技术和应用
批准号:
1018217
负责人:
Heng Yin
金额:
$42.7万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-08-01 至 2014-07-31

项目摘要

项目成果

Heng Yin的其他基金

相似基金

相关文献

中文摘要
翻译
操作系统语义知识是许多安全应用的基础,包括虚拟机自省、恶意软件检测和分析、计算机取证等。然而,现有的操作系统语义提取技术还不够完善。它们对操作系统源代码执行静态分析,因此不能应用于封闭源代码操作系统。源代码分析还存在WYSINWYX(即,您看到的不是您执行的内容)问题。此外,所获得的语义知识很容易被各种核攻击所破坏。在这种不健全的基础上,这些安全应用的功能和可信性变得值得怀疑。为了巩固这一基础,PI旨在构建一个以二进制为中心的、用于提取操作系统语义的健壮分析框架。它是以二进制为中心的,因为它可以从操作系统内核的二进制代码中提取语义信息。从而解决了WYSINWYX问题,克服了封闭源代码操作系统的语义障碍。它是健壮的,因为它可以捕获操作系统级语义中的不变量。因此,可以从这些不变量中获取可信的语义知识,从而可以检测到各种伪造攻击。然后,在这个框架下,将进一步研究如何增强各种安全应用的功能和健壮性。拟议的任务将导致发布原型系统,并为本科生和研究生课程以及专业培训班编写教材。
英文摘要
The knowledge about operating system semantics is the foundation for many security applications, including virtual machine introspection, malware detection and analysis, computer forensics, etc. However, the existing techniques for extracting operating system semantics fall short. They perform static analysis on the OS source code, and thus cannot be applied to the closed-source operating systems. The source-code analysis also suffers from the WYSINWYX (i.e., What You See Is Not What You eXecute) problem. Furthermore, the obtained semantics knowledge can be easily compromised by various kernel attacks. With such an unsound foundation, the functionality and trustworthiness of these security applications become questionable.To fortify this foundation, the PI aims to build a binary-centric and robust analysis framework for extracting operating system semantics. It is binary-centric, because it can extract semantics information from the binary code of an OS kernel. Consequently, the WYSINWYX problem can be solved and the semantics barrier of closed-source operating systems can be overcome. It is robust, because it can capture the invariants in OS-level semantics. So trustworthy semantics knowledge can be derived from these invariants, and various forgery attacks can be detected. Then with this framework, further research will be conducted to investigate how the functionality and robustness of various security applications can be strengthen. The proposed tasks will lead to the release of prototype systems and the development of education materials for undergraduate and graduate courses and for professional training sessions.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Concolic-Execution-Centric Fuzzing
  • 批准号:
    2133487
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Heng Yin
  • 依托单位:
SaTC: CORE: Small: Towards Robust and Scalable Search of Binary Code and Data
  • 批准号:
    1719175
  • 项目类别:
    Standard Grant
  • 资助金额:
    $47.68万
  • 财政年份:
    2017
  • 负责人:
    Heng Yin
  • 依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
  • 批准号:
    1664315
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $16.89万
  • 财政年份:
    2016
  • 负责人:
    Heng Yin
  • 依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
  • 批准号:
    1054605
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $54.95万
  • 财政年份:
    2011
  • 负责人:
    Heng Yin
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: