课题基金 / 基金详情

TC: Small: WATCHDOG: Hardware-Assisted Prevention of All Use-After-Free Security Vulnerabilities

TC: Small: WATCHDOG: Hardware-Assisted Prevention of All Use-After-Free Security Vulnerabilities
TC:小:WATCHDOG:硬件辅助预防所有释放后使用安全漏洞
批准号:
1116682
负责人:
Stephan Zdancewic
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-08-01 至 2017-07-31

项目摘要

项目成果

Stephan Zdancewic的其他基金

相似基金

相关文献

中文摘要
翻译
免费后使用错误是一种软件缺陷,它可能允许攻击者远程注入恶意软件或破坏内存值。这种攻击可能导致私人数据被盗,蠕虫和病毒的传播,或者创建僵尸网络节点,这些节点可以被编程为喷出垃圾邮件或破坏互联网流量。最近,在微软的Internet Explorer、Adobe Acrobat Reader和Firefox等关键软件中发现了“免费后再使用”漏洞。Watchdog项目的目标是设计硬件和软件机制来防止所有此类漏洞。为了防止“免费后使用”漏洞,研究人员将开发硬件,在不影响系统性能的情况下,强制执行安全的手动内存管理。他们将研究其设计的正式模型,以确定技术的正确性。硬件设计将使用详细的微架构模拟进行原型设计。研究人员将通过使用一套基准测试和现成的软件来评估正确性和性能。这些工具和原型将被公开分发,供其他人使用,研究结果将被集成到研究人员教授的安全和硬件课程中。如果成功,这项研究开发的技术将产生重大的社会影响,通过消除一类重要的漏洞来提高我们的计算生态系统的安全性,这些漏洞正在被积极地利用来破坏系统和传播恶意软件。
英文摘要
A use-after-free error is a software flaw that potentially allows an attacker to remotely inject malicious software or corrupt memory values. Such attacks can result in the theft of private data, propagation of worms and viruses, or the creation of botnet nodes that can be programmed to spew spam or disrupt Internet traffic. Recently, use-after-free vulnerabilities have been found in crucial software such as Microsoft's Internet Explorer, Adobe Acrobat Reader, and Firefox among others. The goal of the Watchdog project is to devise hardware and software mechanisms to prevent all such vulnerabilities.To prevent use-after-free vulnerabilities, the researchers will develop hardware for enforcing safe manual memory management, without compromising system performance. They will study a formal model of their designs to establish the correctness of the techniques. The hardware designs will be prototyped using detailed micro-architectural simulations. The researchers will evaluate correctness and performance by using a suite of benchmark tests and off-the-shelf software. The tools and prototypes will be openly distributed for others to build upon, and the research findings will be integrated into the security and hardware courses taught by the researchers. If successful, the technology developed by this research will have significant societal impacts, improving the security of our computing ecosystem by eliminating an important class of vulnerabilities that is actively being exploited to compromise systems and spread malware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
REU Site: Research Experience for undergraduates in Programming Languages (REPL)
  • 批准号:
    2244494
  • 项目类别:
    Standard Grant
  • 资助金额:
    $32.21万
  • 财政年份:
    2023
  • 负责人:
    Stephan Zdancewic
  • 依托单位:
SaTC: CORE: Medium: Secure and Formally-verified Low-level Languages
  • 批准号:
    2247088
  • 项目类别:
    Standard Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2023
  • 负责人:
    Stephan Zdancewic
  • 依托单位:
Student Travel for Programming Languages Mentoring Workshop at ACM SIGACT-SIGPLAN Symposium on Principles of Programming Languages, 2019 (PLMW@POPL)
  • 批准号:
    1841603
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2018
  • 负责人:
    Stephan Zdancewic
  • 依托单位:
NSF Student Travel Grant for 2018 Programming Languages
  • 批准号:
    1749155
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2017
  • 负责人:
    Stephan Zdancewic
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: