课题基金 / 基金详情

TC: Small: Least Privilege Enforcement through Secure Memory Views

TC: Small: Least Privilege Enforcement through Secure Memory Views
TC:小:通过安全内存视图执行最低权限
批准号:
1117065
负责人:
Aniket Kate
金额:
$49.99万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-08-15 至 2017-07-31

项目摘要

项目成果

Aniket Kate的其他基金

相似基金

相关文献

中文摘要
翻译
该项目的目标是提供保护,防止通过不受信任的第三方软件组件进行攻击,并防止恶意应用程序操纵。这些问题构成了当前软件中一类重要的漏洞,并且与一个共同的特征有关——缺乏以细粒度的方式划分程序和由其操纵的数据的能力,以及控制结果组成部分之间的交互的能力。这个项目通过一个计算模型提出了实际的细粒度“最小特权”实施,其中堆可以被划分为动态数量的内存域。可以定义安全上下文——称为安全内存视图(smv)——将在其中执行的代码的特权映射到内存域。允许线程以一种安全和可控的方式动态切换它们的特权集(即切换它们绑定到的smv),称为安全上下文切换。这些想法是通过三个核心贡献实现的。(1)设计编程模型是为了让应用程序编程人员能够轻松地应用所提出的技术,同时还提供足够的结构来推断所得到的属性并确保这些属性的安全。(2)通过开发支持语言扩展的编译器以及修改语言运行时,新概念在现代主流编程语言中得到了具体化。(3)提出了一种安全上下文切换的高效实现方法,涉及语言运行时和操作系统内核本身。为了验证研究结果,一个流行的网络浏览器和一个网络服务器被增强为使用smv。通过使用广泛使用的开源软件来实现和验证所提出的支持,我们的概念可以为大型社区使用以及进一步的研究和开发提供支持。
英文摘要
The goal of this project is to provide protection against exploits through untrusted third-party software components and against malicious application manipulation. These problems constitute an important class of vulnerabilities in current software, and are tied to a common denominator -- the lack of ability to divide a program and the data manipulated by it in a fine-grained manner and to control the interactions between the resulting constituents. This project proposes practical fine-grained ``least privilege'' enforcement through a computation model where the heap can be divided into a dynamic number of memory domains. Security contexts --- called secure memory views (SMVs) --- can be defined that map privileges of code executing within them onto memory domains. Threads are allowed to dynamically switch their set of privileges (i.e., switch which SMVs they are bound to) in a secure and controlled fashion, termed security context switching. These ideas are realized through three core contributions. (1) A programming model is devised to allow the application programmer to easily apply the proposed techniques, while also providing enough structure to reason about the resulting properties and to secure these. (2) The new concepts are reified within a modern mainstream programming language through development of a compiler supporting the language extensions, as well as modifications of the language runtime. (3) An efficient implementation of security context switching is proposed, involving both the language runtime and the operating system kernel itself. To validate the research, a popular web browser as well as a web server are enhanced to use SMVs. By using widely employed open-source software for implementing and validating the proposed support our concepts become available to a large community for use as well as further research and development.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CAREER: Towards Privacy and Availability of Inter-blockchain Communication
  • 批准号:
    1846316
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $43.0万
  • 财政年份:
    2019
  • 负责人:
    Aniket Kate
  • 依托单位:
SaTC-BSF: CORE: Small: Collaborative: Making Blockchains Scale Privately and Reliably
  • 批准号:
    1719196
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.77万
  • 财政年份:
    2017
  • 负责人:
    Aniket Kate
  • 依托单位:
TWC: Small: Practical Assured Big Data Analysis in the Cloud
  • 批准号:
    1421910
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.0万
  • 财政年份:
    2014
  • 负责人:
    Aniket Kate
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: