TWC: Small: Caging Libraries To Control Software Faults
TWC: Small: Caging Libraries To Control Software Faults
批准号:
1223588
负责人:
Justin Cappos
金额:
$49.99万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-09-01 至 2016-08-31
中文摘要
大多数应用程序中的绝大多数代码来自它导入的库,而不是程序本身。因此,黑客经常利用跨多个应用程序使用的库(如glibc或openssl)中的缺陷,而不是攻击特定于应用程序的代码中的单个缺陷。这使得攻击者更容易利用一个漏洞同时危害许多应用程序。这项工作将已部署程序中缺陷的影响隔离到尽可能小的区域。这将极大地提高云、移动电话以及两者之间所有应用程序的安全性。为了实现这一目标,本研究开发了一种新的抽象,作为一种轻量级且极其高效的进程内隔离机制,该机制基于操作系统虚拟化和内存安全代码执行(如SFI)的最新进展。这种抽象称为笼,它允许在同一进程中执行的不同代码片段彼此隔离。这意味着一段代码中的缺陷只能被用来利用这个笼子里的代码。从资源会计的角度来看,每个笼子在概念上也是它自己的过程。此外,笼子之间的调用非常轻量级,不需要上下文切换或操作系统干预。笼抽象提供了一种高性能且开销极低的隔离机制,同时提高了应用程序的安全性。
英文摘要
The vast majority of the code in most applications comes from the libraries it imports, rather than the program itself. As a result, hackers often exploit flaws in libraries like glibc or openssl that are used across multiple applications instead of attacking individual flaws in code specific to the application. This makes it easier for an attacker to compromise many applications at once with a single exploit. This work isolates the impact of flaws in a deployed program into the smallest area possible. This will dramatically increase the security of applications in the cloud, on mobile phones, and everything in between.To achieve this goal, this research develops a new abstraction that acts as a lightweight and extremely efficient intra-process isolation mechanism that builds on recent advances from operating system virtualization and memory-safe code execution (such as SFI). This abstraction, called a cage, allows different pieces of code that execute in the same process to be isolated from each other. This means that a flaw within a piece of code can only be used to exploit the code within that cage. Each cage also conceptually is its own process from an resource accounting standpoint. In addition, calls between cages are extremely lightweight and do not require a context switch or OS intervention. The cage abstraction provides an isolation mechanism that is high-performance and with very low overhead while improving application security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: TTP: Medium: Defending the Supply Chain of Democracy: Towards a Cryptographically Verified and Authenticated Network of Laws
-
批准号:2247829
-
项目类别:Standard Grant
-
资助金额:$68.76万
-
财政年份:2023
-
负责人:Justin Cappos
-
依托单位:
SaTC: TTP: Medium: Securing Python's Software Supply Chain
-
批准号:2054692
-
项目类别:Standard Grant
-
资助金额:$80.0万
-
财政年份:2021
-
负责人:Justin Cappos
-
依托单位:
ASPIRE: An SFS Program for Interdisciplinary Research and Education (Renewal)
-
批准号:1922291
-
项目类别:Continuing Grant
-
资助金额:$483.05万
-
财政年份:2019
-
负责人:Justin Cappos
-
依托单位:
SaTC: TTP: Medium: Collaborative: Securing the Software Supply Chain
-
批准号:1801376
-
项目类别:Standard Grant
-
资助金额:$76.6万
-
财政年份:2018
-
负责人:Justin Cappos
-
依托单位:
SaTC: CORE: Small: Better Software Security Through Caging
-
批准号:1815925
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Justin Cappos
-
依托单位:
Collaborative Research: EAGER: REAL Leafy - A Sustainable, Viral Infrastructure-as-a-Service Edge Cloud
-
批准号:1820906
-
项目类别:Standard Grant
-
资助金额:$8.93万
-
财政年份:2018
-
负责人:Justin Cappos
-
依托单位:
CICI: Data Provenance: Data Quality and Security Evaluation Framework for Mobile Devices Platform
-
批准号:1547290
-
项目类别:Standard Grant
-
资助金额:$29.99万
-
财政年份:2016
-
负责人:Justin Cappos
-
依托单位:
EAGER: Collaborative: Using Cognitive Techniques To Detect and Prevent Security Flaws
-
批准号:1444827
-
项目类别:Standard Grant
-
资助金额:$13.43万
-
财政年份:2015
-
负责人:Justin Cappos
-
依托单位:
TWC: Medium: Collaborative: Developer Crowdsourcing: Capturing, Understanding, and Addressing Security-related Blind Spots in APIs
-
批准号:1513457
-
项目类别:Standard Grant
-
资助金额:$39.43万
-
财政年份:2015
-
负责人:Justin Cappos
-
依托单位:
CI-New: Collaborative Research: An Open Observatory for the Internet's Last Mile
-
批准号:1405907
-
项目类别:Standard Grant
-
资助金额:$19.99万
-
财政年份:2014
-
负责人:Justin Cappos
-
依托单位:
CI-EN: Helping Home Network Research to Seattle On Access Routers (SOAR)
-
批准号:1405904
-
项目类别:Standard Grant
-
资助金额:$68.9万
-
财政年份:2014
-
负责人:Justin Cappos
-
依托单位:
TTP: Securing Python Package Management with The Update Framework (TUF)
-
批准号:1345049
-
项目类别:Standard Grant
-
资助金额:$18.0万
-
财政年份:2013
-
负责人:Justin Cappos
-
依托单位:
CI-ADDO-EN: Enhancing and Supporting a Community Testbed
-
批准号:1205415
-
项目类别:Standard Grant
-
资助金额:$34.63万
-
财政年份:2012
-
负责人:Justin Cappos
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: