课题基金 / 基金详情

TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software

TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software
TWC:媒介:协作:商品软件的自动逆向工程
批准号:
1409807
负责人:
Wenke Lee
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-09-01 至 2017-08-31

项目摘要

项目成果

Wenke Lee的其他基金

相似基金

相关文献

中文摘要
翻译
软件,包括商业应用程序或嵌入式设备固件等常见示例,通常作为闭源二进制文件提供。虽然先前的学术工作已经研究了如何自动发现二进制软件中的漏洞,甚至如何自动针对这些漏洞进行攻击,但回答有关闭源软件的基本安全相关问题的能力仍然难以捉摸。本项目旨在提供回答这些问题的算法和工具。利用以前的工作,基于仿真器的动态分析,我们提出了技术,扩展这种高保真度的分析,以捕获和提取整个系统的行为的背景下,嵌入式设备固件和闭源应用程序。使用从这个分析平台和二进制代码分析技术收集的动态执行痕迹相结合,我们提出了二进制程序工件的自动结构分析技术,分解系统和用户级程序到逻辑模块,通过推理的高级语义行为。这种分解以子程序粒度提供了自动学习的每个模块之间的接口和信息流的描述作为输出。具体活动包括:(a)发展软件引导的全系统仿真器,以支援对真实的嵌入式系统进行复杂的动态分析;(B)发展先进的自动化技术,以便在结构上将闭源软件分解成其组成模块;(c)发展自动化技术,以便产生全系统执行和软件组件的高级摘要;以及(d)开发用于使加密网络协议的反向工程和模糊测试自动化的技术。本文提出的研究将在安全研究界之外产生重大影响。我们将把我们的计划的研究成果纳入我们的本科和研究生教学课程,以及在课外教育工作,如捕获的旗帜,在大波士顿和亚特兰大大都市地区有广泛的推广。密切的联系,集体PI拥有的行业将促进研究转化为实用的防御工具,可以部署到现实世界的系统和网络。
英文摘要
Software, including common examples such as commercial applications or embedded device firmware, is often delivered as closed-source binaries. While prior academic work has examined how to automatically discover vulnerabilities in binary software, and even how to automatically craft exploits for these vulnerabilities, the ability to answer basic security-relevant questions about closed-source software remains elusive.This project aims to provide algorithms and tools for answering these questions. Leveraging prior work on emulator-based dynamic analyses, we propose techniques for scaling this high-fidelity analysis to capture and extract whole-system behavior in the context of embedded device firmware and closed-source applications. Using a combination of dynamic execution traces collected from this analysis platform and binary code analysis techniques, we propose techniques for automated structural analysis of binary program artifacts, decomposing system and user-level programs into logical modules through inference of high-level semantic behavior. This decomposition provides as output an automatically learned description of the interfaces and information flows between each module at a sub-program granularity. Specific activities include: (a) developing software-guided whole-system emulator for supporting sophisticated dynamic analyses for real embedded systems; (b) developing advanced, automated techniques for structurally decomposing closed-source software into its constituent modules; (c) developing automated techniques for producing high-level summaries of whole system executions and software components; and (d) developing techniques for automating the reverse engineering and fuzz testing of encrypted network protocols. The research proposed herein will have a significant impact outside of the security research community. We will incorporate the research findings of our program into our undergraduate and graduate teaching curricula, as well as in extracurricular educational efforts such as Capture-the-Flag that have broad outreach in the greater Boston and Atlanta metropolitan areas.The close ties to industry that the collective PIs possess will facilitate transitioning the research into practical defensive tools that can be deployed into real-world systems and networks.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
2015 Cyber Security Education Workshop
  • 批准号:
    1544099
  • 项目类别:
    Standard Grant
  • 资助金额:
    $3.5万
  • 财政年份:
    2015
  • 负责人:
    Wenke Lee
  • 依托单位:
TWC SBE: TTP Option: Medium: Collaborative: EPICA: Empowering People to Overcome Information Controls and Attacks
  • 批准号:
    1409635
  • 项目类别:
    Standard Grant
  • 资助金额:
    $110.0万
  • 财政年份:
    2014
  • 负责人:
    Wenke Lee
  • 依托单位:
EAGER: The Conceptual Landscape of Information Manipulation
  • 批准号:
    1255453
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2012
  • 负责人:
    Wenke Lee
  • 依托单位:
SaTC Cyber Cafe
  • 批准号:
    1304678
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.34万
  • 财政年份:
    2012
  • 负责人:
    Wenke Lee
  • 依托单位:
海外基金