课题基金 / 基金详情

CAREER: Towards Trustworthy Operating Systems

CAREER: Towards Trustworthy Operating Systems
职业生涯:迈向可信赖的操作系统
批准号:
1453020
负责人:
Zhi Wang
金额:
$49.97万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2021-08-31

项目摘要

项目成果

Zhi Wang的其他基金

相似基金

相关文献

中文摘要
翻译
操作系统是计算机系统的关键软件,它管理硬件和软件资源,并为计算机程序提供基本服务。它对整个系统的安全起着至关重要的作用。不幸的是,现代操作系统经常被数百万行源代码所膨胀,并且经常发现并利用它们的严重漏洞。研究人员提出了基于“下一层”方法的各种新颖解决方案,其中引入了更特权的软件组件(即管理程序)来监视和/或调节操作系统。年代的行为。然而,现代管理程序的大型可信计算基础以及最近针对它们的攻击使这种方法受到质疑。该项目旨在开发一种系统的方法,通过启用操作系统的自我防御来提高操作系统的可信度,而无需求助于可能易受攻击的其他软件层。该项目的目标是通过三个关键步骤实现的:首先,该项目开发了一个内核级别的安全飞地,它将为其他安全系统和机制提供一个可信的、安全的执行环境。其次,基于飞地提供的强隔离,研究人员设计并实现了几种操作系统内核的自卫技术。第三,冷启动攻击是一种强大的物理攻击,可以从丢失或被盗的计算机(包括移动设备)的物理内存中提取敏感信息。它已经成为企业和政府的主要安全问题。该项目通过加密商品硬件平台上敏感程序的整个内存来研究针对冷启动攻击的全面防御。该项目的研究结果可以大大提高我们对恶意和隐蔽的内核级恶意软件和冷启动攻击的防御能力,从而显著提高计算机系统的可信度。研究成果通过出版物传播,发布开发的工具,并纳入研究生和本科生的教育活动。
英文摘要
An operating system is the key software of a computer system that manages the hardware and software resources and provides essential services to computer programs. It plays a critical role in the security of the whole system. Unfortunately, modern operating systems are often bloated with millions of lines of source code, and serious vulnerabilities are routinely being discovered and exploited from them. Researchers have proposed various novel solutions based on the "one-layer-below" approach, in which a more privileged software component (i.e., a hypervisor) is introduced to monitor and/or regulate the operating system?s behavior. However, the large trusted computing base of modern hypervisors and the recent attacks against them put this approach into question. This project aims at developing a systematic approach to improve the trustworthiness of operating systems by enabling their self-defense, without resorting to other software layers that may be vulnerable themselves.The goal of this project is being achieved in three key steps: first, the project develops a kernel-level security enclave that will provide a trusted, secure execution environment for other security systems and mechanisms. Second, based on the strong isolation provided by the enclave, the researchers design and implement several self-defense techniques for operating system kernels. Third, a cold-boot attack is a powerful physical attack that can extract sensitive information from the physical memory of a lost or stolen computer (including mobile devices). It has become a major security concern for corporations and governments. This project investigates a comprehensive defense against cold-boot attacks by encrypting the whole memory of a sensitive program on commodity hardware platforms. The results from this project could substantially improve our defensive capabilities against malicious and stealthy kernel-level malware and cold-boot attacks, and thus significantly improving the trustworthiness of computer systems. Research results are disseminated through publications, releasing of the tools developed, and integrating into the educational activities at both the graduate and undergraduate levels.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: RSARC: DICE - Data Insurance in the Cluster Environment
  • 批准号:
    1738912
  • 项目类别:
    Standard Grant
  • 资助金额:
    $59.03万
  • 财政年份:
    2017
  • 负责人:
    Zhi Wang
  • 依托单位:
海外基金