CRII: SaTC: Lockdown: Guarded Control-Flow and Data Privacy for Sensitive Data
CRII: SaTC: Lockdown: Guarded Control-Flow and Data Privacy for Sensitive Data
批准号:
1464155
负责人:
Mathias Payer
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-07-01 至 2017-06-30
中文摘要
软件系统不断受到攻击:从运行中的计算机系统中提取敏感数据是攻击者的主要目标,而且利润丰厚。然而,当前的防御机制无法保护机密或私有数据以及底层系统的完整性和可用性。虽然发现和修复漏洞很重要,但不太可能发现所有漏洞。因此,即使存在漏洞,也有必要建立更强大的防御机制来保护软件系统。本项目的研究将通过对定义良好的已识别敏感数据子集强制执行完整性和保密性来提高遗留代码和新开发源代码的安全性。该项目提出了新的安全策略,以增加遗留软件抵御攻击的弹性,保护正在运行的程序免受攻击者强加的偏差,并保护重要数据的子集,即使应用程序受到损害。当今系统上运行的大多数软件都是用内存不安全语言编写的。内存安全漏洞非常多,经常被用来危害系统。现有的在C/ c++基础上改进内存安全的技术通常会导致令人望而却步的开销,与遗留代码不兼容,或者只提供部分保护。基于代码指针完整性(CPI),这是一种基于编译器的技术,可以加强代码指针的内存安全性,该项目建议保护控制流并加强敏感数据的数据机密性。这两种技术都将作为编译器传递实现。受保护的控制流将利用基于编译器的静态分析来识别可能用于条件控制流决策的所有数据。在第二步中,编译器为程序提供保护,以保护这些数据和代码指针,从而防止任何攻击者引起的控制流偏差。数据机密性将引入基于静态编译器的分析,用于识别和标记敏感数据,如密码、加密密钥或身份验证令牌。然后,检测传递将添加保护,以在运行时强制执行机密性保证。这些保护措施保护敏感数据子集的私密性和安全性,使其免受攻击者的攻击。数据机密性强制完整性和机密性,即使攻击者具有完整的内存读访问权。此外,该项目将开发度量标准和基准,以评估这些安全策略在不同程序环境中的有效性。
英文摘要
Software systems are under constant attack: extracting sensitive data from running computer systems is a prime and highly lucrative target for attackers. Yet, current defense mechanisms fail to protect confidential or private data along with the integrity and availability of the underlying system. While it is important to find and fix vulnerabilities, it is unlikely that all vulnerabilities will ever be discovered. Therefore, there is an argument to be had for stronger defense mechanisms that protect software systems even in the presence of vulnerabilities. The research in this project will improve the security of legacy and newly developed source code by enforcing both integrity and confidentiality for a well-defined sub-set of identified sensitive data. The project proposes new security policies that increase the resilience of legacy software against attacks, protecting running programs against attacker-imposed deviations and and protecting a subset of important data even if the application is compromised.The majority of software that runs on today's systems is written in memory unsafe languages. Memory safety vulnerabilities are abundant and are often used to compromise systems. Existing techniques that retrofit memory safety on top of C/C++ often result in prohibitive overhead, are not compatible with legacy code, or only provide partial protection. Building on Code-Pointer Integrity (CPI), a compiler-based technique that enforces memory safety for code pointers, this project proposes to guard the control-flow and to enforce data confidentiality for sensitive data. Both techniques will be implemented as compiler-passes. Guarded control-flow will leverage a compiler-based static analysis to identify all data that may be used in conditional control-flow decisions. In a second step, the compiler instruments the program with guards to protect this data alongside code pointers, thereby protecting from any attacker-induced control-flow deviation. Data confidentiality will introduce a static compiler-based analysis that identifies and tags sensitive data like passwords, cryptographic keys, or authentication tokens. An instrumentation pass will then add guards to enforce confidentiality guarantees at runtime. These guards keep the subset of sensitive data private and secure from attackers. Data confidentiality enforces integrity and confidentiality even if the attacker has full memory read access. In addition, this project will develop metrics and benchmarks to evaluate the effectiveness of these security policies in the context of different programs.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: TTP Option: Medium: Collaborative: ENCORE - ENhanced program protection through COmpiler-REwriter cooperation
-
批准号:1513783
-
项目类别:Standard Grant
-
资助金额:$40.37万
-
财政年份:2015
-
负责人:Mathias Payer
-
依托单位:
海外基金