课题基金 / 基金详情

CRII: SaTC: Detecting Security Vulnerabilities in Instruction Set Architectures

CRII: SaTC: Detecting Security Vulnerabilities in Instruction Set Architectures
CRII:SaTC:检测指令集架构中的安全漏洞
批准号:
1464209
负责人:
Cynthia Sturton
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-05-15 至 2017-12-31

项目摘要

项目成果

Cynthia Sturton的其他基金

相似基金

相关文献

中文摘要
翻译
计算机处理器--计算机、平板电脑和手机的核心硬件--与软件--应用程序、Web浏览器和其他应用程序--之间的交互由指令集体系结构(ISA)管理。ISA是定义处理器如何响应来自软件的命令的规范。它又大又复杂,对于一个人来说太大了,无法完全理解和推理不同部分之间的所有相互作用。因此,ISA中存在安全漏洞。攻击者有时可以利用这些漏洞来窃取数据或控制机器。本研究是关于检测ISA中存在的安全漏洞的。找到并消除这些漏洞将为我们所有的计算活动创造一个更安全的基础。这将有利于需要高保证环境的政府机构、依赖硬件功能实现服务安全的云提供商,以及越来越依赖来自各种硬件设计公司的不同硬件组件来处理其私有和敏感数据的用户。研究人员假设ISA中的漏洞以两种方式之一发生:1)错误规范:ISA规定了危险的行为;或2)规范中的不确定性:ISA是不完整的,规范允许的可能行为之一是危险的。这项研究的假设是,可以关注ISA中相对较小的子集,对于这些类型的错误可能会发生。研究人员正在开发一种实用的方法,以发现哪些指令最有可能出现漏洞。有了这些信息,他们正在开发工具来检测和纠正ISA中的安全关键错误。除了做出实际贡献外,这些研究活动还提高了计算机科学界对ISA中的漏洞是什么样子以及在什么地方和什么条件下可能发生的了解。这将使今后的核查工作能够集中在《内审法》最关键的安全方面。
英文摘要
The interaction between computer processors -- the hardware at the heart of our computers, tablets, and phones -- and software -- apps, web browsers, and other applications -- is governed by an Instruction Set Architecture (ISA). The ISA is the specification that defines how the processor will respond to commands from the software. It is large and complex, too large for a person to understand and reason about all the interactions between different parts completely. As a result, security vulnerabilities exist in the ISA. These vulnerabilities can sometimes be exploited by attackers to steal data or take control of the machine. This research is about detecting security vulnerabilities that exist in the ISA. Finding and removing these vulnerabilities will create a more secure foundation for all our computing activities. This will benefit government agencies that require high assurance environments, cloud providers that rely on hardware features for the security for their service, and users who, more and more, are relying on diverse hardware components from a variety of hardware design companies to handle their private and sensitive data.The researchers posit that vulnerabilities in the ISA happen in one of two ways: 1) Erroneous specification: the ISA prescribes behavior that is dangerous; or 2) Nondeterminism in the specification: the ISA is incomplete and one of the possible behaviors allowed by the specification is dangerous. The hypothesis of this research is that it is possible to focus on a relatively small subset of the ISA for which these types of errors are likely to occur. The researchers are developing a practical methodology for discovering for which instructions vulnerabilities are most likely to occur. With that information, they are developing tools to detect and correct security-critical errors in the ISA. In addition to making a practical contribution, the research activities are improving understanding in the computer science community of what a vulnerability in an ISA looks like and where and under what conditions it is likely to occur. This will enable future verification efforts to concentrate on the most security-critical aspects of the ISA.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Hardware Security Insights: Analyzing Hardware Designs to Understand and Assess Security Weaknesses and Vulnerabilities
SaTC: STARSS: Small: Tackling the Corner Cases: Finding Security Vulnerabilities in CPU Designs
CPS: Frontier: Collaborative Research: VeHICaL: Verified Human Interfaces, Control, and Learning for Semi-Autonomous Systems
EAGER: Identifying Security Critical Properties of a Processor
海外基金