课题基金 / 基金详情

CRII: SaTC: A Language Based Approach to Hybrid Mobile App Security

CRII: SaTC: A Language Based Approach to Hybrid Mobile App Security
CRII:SaTC:基于语言的混合移动应用安全方法
批准号:
1566321
负责人:
Meera Sridhar
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2020-08-31

项目摘要

项目成果

Meera Sridhar的其他基金

相似基金

相关文献

中文摘要
翻译
在过去的几年里,全球混合移动的应用程序的份额出现了爆炸性的增长,与HTML5的日益普及相吻合。混合应用程序框架允许移动的开发人员仅使用Web技术设计应用程序代码,并提供本机代码和桥接代码(用于访问设备资源的API)即时移植到几个移动的平台所必需的。这项研究将开发技术,以减轻关键的安全和隐私漏洞的混合应用程序框架,通过创建一个密封的安全模型鲁棒的桥梁利用,以及最小化混合框架的总体攻击面。在日益依赖移动的技术的全球社会中,移动的应用程序安全是一项紧迫的责任,并影响到包括儿童在内的多个社会阶层。该项目将为迎接这一挑战作出重大贡献。从该项目中获得的案例研究,实际例子和研究经验将被整合到研究生课程中,特别是网络安全硕士和证书课程。此外,该项目开发的有趣技术和实例将纳入专门针对计算机领域妇女的课程,目的是吸引和留住更多的计算机领域妇女。本研究将探索扩展强大的基于语言的安全技术,内联引用监控(INLINE REFERENCE MONITORING,简称INLINE)和静态分析,以解决混合应用程序安全性的新问题。该研究有三个主要目标:1)定义混合应用攻击面的系统映射,并建立一类针对有效的基于语言的实施的安全策略; 2)使安全策略方法适应复杂的跨平台混合软件堆栈,包括有效的完整中介,以实现监控系统的无缝保护和防篡改; 3)设计有效的静态分析算法,为混合应用中的页面推断细粒度的权限区域,这些权限区域将提高桥接访问粒度,并作为安全策略模型集成到安全策略框架中进行实施。这些目标将有助于为混合应用程序构建自动保护技术,保护安全应用程序功能的透明执法,以及可应用于脆弱应用程序的追溯执法。
英文摘要
The last few years have seen an explosive growth in the share of hybrid mobile apps worldwide, coinciding with the increasing ubiquity of HTML5. Hybrid app frameworks allow mobile developers to design app code using web technologies alone, and supply native and bridge code (APIs for accessing device resources) necessary for instant porting to several mobile platforms.This research will develop techniques to mitigate critical security and privacy vulnerabilities in hybrid app frameworks, by creating an airtight security model robust against bridge exploits, and minimizing the overall attack surface of the hybrid framework. In a global society increasingly reliant on mobile technology, mobile app security constitutes a pressing responsibility, and impacts several sections of society, including children. This project will provide a significant contribution towards meeting this challenge. Case studies, practical examples, and research experience gained from this project will be integrated into graduate-level courses, especially Master's and certificate programs in cyber-security. Additionally, interesting techniques and examples developed in this project will be incorporated into curricula specifically targeted for women in computing initiatives, with the objective of attracting and retaining more women in computing fields. This research will explore extension of powerful language-based security techniques, in-lined reference monitoring (IRM) and static analysis, to the novel and significant problem domain of hybrid app security. The research has three major goals: 1) defining a systematic mapping of the hybrid app attack surface, and establishing a class of security policies that target effective language-based enforcement; 2) adapting the IRM approach to the complex, cross-platform hybrid software stack, including effective complete mediation for seamless protection and tamper-proofing of the monitoring system; 3) designing an effective static-analysis algorithm to infer fine-grained permissions-regions for pages in a hybrid app. These permissions regions will improve bridge access granularity, and serve as security policy models for integration into the IRM framework for enforcement. These goals will serve towards building automatic protection technologies for hybrid apps, transparent enforcement that preserves the functionality of safe apps, and retroactive enforcement that can be applied to vulnerable apps in the wild.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC:EDU: Enhancing Security Education in Hybrid Mobile and Internet of Things Firmware through Inclusive, Engaging, Learning Modules (E-SHIIELD)
海外基金