CAREER: User-Space Protection Domains for Compositional Information Security
CAREER: User-Space Protection Domains for Compositional Information Security
批准号:
1624124
负责人:
Gang Tan
金额:
$27.66万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-01-01 至 2017-12-31
中文摘要
针对电子邮件阅读器和网页浏览器等软件应用程序的攻击很常见。这些攻击可能造成各种损害,从应用程序故障、私人数据丢失到完全接管用户的计算机。限制损害的一种有效策略是在应用程序设计中采用最小特权原则:将应用程序划分为几个保护域,每个域只授予执行其任务所需的特权。在这种设计中,一个域的泄露不会直接导致其他安全敏感域的泄露。PI建议设计和实现一个框架,使软件开发人员能够轻松地将最小特权原则应用到他们的应用程序中。提出的框架将显著提高关键软件应用程序的安全性。它将通过设计构建安全软件系统的新技术使软件行业受益。提出的研究结合了几个新颖的思想:(1)通过二进制级强制隔离和信息流安全的用户空间保护域;(2)允许灵活配置应用程序安全架构的声明性语言;(3)二进制级分区工具,自动将应用程序划分为最小权限组件;(4)组合推理机制,允许开发人员对应用程序的端到端信息安全进行形式化推理。由于停留在用户空间,所建议的框架是独立于操作系统的,并且通过处理二进制代码,它与源语言无关,使其更广泛地适用。开发人员可以使用它对应用程序进行分区,灵活地配置其安全体系结构,并对其信息安全性进行推理。在教育方面,PI将组织一系列活动,以提高高中生的安全、隐私和安全编程意识。中心活动是一个夏季研讨会,聚集了当地的高中技术教师,帮助他们设计可以融入学校技术课程的课程计划。
英文摘要
Attacks on software applications such as email readers and web browsers are common. These attacks can cause damages ranging from application malfunction, loss of private data, to a complete takeover of users' computers. One effective strategy for limiting the damage is to adopt the principle of least privilege in application design: the application is split into several protection domains and each domain is given only the necessary privileges to perform its task. In this design, the compromise of one domain does not directly lead to the compromise of other security-sensitive domains. The PI proposes to design and implement a framework that makes it easy for software developers to apply the principle of least privilege to their applications. The proposed framework will significantly improve the security of critical software applications. It will benefit the software industry by designing new technologies for building secure software systems.The proposed research combines several novel ideas: (1) user-space protection domains through binary-level enforcement of isolation and information-flow security; (2) a declarative language that allows for flexible configuration of an application's security architecture; (3) a binary-level partitioning tool that automatically splits an application into components of least privilege; (4) a compositional reasoning mechanism that allows developers to perform formal reasoning about an application's end-to-end information security. By staying in the user space, the proposed framework is OS independent, and by working on binary code, it is source-language agnostic, making it more broadly applicable. Developers can use it to partition an application, flexibly configure its security architecture, and reason about its information security. On the education side, the PI will organize a series of activities to increase high school students' awareness of security, privacy, and secure programming. The central activity is a summer workshop that gathers local high-school technology teachers and helps them design lesson plans that can be integrated into their schools' technology curriculum.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Small: Detecting and Localizing Non-Functional Vulnerabilities in Machine Learning Libraries
-
批准号:2230061
-
项目类别:Standard Grant
-
资助金额:$24.66万
-
财政年份:2023
-
负责人:Gang Tan
-
依托单位:
SaTC: CORE: Small: Precise and Robust Binary Reverse Engineering and its Applications
-
批准号:2243632
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Gang Tan
-
依托单位:
CAPA: Collaborative Research: Lightweight Abstract Memory Features
-
批准号:1723571
-
项目类别:Continuing Grant
-
资助金额:$25.0万
-
财政年份:2017
-
负责人:Gang Tan
-
依托单位:
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
-
批准号:1624125
-
项目类别:Standard Grant
-
资助金额:$1.39万
-
财政年份:2016
-
负责人:Gang Tan
-
依托单位:
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
-
批准号:1624126
-
项目类别:Standard Grant
-
资助金额:$27.33万
-
财政年份:2016
-
负责人:Gang Tan
-
依托单位:
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
-
批准号:1408826
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2014
-
负责人:Gang Tan
-
依托单位:
SHF: Small: Collaborative Research: Reusable Tools for Formal Modeling of Machine Code
-
批准号:1217710
-
项目类别:Standard Grant
-
资助金额:$25.88万
-
财政年份:2012
-
负责人:Gang Tan
-
依托单位:
CAREER: User-Space Protection Domains for Compositional Information Security
-
批准号:1149211
-
项目类别:Continuing Grant
-
资助金额:$48.31万
-
财政年份:2012
-
负责人:Gang Tan
-
依托单位:
TC: Small: Collaborative Research: Securing Multilingual Software Systems
-
批准号:0915157
-
项目类别:Standard Grant
-
资助金额:$26.5万
-
财政年份:2009
-
负责人:Gang Tan
-
依托单位:
III-CXT-Small: Collaborative Research: Structuring, Reasoning, and Querying in a Very Large Medical Image Database
-
批准号:0812073
-
项目类别:Continuing Grant
-
资助金额:$5.45万
-
财政年份:2008
-
负责人:Gang Tan
-
依托单位:
III-CXT-Small: Collaborative Research: Structuring, Reasoning, and Querying in a Very Large Medical Image Database
-
批准号:0854606
-
项目类别:Continuing Grant
-
资助金额:$5.45万
-
财政年份:2008
-
负责人:Gang Tan
-
依托单位:
海外基金