SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
批准号:
1801534
负责人:
Trent Jaeger
金额:
$80.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-15 至 2024-07-31
中文摘要
在寻找程序漏洞的竞赛中,攻击者的速度超过了开发人员。程序员必须找到程序中所有潜在的软件缺陷,并确定是否可以在所有部署中利用它们来防止漏洞,而攻击者只需要找到一个软件缺陷,就可以在任何一个部署中实现他们的目标。由于现代软件及其部署的复杂性,当前消除程序漏洞的技术无法发现所有此类缺陷。最近的漏洞检测研究不是证明不存在缺陷,而是探索更强大的技术来自动生成漏洞。然而,这种漏洞生成往往缺乏现代和新兴防御的系统模型,这可能有助于评估防御的效用。此外,一旦一个漏洞被生成,必须手动将防御措施添加到程序中以防止该漏洞。因此,漏洞检测尚未对防御给予足够的重视,以评估其有效性,也没有在必要时生成额外的防御。该项目提出了一种理论和技术,以不断迭代地改进防御,以对抗导致漏洞的威胁。开发了一种搜索违反安全策略的程序并扩展现有防御的方法,以自动阻止检测到的违规行为。主要的见解是将每个项目的威胁和防御连接到一个连贯的模型中,称为项目威胁图(PTG),以主动评估威胁是否使对手能够违反给定当前防御的项目安全策略,并自动改进防御以防止此类违反。该项目探讨了如何在给定程序内部和环境防御的情况下发现安全违规行为。安全违规用于生成目标防御和/或系统防御,以有效地阻止此漏洞,并阻止可能在给定性能约束下利用其他缺陷的潜在未知漏洞。这项研究的目标是不断改进对漏洞的防御。该方法在给定当前和即将到来的防御规范的情况下发现安全违规,自动收紧它们,并在不中断程序功能的情况下从尝试的攻击中恢复。在这个项目中开发的所有工具、基准测试和分析都作为开源发布。在拓展方面,重点是夺旗比赛和夏季软件安全课程。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Adversaries are outpacing developers in the race to find program vulnerabilities. Where programmers have to find all potential software flaws in their programs and determine whether they are exploitable across all deployments to prevent vulnerabilities, adversaries need only find one software flaw that enables them to achieve their goals in any one deployment. Current techniques to rid programs of vulnerabilities cannot find all such flaws due to the complexity of modern software and their deployments. Rather than proving the absence of flaws, recent vulnerability detection research is exploring more powerful techniques to automate exploit generation. However, such exploit generation often lacks a systematic model of modern and emerging defenses, which may be useful in assessing the utility of defenses. In addition, once an exploit is generated, defenses to prevent that exploit must be added manually to the program. As a result, vulnerability detection does not yet pay enough attention to defenses to assess their effectiveness nor generate additional defenses when necessary.This project proposes a theory and techniques to improve defenses continuously and iteratively to counter threats that cause vulnerabilities. A method is developed that searches programs for security policy violations and extends existing defenses to prevent detected violations automatically. The main insight is to link the threats and defenses of each program into one coherent model, called the Program Threat Graph (PTG), to evaluate proactively whether threats enable adversaries to violate program security policies given current defenses and automate the improvement of defenses to prevent such violations. The project explores how to find security violations given a program's internal and environmental defenses. Security violations are used to generate both targeted defenses and/or systematic defenses to block this exploit efficiently and block potentially unknown exploits that may leverage other flaws under given performance constraints. The goal of this research is to continuously improve defenses against vulnerabilities. The approach discovers security violations given a specification for both current and upcoming defenses, tightening them automatically and recovering from attempted attacks without disrupting program functionality. All tools, benchmarks, and analyses developed during this project are released as open-source. For outreach, the focus is on capture-the-flag competitions and summer software security courses.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3319535.3354218
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Shen Liu;Dongrui Zeng;Yongzhe Huang;Frank Capobianco;Stephen McCamant;T. Jaeger;Gang Tan]
通讯作者:
Shen Liu;Dongrui Zeng;Yongzhe Huang;Frank Capobianco;Stephen McCamant;T. Jaeger;Gang Tan
DOI:
10.1145/3368860.3368862
发表时间:
2019-09
期刊:
Proceedings of the New Security Paradigms Workshop
影响因子:
--
作者:
[Frank Capobianco;R. George;Kaiming Huang;T. Jaeger;S. Krishnamurthy;Zhiyun Qian;Mathias Payer;Paul L. Yu]
通讯作者:
Frank Capobianco;R. George;Kaiming Huang;T. Jaeger;S. Krishnamurthy;Zhiyun Qian;Mathias Payer;Paul L. Yu
DOI:
10.1145/3381052.3381328
发表时间:
2020-03
期刊:
Proceedings of the 16th ACM SIGPLAN/SIGOPS International Conference on Virtual Execution Environments
影响因子:
--
作者:
[Vikram Narayanan;Yongzhe Huang;Gang Tan;T. Jaeger;A. Burtsev]
通讯作者:
Vikram Narayanan;Yongzhe Huang;Gang Tan;T. Jaeger;A. Burtsev
DOI:
10.1145/3243734.3243739
发表时间:
2018-05
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer]
通讯作者:
Kyriakos K. Ispoglou;Bader Albassam;T. Jaeger;Mathias Payer
DOI:
10.1145/3593856.3595914
发表时间:
2023-06
期刊:
Proceedings of the 19th Workshop on Hot Topics in Operating Systems
影响因子:
--
作者:
[A. Burtsev;Vikram Narayanan;Yongzhe Huang;Kaiming Huang;Gang Tan;T. Jaeger]
通讯作者:
A. Burtsev;Vikram Narayanan;Yongzhe Huang;Kaiming Huang;Gang Tan;T. Jaeger
共 6 条
SaTC: CORE: Small: Information Flow Control Infrastructure for Single-Use Service Platforms
-
批准号:1816282
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Trent Jaeger
-
依托单位:
TWC: Medium: Collaborative: Retrofitting Software for Defense-in-Depth
-
批准号:1408880
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2014
-
负责人:Trent Jaeger
-
依托单位:
Trusted Infrastructure Workshop 2013
-
批准号:1313027
-
项目类别:Standard Grant
-
资助金额:$1.5万
-
财政年份:2013
-
负责人:Trent Jaeger
-
依托单位:
TC: Small: Towards Customer-Centric Utility Computing
-
批准号:1117692
-
项目类别:Continuing Grant
-
资助金额:$48.8万
-
财政年份:2011
-
负责人:Trent Jaeger
-
依托单位:
TC: Medium: Collaborative Research: Techniques to Retrofit Legacy Code with Security
-
批准号:0905343
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2009
-
负责人:Trent Jaeger
-
依托单位:
CPS:Small:Collaborative Research:Establishing Integrity in Dynamic Networks of Cyber Physical Devices
-
批准号:0931914
-
项目类别:Standard Grant
-
资助金额:$18.5万
-
财政年份:2009
-
负责人:Trent Jaeger
-
依托单位:
CT-IS: Shamon: Systems Approaches for Constructing Distributed Trust
-
批准号:0627551
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2006
-
负责人:Trent Jaeger
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: