SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
SaTC: STARSS: Small: Domain Informed Techniques for Detecting and Defending Against Malicious Firmware
批准号:
1815883
负责人:
Kevin Butler
金额:
$33.33万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-08-15 至 2022-12-31
中文摘要
嵌入式系统在我们的日常生活中扮演着重要的角色。从计算机和消费电子产品到家用电器和汽车,它们无处不在,并且代表了一个估计价值近1600亿美元的市场。然而,它们中的许多使用便宜的微控制器,不易分析,因此尚不清楚它们在实践中的运行情况。该项目旨在通过开发技术来分析这些系统的固件,特别是关于流行的通用串行总线(USB)和蓝牙协议,以提高这些系统的安全性和可靠性。该项目将涉及开发一个平台,用于对这些常见但被忽视的微控制器架构进行固件分析。目标是验证这些嵌入式设备上关键通信的安全性。该项目建立在三个研究重点之上:1)USB和蓝牙协议及其子类的形式化建模,以及对可能的攻击场景的自动探索,2)具有新颖查询语言和分析后端的固件分析框架,3)允许在允许机器使用设备之前对设备进行运行时审查的动态执行基础设施。 该项目将创建可广泛部署在消费者、企业、政府和军事环境中的技术和系统。在USB和蓝牙环境中构建框架的经验教训可以作为一个更大的目标,为通用嵌入式和物联网(IoT)环境开发完整性框架。 本项目的产品将至少在项目期间得到维护。该项目的数据和代码将存储在网站www.firmware-analysis.org上。该奖项反映了NSF的法定使命,并被认为值得通过使用基金会的知识价值和更广泛的影响审查标准进行评估来支持。
英文摘要
Embedded systems play a large role in our daily lives. They are found in everything from computers and consumer electronics to appliances and automobiles, and represent a market estimated to be worth almost $160 billion. Many of them, however, use inexpensive microcontrollers that cannot easily be analyzed, so it is unclear how well they operate in practice. This work seeks improve the safety and security of these systems by developing techniques to analyze their firmware, particularly with regards to the popular Universal Serial Bus (USB) and Bluetooth protocols.This project will involve development of a platform for allowing firmware analysis of these common but overlooked microcontroller architectures. The goal is to validate the security of critical communications on these embedded devices. The project builds on three research thrusts: 1) Formal modeling of the USB and Bluetooth protocols and their sub-classes and automatic exploration of possible attack scenarios, 2) A firmware analysis framework with a novel query language and an analysis back-end, 3) A dynamic enforcement infrastructure that allows runtime vetting of devices prior to allowing machines to use them. This project will create techniques and systems that can be broadly deployed in consumer, enterprise, government and military environments. The lessons learned from building frameworks in the USB and Bluetooth environments can serve as a larger goal towards developing integrity frameworks for general-purpose embedded and internet-of-things (IoT) environments. The products of this project will be maintained for at least the duration of the project. Data and code from this project will be stored on the website www.firmware-analysis.org.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/tdsc.2022.3160346
发表时间:
2023-03
期刊:
IEEE Transactions on Dependable and Secure Computing
影响因子:
7.3
作者:
[Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian]
通讯作者:
Tuba Yavuz;Farhaan Fowze;Grant Hernandez;K. Bai;Kevin R. B. Butler;D. Tian
Analyzing system software components using API model guided symbolic execution
使用 API 模型引导的符号执行分析系统软件组件
DOI:
10.1007/s10515-020-00276-5
发表时间:
2020
期刊:
Automated Software Engineering
影响因子:
3.4
作者:
[Yavuz, Tuba, Bai, Ken]
通讯作者:
Bai, Ken
BigMAC: Fine-Grained Policy Analysis of Android Firmware
BigMAC:Android 固件的细粒度策略分析
DOI:
--
发表时间:
2020
期刊:
29th USENIX Security Symposium (USENIX Security'20
影响因子:
--
作者:
[Hernandez, Grant, Tian, Dave Jing, Yadav, Anurag Swarnim, Williams, Byron J., Butler, Kevin R.B.]
通讯作者:
Butler, Kevin R.B.
DOI:
10.1109/tse.2019.2939526
发表时间:
2019-09
期刊:
IEEE Transactions on Software Engineering
影响因子:
7.4
作者:
[Farhaan Fowze;D. Tian;Grant Hernandez;Kevin R. B. Butler;Tuba Yavuz]
通讯作者:
Farhaan Fowze;D. Tian;Grant Hernandez;Kevin R. B. Butler;Tuba Yavuz
DOI:
10.14722/ndss.2022.23136
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
作者:
[Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler]
通讯作者:
Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler
共 9 条
Collaborative Research: SaTC: CORE: Medium: Enabling Practically Secure Cellular Infrastructure
-
批准号:2055014
-
项目类别:Standard Grant
-
资助金额:$59.8万
-
财政年份:2022
-
负责人:Kevin Butler
-
依托单位:
Collaborative Proposal: SaTC: Frontiers: Securing the Future of Computing for Marginalized and Vulnerable Populations
-
批准号:2206950
-
项目类别:Continuing Grant
-
资助金额:$403.58万
-
财政年份:2022
-
负责人:Kevin Butler
-
依托单位:
Travel Grant Support for Association for Computing Machinery (AC) WiSec 2018
-
批准号:1823067
-
项目类别:Standard Grant
-
资助金额:$0.9万
-
财政年份:2018
-
负责人:Kevin Butler
-
依托单位:
EAGER: Collaborative: Secure and Efficient Data Provenance
-
批准号:1445983
-
项目类别:Standard Grant
-
资助金额:$11.01万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
EAGER: Collaborative: Secure and Efficient Data Provenance
-
批准号:1540216
-
项目类别:Standard Grant
-
资助金额:$11.01万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
TC: Small: Protection Mechanisms for Portable Storage
-
批准号:1540218
-
项目类别:Continuing Grant
-
资助金额:$20.78万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
-
批准号:1540217
-
项目类别:Continuing Grant
-
资助金额:$32.2万
-
财政年份:2014
-
负责人:Kevin Butler
-
依托单位:
CAREER: Securing Critical Infrastructure with Autonomously Secure Storage
-
批准号:1254198
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2013
-
负责人:Kevin Butler
-
依托单位:
TC: Small: Protection Mechanisms for Portable Storage
-
批准号:1118046
-
项目类别:Continuing Grant
-
资助金额:$49.95万
-
财政年份:2011
-
负责人:Kevin Butler
-
依托单位:
海外基金