SaTC: CORE: Small: Collaborative: Understanding and Detecting Memory Bugs in Rust
SaTC: CORE: Small: Collaborative: Understanding and Detecting Memory Bugs in Rust
批准号:
1956364
负责人:
Hao Chen
金额:
$20.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-07-01 至 2024-06-30
中文摘要
Rust是一种为系统软件开发而设计的年轻编程语言。它的主要设计目标是实现与其竞争语言C一样好的运行时性能,同时使用线性类型系统和严格的编译时检查提供更好的内存和线程安全性。Rust在安全关键软件(如操作系统、浏览器和区块链系统)的开发人员中越来越受欢迎。然而,实践者和研究人员对真实Rust程序中内存bug的状态知之甚少。例如,Rust编译时检查是否消除了所有内存错误?如果不是,Rust中的内存错误是否表现出某些可检测的模式?本项目通过设计识别和消除内存漏洞的技术来寻求这些问题的答案。特别是,它旨在更好地理解Rust程序员所犯的常见错误,并构建新的技术来捕获Rust编译时检查遗漏的内存错误。其结果将影响Rust的发展,指导开发者如何安全地编程Rust,并提高Rust生态系统的安全性。Rust安全机制是健全的,但有时过于严格,阻碍了对底层资源的灵活控制。为了缓解这个问题,Rust允许开发人员使用不安全的代码绕过编译器的检查。可以将函数声明为不安全的。安全函数中的一段代码可能是不安全的,称为内部不安全,其中不安全代码在内部封装并在外部被视为安全的。不幸的是,不安全代码和内部不安全代码会导致内存错误,因为它们绕过Rust安全检查。这个项目旨在更好地理解Rust内存错误,并构建新的静态/动态工具来对抗Rust内存错误。该项目包含三个组成部分:(1)Rust内存错误的全面分类,(2)识别内部不安全函数中内存错误的新颖静态技术,以及(3)Rust中安全/不安全信息增强的新型模糊测试技术。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Rust is a young programming language designed for systems software development. Its main design goal is to achieve runtime performance as good as its competitor language, C, while offering better memory and thread safety using a linear type system and strict compile-time checking. Rust has become increasingly popular among developers of safety-critical software, such as operating systems, browsers, and block-chain systems. However, both practitioners and researchers know little about the status of memory bugs in real-world Rust programs. For example, do Rust compile-time checks eliminate all memory bugs? If not, do memory bugs in Rust exhibit certain detectable patterns? This project seeks answers to these questions by devising techniques to identify and eliminate the memory bugs? In particular, it aims to achieve a better understanding of common mistakes made by Rust programmers and build novel techniques to catch memory bugs missed by Rust compile-time checks. The outcome will influence how Rust evolves, guide how developers program Rust safely, and improve the safety of the Rust ecosystem. Rust safety mechanisms are sound, but sometimes they are too strict and prevent flexible control over low-level resources. To mitigate this problem, Rust allows developers to bypass its compiler checks using unsafe code. A function can be declared as unsafe. A piece of code inside a safe function can be unsafe, known as interior unsafe, where the unsafe code is encapsulated internally and treated as safe externally. Unfortunately, unsafe code and interior unsafe code can lead to memory bugs since they bypass Rust safety checks. This project aims to better understand Rust memory bugs and build novel static/dynamic tools to combat Rust memory bugs. This project contains three components: (1) a comprehensive taxonomy of Rust memory bugs, (2) novel static techniques to identify memory bugs in interior unsafe functions, and (3) novel fuzzing techniques enhanced by the safe/unsafe information in Rust.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1007/s10994-021-05951-6
发表时间:
2021-04
期刊:
Machine Learning
影响因子:
7.5
作者:
[Jiyu Chen;Yiwen Guo;Qianjun Zheng;Hao Chen]
通讯作者:
Jiyu Chen;Yiwen Guo;Qianjun Zheng;Hao Chen
DOI:
10.1109/qrs57517.2022.00069
发表时间:
2022-12
期刊:
2022 IEEE 22nd International Conference on Software Quality, Reliability and Security (QRS)
影响因子:
--
作者:
[Yuyang Rong;Chibin Zhang;Jianzhong Liu;Hao Chen]
通讯作者:
Yuyang Rong;Chibin Zhang;Jianzhong Liu;Hao Chen
DOI:
10.1007/978-3-030-63086-7_20
发表时间:
2020
期刊:
影响因子:
--
作者:
[Yuyang Rong;Peng Chen;Hao Chen]
通讯作者:
Yuyang Rong;Peng Chen;Hao Chen
DOI:
--
发表时间:
2020-12
期刊:
ArXiv
影响因子:
--
作者:
[Yiwen Guo;Qizhang Li;Hao Chen]
通讯作者:
Yiwen Guo;Qizhang Li;Hao Chen
DOI:
10.1145/3576915.3616610
发表时间:
2023-09
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Peng Chen;Yuxuan Xie;Yunlong Lyu;Yuxiao Wang;Hao Chen]
通讯作者:
Peng Chen;Yuxuan Xie;Yunlong Lyu;Yuxiao Wang;Hao Chen
共 8 条
ERI: Representations of Complex Engineering Systems via Technology Recursion and Renormalization Group
-
批准号:2301627
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2023
-
负责人:Hao Chen
-
依托单位:
Making Use of the Curse of Dimensionality in Modern Data Analysis
-
批准号:2311399
-
项目类别:Standard Grant
-
资助金额:$27.5万
-
财政年份:2023
-
负责人:Hao Chen
-
依托单位:
Development of Absolute Quantitative Protein Footprinting Mass Spectrometry (aqPFMS) for Probing Protein 3D Structures
-
批准号:2203284
-
项目类别:Standard Grant
-
资助金额:$39.0万
-
财政年份:2022
-
负责人:Hao Chen
-
依托单位:
CAREER: New Change-Point Problems in Analyzing High-Dimensional and Non-Euclidean Data
-
批准号:1848579
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2019
-
负责人:Hao Chen
-
依托单位:
SaTC: CORE: Medium: Collaborative: Towards Robust Machine Learning Systems
-
批准号:1801751
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2018
-
负责人:Hao Chen
-
依托单位:
Development of Electrochemical Mass Spectrometry for the Study of Protein Redox Chemistry and Protein Structures
-
批准号:1915878
-
项目类别:Continuing Grant
-
资助金额:$31.35万
-
财政年份:2018
-
负责人:Hao Chen
-
依托单位:
Development of Electrochemical Mass Spectrometry for the Study of Protein Redox Chemistry and Protein Structures
-
批准号:1709075
-
项目类别:Continuing Grant
-
资助金额:$36.3万
-
财政年份:2017
-
负责人:Hao Chen
-
依托单位:
Change-Point Analysis for Multivariate and Object Data
-
批准号:1513653
-
项目类别:Standard Grant
-
资助金额:$34.18万
-
财政年份:2015
-
负责人:Hao Chen
-
依托单位:
CAREER: Development of Microsecond Time-Resolved Mass Spectrometry for the Study of Biochemical Reaction Mechanisms and Kinetics
-
批准号:1149367
-
项目类别:Continuing Grant
-
资助金额:$57.48万
-
财政年份:2012
-
负责人:Hao Chen
-
依托单位:
TC: Small: Designing New Authentication Mechanisms using Hardware Capabilities in Advanced Mobile Devices
-
批准号:1018964
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2010
-
负责人:Hao Chen
-
依托单位:
The Study of Ion/Ion Reactions at Atmospheric Pressure by Ambient Neutral Re-ionization Mass Spectrometry and Ambient Soft Landing
-
批准号:0911160
-
项目类别:Standard Grant
-
资助金额:$31.43万
-
财政年份:2009
-
负责人:Hao Chen
-
依托单位:
CAREER: Securing Broadband Cellular Data Networks
-
批准号:0644450
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2007
-
负责人:Hao Chen
-
依托单位:
CT-ISG: Reasoning about Composable Intrusion Detection Systems
-
批准号:0524826
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Hao Chen
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: