课题基金 / 基金详情

I-Corps: Utilization of Moving Target Defenses in Software Applications

I-Corps: Utilization of Moving Target Defenses in Software Applications
I-Corps:在软件应用程序中利用移动目标防御
批准号:
2011066
负责人:
Deanna Meador
金额:
$5.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-06-01 至 2022-09-30

项目摘要

项目成果

Deanna Meador的其他基金

相似基金

相关文献

中文摘要
翻译
这个i-Corps项目的更广泛影响集中在探索主动深度防御技术的翻译上,重点是利用移动目标防御技术。全球网络安全市场目前价值1240亿美元,预计未来5年的复合年增长率为8.7%。由于大多数解决方案侧重于监控和应对攻击,因此有机会探索一种主动的方法。每个系统的相同软件实现表明,识别一个程序中的关键漏洞的攻击者可以在运行该程序的每个设备上利用这一知识。这是计算机病毒执行的根本基础,也是Stuxnet和Pegasus等网络间谍软件如何能够渗透到敏感系统并在其中转移的主要原因。在安全关键型应用中越来越多地使用物联网设备,不仅会泄露患者记录和信用卡信息等敏感数据,还会带来更大规模的远程、廉价的网络恐怖活动。这个i-Corps项目推动了新网络安全系统的开发。利用安全关键型软件的主要途径通常是基于堆栈的利用,最显著的是缓冲区溢出,这是超过60%的物联网设备攻击的直接原因。任何基于堆栈的网络攻击要想成功,关键一步是侦察。提出使用移动目标防御来多样化应用程序的内部结构,确保每个程序都有唯一的身份。具体地说,该项目建议通过利用堆栈分段、地址空间随机化、数据加密、函数洗牌、伪代码插入、堆栈金丝雀和变量混淆来缓解基于堆栈的漏洞。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The broader impact of this I-Corps project is focused on exploring translation of proactive defense-in-depth technologies focused on leveraging moving target defense techniques. The global cybersecurity market is currently valued at $124 Billion with an estimated 8.7% CAGR over the next 5 years. Since most solutions focus on monitoring and reacting to attacks, an opportunity exists to explore a proactive approach. Identical software implementations for every system suggest that an attacker identifying critical vulnerabilities in one program can exploit this knowledge for every device running that program. This is the fundamental basis behind the execution of computer viruses, and the primary reason how cyber-espionage software, such as STUXNET and Pegasus, have been able to infiltrate and pivot within sensitive systems. The increased use of IoT devices in safety-critical applications creates risks beyond exfiltrating sensitive data, such as patient records and credit card information, to larger scale cyber-terrorist activities conducted remotely and inexpensively. This I-Corps project advances the development of new cybersecurity systems. The key avenue for exploiting safety-critical software is often stack-based exploits, most notably buffer overflows, which are directly responsible for over 60% of IoT device attacks. The key step for any stack-based cyber-attack to be successful is reconnaissance. The use of moving target defense to diversify the internal structure of applications is proposed, ensuring that every program will have a unique identity. Specifically, this project proposes mitigating stack-based vulnerabilities by utilizing stack segmentation, address space randomization, data encryption, function shuffling, dummy code insertion, stack canaries, and variable obfuscation.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
I-Corps: Artificial intelligence-based image processing to automate fashion e-commerce
  • 批准号:
    2040558
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2020
  • 负责人:
    Deanna Meador
  • 依托单位:
海外基金