SaTC: CORE: Medium: Microverification of Information-Flow Security for the Linux Operating System Kernel
SaTC: CORE: Medium: Microverification of Information-Flow Security for the Linux Operating System Kernel
批准号:
2052947
负责人:
Ronghui Gu
金额:
$116.7万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-03-15 至 2025-02-28
中文摘要
商用操作系统(OS)内核构成了当今计算基础设施的主干。尽管它们很重要,但这些商用操作系统内核是复杂的、高度并发的,所有需要做的就是代码中的一个薄弱环节--让系统容易受到黑客的攻击。其中许多漏洞几乎不可能通过传统测试检测出来。即使一个商用的操作系统内核可以写出99%的正确率,黑客仍然可以潜入到那个特定的1%的设置中,在那里系统将不会像预期的那样运行。这个项目正在设计、实现和评估微验证,这是一种新的方法,可以验证一个大型的、商用的、多处理器的操作系统内核在任何情况下都是安全的,而不需要证明系统的每个部分的正确性。这种方法正在与Linux内核一起使用,该内核在当今的许多计算基础设施中使用。该项目为未来在构建可信系统软件和使未来的计算基础设施更加安全方面的创新奠定了基础。微观验证将现有的商用操作系统内核改造成一个小的可信内核和更大的一组不可信服务,从而可以仅通过对内核的推理来验证整个操作系统内核的信息流安全。该项目正在开发安全保护层,通过将核心分解为可组合的、分层的规范层次结构,使验证变得容易处理。然后,可以递增地验证核心实现以细化其高级分层规范,使得安全保证可以在核心的顶层规范上得到证明,跨层保留,并适用于改进后的OS内核的整个实现。正在对Linux内核进行改造和验证,其验证之前被认为是棘手的,表明微验证技术能够验证现有的大规模商用OS内核。这一奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Commodity operating system (OS) kernels form the backbone of today's computing infrastructure. Despite their importance, these commodity OS kernels are complicated, highly concurrent, and all it takes is a single weak link in the code—one to leave a system vulnerable to hackers. Many of these vulnerabilities are virtually impossible to detect via traditional testing. Even if a commodity OS kernel can be written 99% correctly, a hacker can still sneak into that particular 1% set-up where the system will not behave as expected. This project is designing, implementing, and evaluating microverification, a new approach to verify that a large, commodity, multiprocessor OS kernel is secure under all circumstances without the need to prove the correctness of every part of the system. This approach is being used with the Linux kernel, used in much of today’s computing infrastructure. The project provides a foundation for future innovations in building trustworthy system software and making tomorrow’s computing infrastructure more secure.Microverification retrofits an existing commodity OS kernel into a small, trusted core and a larger set of untrusted services, such that it is possible to verify the information-flow security of the entire OS kernel by reasoning about the core alone. This project is developing security-preserving layers to make verification tractable by decomposing the core into a hierarchy of composable, layered specifications. The core implementation can then be incrementally verified to refine its high-level layered specification, such that security guarantees can be proven over the core's top layer specification, preserved across layers, and hold for the entire implementation of the retrofitted OS kernel. Retrofitting and verification are being done on the Linux Kernel, whose verification was previously considered intractable, demonstrating that microverification techniques are capable of verifying existing large-scale commodity OS kernels.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[Xupeng Li;Xuheng Li;Christoffer Dall;Ronghui Gu;Jason Nieh;Yousuf Sait;Gareth Stockwell]
通讯作者:
Xupeng Li;Xuheng Li;Christoffer Dall;Ronghui Gu;Jason Nieh;Yousuf Sait;Gareth Stockwell
DOI:
10.1145/3453483.3454029
发表时间:
2021-04
期刊:
Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation
影响因子:
--
作者:
[Runzhou Tao;Yunong Shi;Jianan Yao;J. Hui;F. Chong;Ronghui Gu]
通讯作者:
Runzhou Tao;Yunong Shi;Jianan Yao;J. Hui;F. Chong;Ronghui Gu
UPGRADVISOR: Early Adopting Dependency Updates Using Hybrid Program Analysis and Hardware Tracing
UPGRADVISOR:使用混合程序分析和硬件跟踪尽早采用依赖项更新
DOI:
--
发表时间:
2022
期刊:
Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2022
影响因子:
--
作者:
[David, Yaniv, Sun, Xudong, Sofaer, Raphael J., Senthilnathan, Aditya, Yang, Junfeng, Zuo, Zhiqiang, Xu, Guoqing Harry, Nieh, Jason, Gu, Ronghui]
通讯作者:
Gu, Ronghui
DOI:
--
发表时间:
2023
期刊:
ArXiv
影响因子:
--
作者:
[Xupeng Li;Xuheng Li;Wei Qiang;Ronghui Gu;Jason Nieh]
通讯作者:
Xupeng Li;Xuheng Li;Wei Qiang;Ronghui Gu;Jason Nieh
DuoAI: Fast, Automated Inference of Inductive Invariants for Verifying Distributed Protocols
DuoAI:用于验证分布式协议的归纳不变量的快速自动推理
DOI:
--
发表时间:
2022
期刊:
Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2022
影响因子:
--
作者:
[Yao, Jianan, Tao, Runzhou, Gu, Ronghui, Nieh, Jason]
通讯作者:
Nieh, Jason
共 10 条
CAREER: Automated Verification of Loops in Systems Code
-
批准号:2239484
-
项目类别:Continuing Grant
-
资助金额:$52.5万
-
财政年份:2023
-
负责人:Ronghui Gu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: