课题基金 / 基金详情

SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks

SaTC: CORE: Small: Selective Data Protection against Data-oriented and Transient Execution Attacks
SaTC:核心:小型:针对面向数据和瞬态执行攻击的选择性数据保护
批准号:
2104148
负责人:
Michail Polychronakis
金额:
$49.91万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2021
资助国家:
美国
项目状态:
未结题
起止时间:
2021-07-01 至 2025-06-30

项目摘要

项目成果

Michail Polychronakis的其他基金

相似基金

相关文献

中文摘要
翻译
由于部署了许多漏洞缓解技术,利用由内存错误引起的软件漏洞变得更具挑战性。因此,攻击者不再努力获得任意的代码执行能力,而是将注意力转向了通过内存披露漏洞泄露敏感进程数据。更糟糕的是,最近大量的瞬态执行攻击加剧了数据泄漏的威胁,这些攻击可能会通过残留的微架构副作用泄露原本无法访问的进程数据。为了抵御新出现的面向数据的攻击威胁,该项目将研究实用的选择性数据保护技术,重点关注i)使开发人员能够以最少的人工工作量保护敏感数据;Ii)保护敏感数据免受内存泄露漏洞和瞬态执行攻击;iii)维护与大规模现实世界应用程序的兼容性。该项目的成果有望提高针对面向数据和瞬态执行攻击的防御水平,并通过屏蔽现有易受攻击的应用程序来实现实质性的实际影响,从而使最终用户和安全研究人员都受益。该项目还将为学生提供进行网络安全研究的机会,并将通过为学生提供实践讲习班和为科学教师提供研讨会,促进网络安全融入高中教育。为了防御内存泄露漏洞和瞬态执行攻击的新威胁,该项目将研究基于内存数据加密的选择性数据保护技术,主要围绕三个创新方面。首先,将数据保护提升为一种核心语言特性,将使开发人员能够毫不费力地在内存中启用他们认为重要的数据加密。除了C/ c++之外,该项目还将关注JavaScript和Rust,尽管它们不受内存泄露漏洞的影响,但仍然容易受到瞬态执行攻击。其次,将静态指针分析与有作用域的动态数据流跟踪相结合的混合方法将最大限度地减少在内存中加密敏感数据所需的重量级工具。该技术背后的关键见解是,可以通过依赖轻量级标签查找来确定潜在敏感数据是否真正敏感,从而改善指针分析固有的过度近似。第三,可以通过以下方式以可伸缩的方式提高指针分析的灵敏度:1)引入基于摘要的上下文敏感堆建模方法,该方法适合于在流行的应用程序中广泛使用内存包装器;2)有选择地只在程序的某些部分增加灵敏度,因为这可能有利于整体分析精度。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The exploitation of software vulnerabilities caused by memory errors has become more challenging due to the deployment of numerous exploit mitigation technologies. Consequently, instead of striving to gain arbitrary code execution capabilities, attackers have turned their attention to the leakage of sensitive process data through memory disclosure vulnerabilities. To make matters worse, the threat of data leakage has been exacerbated by the recent spate of transient execution attacks, which can leak otherwise inaccessible process data through residual microarchitectural side effects. To defend against the emerging threat of data-oriented attacks, the project will investigate practical selective data protection techniques by focusing on i) enabling developers to protect sensitive data with minimal manual effort; ii) protecting sensitive data against both memory disclosure vulnerabilities and transient execution attacks; and iii) maintaining compatibility with large-scale real-world applications. The outcomes of the project are expected to improve the state of the art in defenses against data-oriented and transient execution attacks and achieve substantial practical impact by shielding existing vulnerable applications against exploitation, benefiting both end users and security researchers. The project will also provide students the opportunity to conduct research in cybersecurity, and will foster the integration of cybersecurity into high school education through hands-on workshops for students and seminars for science teachers.To defend against the emerging threats of memory disclosure vulnerabilities and transient execution attacks, the project will investigate selective data protection techniques based on in-memory data encryption, centered around three innovative aspects. First, elevating data protection as a core language feature will enable developers to effortlessly enable in-memory encryption of data they deem critical. Besides C/C++, the project will also focus on JavaScript and Rust, which, although immune against memory disclosure vulnerabilities, are still prone to transient execution attacks. Second, a hybrid approach that combines static pointer analysis with scoped dynamic data flow tracking will minimize the heavyweight instrumentation required for keeping sensitive data encrypted in memory. The key insight behind this technique is that the inherent over-approximation of pointer analysis can be ameliorated by relying on lightweight label lookups to determine if potentially sensitive data is actually sensitive. Third, the sensitivity of pointer analysis can be increased in a scalable way by i) introducing a summarization-based context-sensitive heap modeling approach tailored to the extensive use of memory wrappers in popular applications, and ii) selectively increasing sensitivity only at certain parts of the program where it is likely to be beneficial to the overall analysis precision.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Decap: Deprivileging Programs by Reducing Their Capabilities
Decap:通过降低程序的能力来剥夺程序的特权
DOI: 10.1145/3545948.3545978
发表时间: 2022
期刊: Intrusions and Defenses (RAID
影响因子: --
作者: [Hasan, Md Mehedi, Ghavamnia, Seyedhamed, Polychronakis, Michalis]
通讯作者: Polychronakis, Michalis
CAREER: Principled and Practical Software Shielding against Advanced Exploits
  • 批准号:
    1749895
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $49.99万
  • 财政年份:
    2018
  • 负责人:
    Michail Polychronakis
  • 依托单位:
TWC: Small: Combating Environment-aware Malware
  • 批准号:
    1617902
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.8万
  • 财政年份:
    2016
  • 负责人:
    Michail Polychronakis
  • 依托单位:
CSR: Small: An Information Accountability Architecture for Distributed Enterprise Systems
  • 批准号:
    0914312
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.0万
  • 财政年份:
    2009
  • 负责人:
    Michail Polychronakis
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: