CAREER: Automatically Taming System Complexity with the Least-Authority Virtual Architecture
CAREER: Automatically Taming System Complexity with the Least-Authority Virtual Architecture
批准号:
2146537
负责人:
Nathan Dautenhahn
金额:
$63.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2027-06-30
中文摘要
今天的计算机系统就像现代的泰坦尼克号。它们很大,很容易穿透,结构上没有足够的隔离。攻击者利用薄弱的外壳并立即获得对整个系统的访问权限。例如,SolarWinds或Stuxnet等恶意软件已经深入渗透到政府和企业系统中,泄漏、控制或破坏敏感信息,如核控制系统、财务或国家机密。像这样的漏洞每年给公共和私营部门造成数十亿美元的损失。LAVA通过自动将系统划分为限制访问的分区来解决这个问题,并引入机制来确保分解的软件元素不会相互破坏,同时有效地允许合法的交互和发现攻击者的行为。所有原型都将作为开放源代码工件发布,可供非专业最终用户使用。新的发现将被纳入莱斯大学的安全课程。一个基于Arduino的迷你系列讲座和实验室将通过赖斯REMSL项目和家庭学校社区发布,以吸引小学年龄的儿童。为复杂系统的用户确定所需的访问权限和功能是具有挑战性的。例如,Linux内核有超过200个模块,需要超过40000个唯一的访问控制决策。LAVA(最少权限虚拟体系结构)提出了端到端编译器和运行时框架的激进观点,用于分析、优化、转换和执行分隔的系统。有三个主要的挑战和目标。首先,如何在没有完整系统专业知识的情况下扩展到大量对象和用户?LAVA通过一个新的统一的表示和分析框架解决了这个问题,该框架从源代码映射到目标运行时和执行机制。其次,如何在不降低性能的情况下,用细粒度的分区增强安全性?LAVA新颖的运行时架构通过结合新机制和可移植的转换层来优化策略,提供高效而安全的系统隔离。第三,如何监控那些容易隐藏在黑盒应用程序中的攻击者?LAVA通过溯源跟踪扩展了强制监控,能够部署安全策略以及跟踪和调查攻击者行为。总体结果是一个高效和强大的进程内监控设施,可以检测到真实系统中复杂的隐藏威胁。程序可以从监视少数对象发展到监视大多数对象。该项目将提供分析框架、编译器扩展和具有适当抽象和保护机制的安全监视器,以实现细粒度和快速的保护。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Today's computing systems resemble a modern day Titanic. They are huge, easy to penetrate, and structured without sufficient isolation. Attackers exploit weak outer shells and instantly gain access to the whole system. For example, malware such as SolarWinds or Stuxnet has penetrated deeply into government and corporate systems to leak, control, or corrupt sensitive information such as nuclear control systems, finances, or state secrets. Breaches like this cost billions of dollars per year across the public and private sectors. LAVA addresses this problem by automatically partitioning systems into limited-access compartments and introduces mechanisms to ensure decomposed software elements cannot corrupt each other while efficiently allowing legitimate interactions and discovering attacker behavior. All prototypes will be released as open source artifacts that can be used by non-expert end users. New findings will be incorporated in Rice University security courses. A mini-series of Arduino based lectures and labs will be released with security challenges and taught through the Rice REMSL program as well as homeschool communities to engage elementary aged children.Determining required access and capabilities for users of complex systems is challenging. For example, the Linux kernel has over 200 modules and would require over 40000 unique access control decisions. LAVA (Least-Authority Virtual Architecture) suggests the radical view of an end-to-end compiler and runtime framework for analyzing, optimizing, transforming, and enforcing compartmentalized systems. There are three primary challenges and objectives. First, how to scale to large numbers of objects and users without complete system expertise? LAVA addresses this with a new unified representation and analysis framework that is mapped from source code to target runtime and enforcement mechanisms. Second, how to enhance security with fine-grained compartments without degrading performance? LAVA's novel runtime architecture provides efficient yet secure system isolation using a combination of new mechanisms and portable translation layers to optimize policies. Third, how to monitor attackers that easily cloak themselves inside of black box applications? LAVA extends the enforcement monitor with provenance tracing that is capable of deploying security policies as well as tracking and investigating attacker behavior. The overall outcome is an efficient and powerful in-process monitoring facility that can detect sophisticated cloaked threats in real systems. Programs can go from monitoring a few objects to monitoring the majority. The project will contribute analysis frameworks, compiler extensions, and a security monitor with appropriate abstractions and protection mechanisms to make protection fine-grained and fast.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CNS Core: Small: eXecution Graph Path Security (XGPS)
-
批准号:2008867
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2020
-
负责人:Nathan Dautenhahn
-
依托单位:
海外基金