课题基金 / 基金详情

CAREER: Re-configurable, Source-Language-Agnostic Decompilation for Binary Programs

CAREER: Re-configurable, Source-Language-Agnostic Decompilation for Binary Programs
职业:可重新配置、与源语言无关的二进制程序反编译
批准号:
2146568
负责人:
Ruoyu Wang
金额:
$54.28万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2027-06-30

项目摘要

项目成果

Ruoyu Wang的其他基金

相似基金

相关文献

中文摘要
翻译
软件安全在现代是至关重要的。不管人们是否意识到,从个人电脑到智能手机,从关键基础设施到网络物理系统,软件正在为数百亿设备和系统提供动力。这些系统通常受到网络犯罪分子开发和部署的一种对抗性软件——恶意软件的攻击。不幸的是,无法获得软件的源代码从两个方面严重阻碍了使软件和系统更安全的努力:(a)无法获得通用软件的源代码使软件审计员更难发现和减轻软件缺陷和后门;(b)无法访问恶意软件的源代码使安全分析师更难以及时了解和击败网络威胁。尽管经过多年的研究,该领域的现代工具和技术还不足以从软件工件中恢复可读的源代码。因此,开发新的技术和工具来有效地从软件中恢复源代码,将大大提高现代软件的安全性,从而有利于整个社会的安全。反编译是指从已经编译成机器码的软件中恢复源代码的过程。该研究项目包括三个主要的研究重点,其最终目标是开发一套新技术,以支持特定于目的和源语言无关的二进制反编译器。首先,认识到安全分析中的不同任务可能有不同的最终目标(例如,单个函数的可读性与程序级数据流的可理解性),本项目将系统地研究反编译的常见安全特定目的。对于每个目的,本项目将开发特定的反编译和优化技术。其次,本研究项目将产生新的理论和方法,将单片二进制反编译实践转化为模块化、可插拔和可配置的技术和步骤。最后,这个项目的关键将是研究编译器特定模型的自动生成和技术,用于将用高级语言(例如Visual Basic 6、c++、Go和Rust)编译的二进制文件转换为高质量的伪源代码输出,这些伪源代码输出显示了原始高级编程语言的特性。除了研究出版物之外,该项目还将产生一个完全开源的、与源语言无关的二进制反编译框架,这将促进安全行业、研究、教育和爱好者之间的活动。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Software security is crucial in modern times. With or without people’s awareness, from personal computers to smart phones, from critical infrastructure to cyber-physical systems, software is powering tens of billions of devices and systems. These systems are commonly attacked by an adversarial type of software, malware, which is developed and deployed by cyber criminals. Unfortunately, the inaccessibility of source code of software severely hampers the effort of making software and systems more secure from two aspects: (a) Not having access to source code of common software makes it harder for software auditors to discover and mitigate software defects and backdoors; (b) Not having access to source code of malware makes it harder for security analysts to understand and defeat cyber threats in a timely manner. Despite years of research, modern tools and techniques in the field are insufficient in recovering readable source code from software artifacts. Therefore, developing new technologies and tools to effectively recover source code from software will greatly improve the security of modern software, which will in turn benefit the security of the entire society. Decompilation refers to the process of recovering source code from software that is already compiled into machine code. This research project consists of three major research thrusts with the final goal of developing a set of new techniques to support a purpose-specific and source-language-agnostic binary decompiler. First, recognizing different tasks in security analysis may have different end goals (e.g., the readability of a single function versus the understandability of program-level data flows), this project will systematically study common security-specific purposes for decompilation. For each purpose, this project will develop specific decompilation and optimization techniques. Second, this research project will generate new theories and methods to transform monolithic binary decompilation practices into modular, pluggable, and configurable techniques and steps. Finally, the crux of this project will be studying the automated generation of compiler-specific models and techniques for transforming binaries compiled in high-level languages (e.g., Visual Basic 6, C++, Go, and Rust) into high-quality pseudo-source code output that exhibits features in the original high-level programming languages. Besides research publications, this project will produce a fully open-sourced, source-language-agnostic binary decompilation framework, which will facilitate activities in security industry, research, education, and among enthusiasts.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者: [Hui Jun Tay;Kyle Zeng;J. Vadayath;A. S. Raj;A. Dutcher;T. Reddy;Wil Gibbs;Zion Leonahenahe Basque;Fangzhou Dong;Zack Smith;Adam Doupé;Tiffany Bao;Yan Shoshitaishvili;Ruoyu Wang]
通讯作者: Hui Jun Tay;Kyle Zeng;J. Vadayath;A. S. Raj;A. Dutcher;T. Reddy;Wil Gibbs;Zion Leonahenahe Basque;Fangzhou Dong;Zack Smith;Adam Doupé;Tiffany Bao;Yan Shoshitaishvili;Ruoyu Wang
CICI: TCR: Improving the Robustness of Cyberinfrastructure via Scalable Vulnerability Discovery and Mitigation on "Big Binaries"
  • 批准号:
    2232915
  • 项目类别:
    Standard Grant
  • 资助金额:
    $120.0万
  • 财政年份:
    2023
  • 负责人:
    Ruoyu Wang
  • 依托单位:
国内基金
海外基金
从调控RE-MEC神经环路探讨三七“从瘀论治”老年失眠认知损伤的机制
  • 批准号:
    JCZRLH202600245
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
  • 依托单位:
Re与难熔金属的交互效应对镍基单晶高温合金高温蠕变抗力的影响
  • 批准号:
    2026JJ90041
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
    易洲
  • 依托单位:
钛颗粒增强Mg-RE-Zn基复合材料耐蚀行为及MAO涂层改性机理研究
  • 批准号:
    2026JJ60481
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2026
  • 负责人:
    蒲冬梅
  • 依托单位:
RE-BOA联合VA-ECMO对难治性心跳骤停患者脑复苏效果的评估