课题基金 / 基金详情

CAREER: Improving the Lifecycle Security of Microcontroller Devices

CAREER: Improving the Lifecycle Security of Microcontroller Devices
职业:提高微控制器设备的生命周期安全性
批准号:
2238264
负责人:
Le Guan
金额:
$53.26万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-03-15 至 2028-02-29

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
微控制器单元(MCU)驱动许多安全和安全关键的嵌入式应用。然而,它们继承了所有计算系统中存在的软件错误。固件漏洞因此成为现实世界攻击的主要目标之一。成功的利用可能会对关键基础设施造成灾难性后果(例如停电和工厂损坏),并危及人类生命(例如禁用起搏器)。在软件社区中,已经有了丰富的关于错误发现和攻击缓解的知识。然而,将这些结果应用于MCU固件是出了名的困难。事实上,MCU固件运行在具有不同架构的资源受限的硬件上,集成了定制的运行时环境,并与物理世界进行了不可预测的交互。这使得现有的动态分析技术不兼容、昂贵且效率低下。拟议的研究将跨越上述挑战带来的技术障碍,并通过新的知识、框架、分析工具和支持技术极大地丰富MCU固件安全的武器库。由于MCU设备在现实生活中扮演的关键角色,该项目将在保障网络空间安全和加强国家安全方面取得巨大进展。这个项目的一个关键观察是,MCU设备通常不能自己操作。相反,在它们的整个生命周期中,它们不得不依赖于某些外部计算机。因此,围绕一个统一的主题,将安全分析从原来的应用程序工作负载转移到附近更有能力的工作站或集线器,该项目将提供一系列新的方法和理论,以显著提高MCU设备的生命周期安全性。通过解耦设计,将调查三个研究推力。第一个重点是自动发现固件漏洞的新技术,例如隐藏在程序空间深处的错误。第二个目标是对生产环境中的固件执行进行运行时监控,使利益相关者能够检测正在进行的攻击并捕获在内部测试期间从未发生的错误。第三个推力与第二个推力合作,研究漏洞修复技术,特别是如何在不泄露隐私的情况下有效诊断生产错误。这项研究的成果将免费分发给社区。这项研究还将被整合到研究人员的教育计划中,以开发一套基于虚拟机的实验室,以教育年轻人和未来的嵌入式系统开发人员和架构师有关MCU安全的知识。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Microcontroller units (MCUs) drive many security- and safety-critical embedded applications. However, they inherit software bugs present in all computing systems. Firmware vulnerabilities have thus become one of the main targets of real-world exploitation. Successful exploitation can cause disastrous consequences to critical infrastructures (e.g., power outages and plant damage) and endanger human lives (e.g., by disabling a pacemaker). In the software community, there has been a rich body of knowledge regarding bug discovery and attack mitigation. However, it is notoriously difficult to apply these results to MCU firmware. Indeed, MCU firmware runs on resource-constrained hardware with heterogeneous architectures, integrates custom runtime environments, and makes unpredictable interactions with the physical world. This renders existing dynamic analysis techniques incompatible, expensive, and ineffective. The proposed research will cross the technical barriers imposed by the aforementioned challenges and greatly enrich the arsenal of MCU firmware security with new knowledge, frameworks, analysis tools, and supporting techniques. Due to the critical roles that MCU devices take in real life, this project will make huge progress towards securing the cyberspace and enhancing national security. A key observation of this project is that MCU devices usually cannot operate by themselves. Rather, they have to rely on certain external computers in their entire life cycles. Therefore, around a unifying theme of offloading security analysis from the original application workload to more capable nearby workstations or hubs, this project will deliver a series of new methodologies and theories to significantly improve the lifetime security of MCU devices. With the decoupled design, three research thrusts will be investigated. The first thrust focuses on new techniques to automatically discover firmware vulnerabilities, such as bugs lurking deeply in the program space. The second thrust targets run-time monitoring of firmware execution in the production environment, allowing the stakeholders to detect ongoing attacks and catch bugs that never happen during in-house testing. The third thrust, cooperating with the second thrust, investigates vulnerability remediation techniques, in particular, how to efficiently diagnose production bugs without leaking privacy. The outcomes of this research will be freely distributed to the community. This research will also be integrated into the investigator’s education plan to develop a set of Virtual Machine-based labs to educate young minds and future embedded system developers and architects about MCU security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
Improving modelling of compact binary evolution.
  • 批准号:
    10903001
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2009
  • 负责人:
    史蒂芬
  • 依托单位: