课题基金 / 基金详情

CAREER: Countering Emerging Software Threats with Adaptive Hardening, Debloating, and Hardware-assisted Protection

CAREER: Countering Emerging Software Threats with Adaptive Hardening, Debloating, and Hardware-assisted Protection
职业:通过自适应强化、反膨胀和硬件辅助保护来应对新兴软件威胁
批准号:
2238467
负责人:
Vasileios Kemerlis
金额:
$66.01万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-06-01 至 2028-05-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
今天的大型而复杂的软件系统充满了漏洞,这些漏洞允许犯罪者利用它来牟利。在所有不同类型的可被利用的软件弱点中,内存错误--即攻击者可以通过狡猾的输入(Ab)利用来破坏或泄漏内存内容的错误--处理起来尤其有害。开发人员和安全工程师无法跟上需要修补的安全错误(例如内存错误)的绝对数量。本项目的重点是使软件防御适应特定的部署环境,因为该环境会因新功能和新威胁而发生变化。该项目将产生开放源码的工具原型,以实现防御的自动化调整,从而提高防御的有效性,同时在新威胁出现时从根本上减少防御所需的人力。其目标是通过自动定制防御以适应部署环境,从而实现更有效、更复杂的防御。由此产生的技术和工具将有助于下一代安全体系结构,使软件防御能够不断变化,以提供强大的软件保护机制。该项目包括自适应安全保护伞下的三个协同推力:自适应加固、硬件辅助自适应保护和自适应消胀。该项目将研究使软件系统能够在几个维度上动态调整其防御和功能的技术。二进制重写和程序强化的技术将得到增强,以支持适应性。自适应强化将为二进制文件配备丰富的元数据,包括调用图和类型。静态二进制重写执行安装时、加载时和运行时自适应。硬件辅助自适应强化使用诸如Intel的CET等硬件功能进行自适应强化;最后,通过自动去膨胀来删除未使用的代码。软件安全的自适应方法有几个好处。首先,在软件强化中灵活的能力创造了一个多样化和不可预测的环境,这阻碍了对手使用罐装食谱绕过利用缓解的能力。其次,加固纠正允许软件充分利用特定设置提供的加固功能,同时动态调整部署的防御措施以满足不断变化的需求。这项研究的结果将改进针对新出现的软件威胁的最先进的防御,并缓解更广泛的安全社区对障碍(例如,性能、兼容性)的担忧,这些障碍到目前为止阻碍了具有有保证的安全特性的保护的部署。该项目将通过网络安全和计算机科学课程,以及为高中生和科学教育工作者举办的更广泛的思想研讨会和研讨会来开发和分享新知识。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Today's large and complex software systems are plagued with vulnerabilities that allow perpetrators to exploit it for profit. Of all the different kinds of exploitable software weaknesses, memory errors -- i.e., bugs that can be (ab)used by attackers, via crafty inputs, to corrupt or leak memory contents -- have been particularly pernicious to deal with. Developers and security engineers are unable to keep up with the sheer number of security errors (e.g., memory errors) being exploited that need patching. The focus of this project is on adapting software defenses to the specific deployment environment, as that environment changes due to new functionality and new threats. The project will produce open source prototypes of tools to automate the adaptation of defenses, thereby increasing the effectiveness of the defenses while radically reducing the human effort involved in defending against new threats as they arise. The objective is to enable more effective, sophisticated defenses by automating the customization of defenses to fit the deployment environments. The resulting techniques and tools will contribute to the next-generation security architecture that enables software defenses to be constantly in flux to provide robust software protection mechanisms. The project consists of three synergistic thrusts under the umbrella of adaptive security: adaptive hardening, hardware-assisted adaptive protection and adaptive debloating. The project will investigate techniques to enable software systems to dynamically adapt their defenses and functionality along several dimensions. Techniques for binary rewriting and program hardening will be enhanced to support adaptability. Adaptive hardening will equip binaries with rich metadata including call graphs and types. Static binary rewriting performs install-time, load-time, and runtime adaptations. Hardware-assisted adaptive hardening uses hardware features such as Intel's CET for adaptive hardening; Finally, unused code is removed by automating debloating. There are several benefits of an adaptive approach to software security. First, the capability to be agile in software hardening creates a diversified and unpredictable environment, which hinders the ability of adversaries to use canned recipes to bypass exploit mitigations. Second, hardening rectification allows software to make the best use of the hardening capabilities that a particular setting offers, while dynamically adapting the deployed defenses to meet changing needs. The outcomes of this research will improve the state-of-the-art in defense against emerging software threats, and alleviate the concerns of the broader security community regarding hurdles (e.g., performance, compatibility) that until now have prevented the deployment of protections with guaranteed security properties. The project will develop and share new knowledge through cybersecurity and computer science curricula, and more broadly thought workshops and seminars for high school students and science educators.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金