课题基金 / 基金详情

SaTC: CORE: Small: Regulating and Leveraging Types for Security

SaTC: CORE: Small: Regulating and Leveraging Types for Security
SaTC:核心:小型:监管和利用安全类型
批准号:
2247434
负责人:
Kangjie Lu
金额:
$59.93万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-08-01 至 2026-07-31

项目摘要

项目成果

Kangjie Lu的其他基金

相似基金

相关文献

中文摘要
翻译
数据元素是在软件编程过程中用类型定义的。类型不仅指定数据元素的语义和特征,而且还约束针对数据元素的程序操作和行为。这种类型信息对于程序分析是有价值的,并且类型分析不需要复杂的数据流分析。然而,在广泛使用的系统编程语言(C/ c++)中,类型系统存在两个基本问题。首先,一般类型很普遍;它们模糊了特定的数据类型,导致基于类型的分析结果不精确。其次,类型错误和类型转换很常见;直接使用错误类型作为防御机制将导致运行时错误,这被认为是不可接受的。本项目旨在解决各种安全应用程序的问题和使用类型。研究结果将融入教育中,提高学生对打字错误的认识,帮助他们捕捉打字错误,强化他们的代码。该项目旨在解决C/ c++等类型不安全编程语言中类型的基本问题,然后将改进后的类型用于各种安全应用程序。该项目有三个研究重点。首先,该项目将规范类型——指定流行的通用类型并静态检测类型混淆错误。它将采用选择性的、基于路径的和功能粒度的类型转换分析来提高可伸缩性和精度。第二个研究重点将开发新技术,利用监管类型来显着提高几种基础安全分析技术的精度。通过规范的类型和精确的分析技术,最后的研究推力将建立有效和实用的防御机制,如基于类型的数据/控制流完整性。这些技术将在LLVM通过时实现,因此它们可以很容易地用作编译器插件。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Data elements are defined with types during software programming. A type not only specifies the semantics and characteristics of data elements, but also constrains the program operations and behaviors against data elements. Such type information is valuable for program analysis, and type analysis does not require complicated data-flow analysis. However, the type system in the widely used system programming languages (C/C++) has two fundamental problems. First, general types are prevalent; they obscure the specific data types and result in imprecise type-based analysis results. Second, type errors and typecasting are common; directly using erroneous types for defense mechanisms would lead to runtime errors which are considered unacceptable. This project aims to address the problems and use types for various security applications. The research results will be integrated into education to improve students' awareness of type errors, and help them capture type errors and harden their code.This project aims to address fundamental problems with types in type-unsafe programming languages like C/C++ and then use the improved types for various security applications. The project has three research thrusts. First, the project will regulate types—specifizing the prevalent general types and statically detecting type-confusion errors. It will employ selective, path-based, and function-grained typecasting analysis to improve scalability and precision. The second research thrust will then develop new techniques that leverageregulated types to significantly improve the precision of several foundational analysis techniques for security. With the regulated types and precise analysis techniques, the last research thrust will build effective and practical defense mechanisms such as type-based data-/control-flow integrity. The techniques will be implemented as LLVM passes, so that they can be easily used as compiler plugins.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Travel: NSF Student Travel Grant for The 2nd International Workshop on Ethics in Computer Security (EthiCS 2023)
  • 批准号:
    2312705
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.84万
  • 财政年份:
    2023
  • 负责人:
    Kangjie Lu
  • 依托单位:
Collaborative Research: SaTC: CORE: Small: Improving Decentralized Kernel Patch Ecosystems
  • 批准号:
    2154989
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2022
  • 负责人:
    Kangjie Lu
  • 依托单位:
CAREER: Whole-Kernel Analysis Against Developer- and Compiler-Introduced Errors
  • 批准号:
    2045478
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $49.3万
  • 财政年份:
    2021
  • 负责人:
    Kangjie Lu
  • 依托单位:
SaTC: CORE: Small: Checking Security Checks in OS Kernels
  • 批准号:
    1931208
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2019
  • 负责人:
    Kangjie Lu
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: