课题基金 / 基金详情

SaTC: CORE: Small: Automatic Identification of Privilege-guard Variables for Data-only Attacks and Defenses

SaTC: CORE: Small: Automatic Identification of Privilege-guard Variables for Data-only Attacks and Defenses
SaTC:核心:小型:自动识别纯数据攻击和防御的权限保护变量
批准号:
2247652
负责人:
Hong Hu
金额:
$59.01万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-08-01 至 2026-07-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
由于网络攻击者总是在探索新的、低成本的黑客载体来绕过当前的防御系统,安全研究人员应该全面检查剩余的威胁,以便提前开发有效的防御系统。在程序内存内,攻击者正在将注意力从控制劫持转移到更隐蔽、更纯粹的数据操纵上:他们的目标是修改安全关键变量,以绕过身份验证和授权等安全检查。研究人员在开发有效的防御措施以防止所谓的纯数据攻击之前,必须了解哪些变量决定了应用程序的安全性。该项目提出了三个突破口,以全面了解自动构建仅数据攻击的实用性。首先,推力1包括一套旨在从通用程序中自动识别安全关键、非控制数据的新技术。推力1将专注于阻止不受信任的用户访问高权限资源的条件分支。这一结果将帮助防御者了解是否可以自动识别安全关键变量。其次,推力2将开发解决方案,以衡量构建仅针对数据的具体攻击的挑战。目标是估计建筑攻击的上限成本。这一努力的结果将有助于理解这一新威胁的实用性。第三,推力3将建立纯数据攻击基准,为测试未来纯数据攻击和防御提供统一平台。该项目将产生一套用于识别安全关键变量和评估变量关键程度的工具,并为开发针对纯数据攻击的新防御措施提供平台。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
As cyber attackers are always exploring novel, low-cost hacking vectors to bypass current defenses, security researchers should examine the remaining threats comprehensively in order to develop effective defenses in advance. Within program memory, attackers are shifting their attentions from control hijacking to more stealthy, pure data manipulation: they aim to modify security-critical variables to bypass security checks, like authentication and authorization. Researchers must understand which variables determine application security before developing efficient defenses to prevent so-called data-only attacks. This project proposes three thrusts to comprehensively understand the practicality of automatically constructing data-only attacks. First, Thrust 1 includes a set of novel techniques aiming to automatically identify security-critical, non-control data from general-purpose programs. Thrust 1 will focus on conditional branches that prevent untrusted users from accessing high-privilege resources. The result will help defenders understand whether security-critical variables can be identified automatically. Second, Thrust 2 will develop solutions to measure the challenges of constructing concrete data-only attacks. The goal is to estimate the upper-bound cost of building attacks. The results of this thrust will help understand the practicality of this new threat. Third, Thrust 3 will build a benchmark of data-only attacks to offer a unified platform for testing future data-only attacks and defenses. This project will produce a set of tools for identifying security-critical variables and assessing variable criticalness, and provide a platform for developing new defenses against data-only attacks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者: [Hengkai Ye;Song Liu;Zhechang Zhang;Hong Hu]
通讯作者: Hengkai Ye;Song Liu;Zhechang Zhang;Hong Hu
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: