Hybrid static/dynamic inter-application data-flow analysis
Hybrid static/dynamic inter-application data-flow analysis
批准号:
264112078
负责人:
Professor Dr. Reiner Hähnle, since 2/2016
金额:
$0.0万
依托单位国家:
德国
项目类别:
Priority Programmes
财政年份:
2014
资助国家:
德国
项目状态:
已结题
起止时间:
2013-12-31 至 2016-12-31
中文摘要
信息流分析允许安全分析人员通过软件应用程序发现数据流,或者更一般地发现关于该数据的信息流。例如,这对于发现私人信息的意外或恶意泄漏非常有用,或者相反,对于检测允许攻击者修改输入数据的漏洞非常有用,例如导致受攻击的应用程序泄漏其应用程序数据或错误地处理它。sql注入攻击属于后一类。过去,研究人员主要关注单个软件组件甚至单个执行线程的数据流和信息流分析。该模型虽然允许相对有效的算法和工具,但相对有限。尤其是针对移动设备的现代操作系统,都是围绕一个小型的、高度互联的应用程序(app)模型构建的,这些应用程序通过交换命令和数据来实现用户故事。在这样的操作系统上,恶意代码可以利用这种进程间通信。例如,一些知名的恶意软件应用程序使用进程间通信从其他编程糟糕、因而易受攻击的应用程序中勒索私人数据。为了解决这个问题,InterFlow项目将开发新的算法、方法和工具,利用这些算法、方法和工具可以跨进程边界跟踪数据流,既可以使用静态代码分析,也就是说,不执行有问题的应用程序,也可以在应用程序执行期间动态地跟踪数据流。过去的研究表明,这两种技术的结合可以产生既高效又高效的系统。设想的解决方案的一个特殊特性是,它应该完全不需要对移动操作系统进行任何修改。这将允许最终用户轻松地在各种设备上部署这些机制。虽然这个实际问题的动机是这样的,但这个限制将产生有趣的研究挑战,因为解决方案将不能依赖于特殊的信任锚,如可信内核或可信平台模块,以确保安全的运行时。在InterFlow项目中开发的分析将允许软件工程师通过涉及多个应用程序的数据流问题的交互来可靠地查明漏洞,并允许他们检测利用这些漏洞的恶意软件。
英文摘要
Information-flow analyses allow security analysts to discover the flow of data through software applications, or more generally the flow of information about that data. This is useful, for instance, to discover accidental or malicious leakages of private information, or conversely to detect vulnerabilities granting attackers the possibility to modify input data such as to cause the application under attack to leak its application data or to process it incorrectly. SQL-injection attacks fall into the latter category.In the past, researchers have mostly focused on data-flow and information-flow analyses for single software components or even for only single execution threads. This model, while allowing for relatively effective algorithm and tools, is comparatively limited. Especially modern operating systems for mobile devices are built around a model of small, highly inter-connected applications (apps), which fulfill user stories by exchanging commands and data. On such operating systems, malicious code can base exploits on this inter-process communication. Some well-known malware apps, for instance, use inter-process communication to extort private data from other badly programmed and thus vulnerable applications.To address this problem, the project InterFlow will develop novel algorithm, methods and tools with which data flows can be tracked across process boundaries, both using static code analysis, i.e., without executing the applications in question, and dynamically during the applications' execution. Past research has shown that the combination of both techniques can yield systems that are both highly effective and efficient. A particular feature of the envisioned solution is that it should go completely without any modifications to the mobile operating system. This will allow end users to deploy the mechanisms with ease, and on a wide range of devices. While motivated through this practical problem, this restriction will yield interesting research challenges, as the solution will not be able to rely on special trust anchors such as trusted kernels or Trusted Platform Modules to ensure a secure runtime.The analyses developed within the project InterFlow will allow software engineers to reliably pinpoint vulnerabilities which occur through the interaction of data-flow problems involving multiple applications, and will allow them to detect malware that exploits exactly such vulnerabilities.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
黎曼流形上的Ricci Soliton及几何结构研究
-
批准号:11401179
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2014
-
负责人:马冰清
-
依托单位:
静动态损伤问题的基面力元法及其在再生混凝土材料细观损伤分析中的应用
-
批准号:11172015
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2011
-
负责人:彭一江
-
依托单位: