Secure Software Execution System
Secure Software Execution System
批准号:
12133201
负责人:
KATO Kazuhiko
金额:
$25.54万
依托单位:
依托单位国家:
日本
项目类别:
Grant-in-Aid for Scientific Research on Priority Areas
财政年份:
2000
资助国家:
日本
项目状态:
已结题
起止时间:
2000 至 2003
中文摘要
我们已经开发了使用操作系统和系统软件技术,用于在开放网络环境中安全执行软件。我们总结了我们的主要研究课题如下:(1)处理程序攻击的技术再次防御攻击我们开发了一种技术,通过将软件与主机环境隔离来保护易受攻击的程序。攻击检测我们开发了一个入侵检测系统来监控软件,这样系统就可以检测出偏离规范的行为。我们的系统通过检查程序发出的系统调用来检测任何此类恶意行为。在软件被成功利用的情况下,我们开发了一种技术来限制软件拥有的特权,从而可以避免进一步的损害。从损坏中恢复我们的技术通过将机器恢复到以前的状态来从攻击造成的任何损坏中恢复。(2)网络的安全和隐私安全虚拟专用网目前的虚拟专用网(VPN)系统不存在对用户允许做什么的细粒度限制。在我们的研究中,我们试图解决这个问题。防火墙我们开发了一种实现高性能防火墙的技术。我们的技术改进了现有的以前的作品,能够检测未经授权的访问,而以前的作品不能。此外,我们的技术可以通过有效地检查内容来检测此类未经授权的访问,而不会造成重大的性能损失。访问服务器时匿名的实现我们开发了一种用户访问服务器时匿名的技术。这样可以保护用户的信息不被收集。
英文摘要
We have developed using operating systems and system software techniques for secure software execution in an open network environment. We summarize our main research topics as follows(1) Techniques for handling attacks on programs Defense again attacks We developed a technique for protecting programs that are vulnerable to attacks by isolating the software from the host environment. Detection of attacks We developed an intrusion detection system that monitors software such that the system can detect behaviors that deviate from the norm. Our system detects any such malicious behavior by examining system calls issued by the program. Minimization of damage In case the software is successfully exploited, we developed a technique to limit the privileges the software has, so that further damage can be avoided. Recovery from damage Our technology recovers from any damage caused by an attack by restoring the machine to a previous state.(2) Security and Privacy on Networks Secure Virtual Private Networks Fine-grained restrictions of what users are allowed to do are inexistent in current Virtual Private Network (VPN) systems. In our research, we attempt to solve this problem. Firewalls We developed a technology for realizing a high-performance firewall. Our technology improves on existing previous works by being able to detect unauthorized accesses that predecessors could not. Furthermore, our techniques can detect such unauthorized accesses without significant performance loss by examining the contents efficiently. Realization of Anonymity when accessing servers We developed a technology for anonymaing a user when accessing servers. This enables the protection of the user's information from being collected.
期刊论文(282)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Mizuki Oka: "Intrusion Detection System Based on Binary Code and Execution Stack Analysis"日本ソフトウェア科学会第20回記念大会. 4 (2003)
Mizuki Oka:“基于二进制代码和执行堆栈分析的入侵检测系统”日本软件学会第20届年会4(2003年)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
Kazuhiko Kato: "Software Circulation using Sandboxed File Space-Previous Experience and New Approach"Proc.of 8^<th> ECOOP Workshop on Mobile Object Systems. 17 (2002)
Kazuhiko Kato:“使用沙盒文件空间的软件流通 - 先前的经验和新方法”Proc.of 8^<th>移动对象系统 ECOOP 研讨会。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
Kazuhiko Kato: "Persistently Cached B-Trees"IEEE Transactions on Knowledge and Data Engineering. (掲載予定). (2002)
Kazuhiko Kato:“持久缓存 B 树”IEEE 知识与数据工程汇刊(即将出版)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
渡辺 元晴: "P2P型ファイル検索における高スループット・ピアの自動選択機構"情報処理学会研究会報告. 65-72 (2004)
Motoharu Watanabe:“P2P 文件搜索中的高吞吐量对等自动选择机制”日本信息处理学会研究小组报告 65-72 (2004)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
榮樂恒太郎: "システム・コールに対するラッパ/リファレンス・モニタSysGuardの設計と実現"情報処理学会論文誌. Vol.43・No.6. 1670-1701 (2002)
Kotaro Eiraku:“系统调用的包装器/参考监视器 SysGuard 的设计和实现”,日本信息处理学会卷 43·No.6(2002 年)。
DOI:
--
发表时间:
期刊:
影响因子:
--
作者:
[]
通讯作者:
共 141 条
Game theoretic approach to autonomous mechanism in distributed systems
-
批准号:24650010
-
项目类别:Grant-in-Aid for Challenging Exploratory Research
-
资助金额:$2.5万
-
财政年份:2012
-
负责人:KATO Kazuhiko
-
依托单位:
Equilibrium analyses and the comparison of the effects among environmental policies in mixed oligopoly under transboundary pollution
-
批准号:23730247
-
项目类别:Grant-in-Aid for Young Scientists (B)
-
资助金额:$0.92万
-
财政年份:2011
-
负责人:KATO Kazuhiko
-
依托单位:
The substance of Japanese-style parliamentary system andconstitutional control of the cabinet governance
-
批准号:22530038
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$1.83万
-
财政年份:2010
-
负责人:KATO Kazuhiko
-
依托单位:
A Study on a Programming Framework for Virtual Computing Environments
-
批准号:22300006
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$11.48万
-
财政年份:2010
-
负责人:KATO Kazuhiko
-
依托单位:
An Access Control Mechanism to Allow High-level Policy Description
-
批准号:19300005
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$11.4万
-
财政年份:2007
-
负责人:KATO Kazuhiko
-
依托单位:
Study on Resource-Oriented Operating System
-
批准号:13480075
-
项目类别:Grant-in-Aid for Scientific Research (B)
-
资助金额:$9.02万
-
财政年份:2001
-
负责人:KATO Kazuhiko
-
依托单位:
A distributed and parallel WWW search system with a mobile object technique
-
批准号:11680337
-
项目类别:Grant-in-Aid for Scientific Research (C)
-
资助金额:$2.37万
-
财政年份:1999
-
负责人:KATO Kazuhiko
-
依托单位:
Wide-Area Distributed Computing Based on a Mobile Object Computing Approach
-
批准号:10358004
-
项目类别:Grant-in-Aid for Scientific Research (A).
-
资助金额:$19.33万
-
财政年份:1998
-
负责人:KATO Kazuhiko
-
依托单位:
海外基金