课题基金 / 基金详情

Compositional Security Analysis for Binaries

Compositional Security Analysis for Binaries
二进制文件的组成安全分析
批准号:
EP/K032011/1
负责人:
Pasquale Malacaria
金额:
$34.53万
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2013
资助国家:
英国
项目状态:
已结题
起止时间:
2013 至 --

项目摘要

项目成果

Pasquale Malacaria的其他基金

相似基金

相关文献

中文摘要
翻译
为了寻找漏洞,情报机构、军事组织和安全工程师会定期检查二进制文件。二进制文件通常很大,因此验证和程序分析技术应该是可伸缩的。这个项目将成为二进制代码成分分析的先驱。这将导致分析既模块化又可扩展。组合推理的科学挑战是如何分离复杂的相互作用,避免昂贵的操作,如量词消除,并得出紧凑的过程摘要。项目团队将开发二进制文件组成分析的基础技术,并通过一个运行的案例研究测试它们的可行性:数据封存问题。当机密数据的内存在释放之前被归零时,机密数据将被消毒,从而防止攻击者检索敏感信息。数据归档在科学上很有吸引力,因为需要跟踪秘密如何从一个过程传递到另一个过程,此外,还需要跟踪秘密如何嵌入到复合数据结构中。向上和向下转换以及需要跟踪数据对象的大小以确保(例如,缓冲区的所有元素都正确归零)会加剧这个问题。
英文摘要
Binaries are routinely inspected by the intelligence community, military organisations and security engineers in their search for vulnerabilities. Binaries are often huge and therefore verification and program analysis techniques should be scalable.This project will pioneer compositional analyses for binary code. This will result in analyses that are both modular and scalable.The scientific challenge in compositional reasoning is how to separate intricate interactions, avoidexpensive operations such as quantifier elimination, and derive procedure summaries that are compact.The project team will develop foundational techniques for the compositional analysis of binaries, testing their viability with a running case study: the data santisation problem. Confidential data is sanitised when its memory is zeroed before it is deallocated, preventing an attacker retrieving the sensitive information.Data santisation is scientifically fascinating because of the need to track how secrets are passedfrom one procedure to another and, in addition, how secrets are embedded into compound data-structures.The problem is exacerbated by up-casting and down-casting, and the need to track the sizeof a data object to ensure, for example, that all the elements of a buffer are properly zeroed.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/2693208.2693240
发表时间: 2015-02
期刊: ACM SIGSOFT Softw. Eng. Notes
影响因子: --
作者: [Quoc-Sang Phan;P. Malacaria;C. Păsăreanu]
通讯作者: Quoc-Sang Phan;P. Malacaria;C. Păsăreanu
DOI: 10.1109/csf.2016.34
发表时间: 2016-08
期刊: 2016 IEEE 29th Computer Security Foundations Symposium (CSF)
影响因子: --
作者: [C. Păsăreanu;Quoc-Sang Phan;P. Malacaria]
通讯作者: C. Păsăreanu;Quoc-Sang Phan;P. Malacaria
Abstract model counting
抽象模型计数
DOI: 10.1145/2590296.2590328
发表时间: 2014
期刊:
影响因子: --
作者: [Phan Q]
通讯作者: Phan Q
DOI: 10.1109/ares.2015.14
发表时间: 2015-08
期刊: 2015 10th International Conference on Availability, Reliability and Security
影响因子: --
作者: [Quoc-Sang Phan;P. Malacaria]
通讯作者: Quoc-Sang Phan;P. Malacaria
CHAI: Cyber Hygiene in AI enabled domestic life
  • 批准号:
    EP/T026596/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $41.99万
  • 财政年份:
    2020
  • 负责人:
    Pasquale Malacaria
  • 依托单位:
Customized and Adaptive approach for Optimal Cybersecurity Investment
  • 批准号:
    EP/R004897/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $49.54万
  • 财政年份:
    2017
  • 负责人:
    Pasquale Malacaria
  • 依托单位:
Games and Abstraction: The Science of Cyber Security
  • 批准号:
    EP/K005820/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $40.32万
  • 财政年份:
    2013
  • 负责人:
    Pasquale Malacaria
  • 依托单位:
Model Checking and Program Analysis for Quantifying Interference
  • 批准号:
    EP/F023766/1
  • 项目类别:
    Research Grant
  • 资助金额:
    $14.02万
  • 财政年份:
    2008
  • 负责人:
    Pasquale Malacaria
  • 依托单位:
海外基金