Hybrid approaches for enforcing security policies.
Hybrid approaches for enforcing security policies.
批准号:
RGPIN-2015-04461
负责人:
Tawbi, Nadia
金额:
$1.31万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2019
资助国家:
加拿大
项目状态:
已结题
起止时间:
2019-01-01 至 2020-12-31
中文摘要
在我们高度联系和高度计算机化的世界里,安全问题是非常重要的。*可信系统需要与使用户面临信息泄露或数据损坏风险的不可信方进行通信。迫切需要找到有效的解决方案来保护用户。尽管已经做出了重大的研究努力,但仍有许多具有挑战性的问题有待探索。*我的广泛研究目标是为在应用程序级别执行安全策略的可证明合理的技术、方法和执行机制的设计做出贡献。*访问控制、加密、防火墙、数字签名、防病毒扫描等机制要么限制过多,导致灵活性下降,要么无法抵御新引入的威胁或恶意攻击。其中一个根本原因是它们没有解决根本问题,即以特定于应用程序的细粒度方式跟踪信息流。要做到这一点,需要分析应用程序的代码;这种研究趋势被称为“基于语言的安全”。在本研究计划中,我将讨论信息流实施机制,以防止信息从较高安全级别流向较低安全级别,或以双重方式防止较低安全级别的数据破坏较高安全级别的数据。其主要思想是检查应用程序的代码并控制其执行,以便应用策略。*我将采用以下目标和方法路线。*1.引入尽可能少的开销,同时减少误报。采用静力分析与动力分析相结合的混合分析方法。*2.解密处理。解密意味着故意从较高的安全级别泄露到较低的安全级别。*信息流策略非常严格;现实世界中的应用程序将发布信息作为其预期功能的一部分。例如,登录程序、加密数据的通信或投票系统不符合信息流政策。一些信息的发布必须得到允许,但必须加以控制,以防止意外泄漏。*3.设计针对更具表现力的语言的机制,例如并发语言。可能会出现更具挑战性的问题,如计时通道,由于攻击者观察时间的能力而导致泄漏。将采用适合并发的广泛的数据流分析和语义模型。*4.在概率框架中量化泄漏量。其目的是放松不干预,并容忍一些量化的泄漏。*5.将所有这些技巧转化为一种现实世界的语言。*结果将为制定有效和强有力的机制以保护其数据的机密性和完整性提供实践和理论基础。*
英文摘要
In our highly connected and highly computerized world, security issues are of major importance. ***Trusted systems need to communicate with untrustworthy parties exposing the users to a risk of information leakage or data corruption. It is urgent to find effective solutions to protect users. Despite major research efforts that have been devised, there still are many challenging problems to be explored.***My broad research aim is to contribute to the design of provably sound techniques, methods and enforcement mechanisms that enforce security policies at the level of applications. ***Mechanisms such as access control, encryption, firewalls, digital signatures, and antivirus scanning are either too restrictive, causing loss of flexibility, or unable to protect from newly introduced threats or malicious attacks. One of the underlying reasons is that they do not address the fundamental problem, which is tracking information flow in a fine-grained application-specific way. To do this one needs to analyze the code of an application; this research trend is known as "language-based security". In this research program, I will address information flow enforcement mechanisms that prevent information from flowing from a higher security level to a lower one or in a dual way to prevent lower security level data from corrupting higher ones. The main idea is to inspect the code of an application and control its execution in order to apply the policy. ***I will adopt the following objectives and methodological lines. ******1. Introducing the least overhead possible while reducing false positives. A hybrid approach combining static and dynamic analysis in an effective way is to be adopted. ***2. Dealing with declassification. Declassification means an intentional leak from higher security levels to lower ones. ***Information flow policy is very restrictive; real-world applications release information as part of their intended function. For instance, login procedures, communication of encrypted data, or voting systems do not comply with information-flow policy. Release of some information must be allowed but controlled to prevent non-intended leaks. ******3. Designing mechanisms that target more expressive languages such as concurrent languages. More challenging issues may appear such as timing channels, which cause leaks due to attackers' capacity to observe time. Extensive data-flow analysis and semantic models suitable to concurrency will be adopted. ***4. Quantifying the amount of leakage in a probabilistic framework. The aim is to relax non-interference and tolerate some quantified leaks. ***5. Leveraging all these techniques to a real world language. *********The results will provide practical and theoretical foundations for the development of effective and robust mechanisms to preserve the confidentiality and the integrity of their data. *** **
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Enforcing security and safety policies in IoT applications
-
批准号:RGPIN-2020-04283
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.75万
-
财政年份:2022
-
负责人:Tawbi, Nadia
-
依托单位:
Enforcing security and safety policies in IoT applications
-
批准号:RGPIN-2020-04283
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.75万
-
财政年份:2021
-
负责人:Tawbi, Nadia
-
依托单位:
Enforcing security and safety policies in IoT applications
-
批准号:RGPIN-2020-04283
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.75万
-
财政年份:2020
-
负责人:Tawbi, Nadia
-
依托单位:
Hybrid approaches for enforcing security policies.
-
批准号:RGPIN-2015-04461
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2018
-
负责人:Tawbi, Nadia
-
依托单位:
Hybrid approaches for enforcing security policies.
-
批准号:RGPIN-2015-04461
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2017
-
负责人:Tawbi, Nadia
-
依托单位:
Hybrid approaches for enforcing security policies.
-
批准号:RGPIN-2015-04461
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2016
-
负责人:Tawbi, Nadia
-
依托单位:
Hybrid approaches for enforcing security policies.
-
批准号:RGPIN-2015-04461
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2015
-
负责人:Tawbi, Nadia
-
依托单位:
Security policy enforcement mechanisms
-
批准号:194380-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2014
-
负责人:Tawbi, Nadia
-
依托单位:
Security policy enforcement mechanisms
-
批准号:194380-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2013
-
负责人:Tawbi, Nadia
-
依托单位:
Security policy enforcement mechanisms
-
批准号:194380-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2012
-
负责人:Tawbi, Nadia
-
依托单位:
Security policy enforcement mechanisms
-
批准号:194380-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2011
-
负责人:Tawbi, Nadia
-
依托单位:
Security policy enforcement mechanisms
-
批准号:194380-2010
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.26万
-
财政年份:2010
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2009
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2008
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2007
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2006
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2005
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2004
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2003
-
负责人:Tawbi, Nadia
-
依托单位:
Formal, automatic and efficient malicious code detection by static analysis
-
批准号:194380-2002
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2002
-
负责人:Tawbi, Nadia
-
依托单位:
国内基金
海外基金
Lagrangian origin of geometric approaches to scattering amplitudes
-
批准号:24ZR1450600
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:ALEXANDER OCHIROV
-
依托单位: