Hardware-assisted Security
Hardware-assisted Security
批准号:
RGPIN-2020-04744
负责人:
Asokan, Nadarajah
金额:
$4.01万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2020
资助国家:
加拿大
项目状态:
已结题
起止时间:
2020-01-01 至 2021-12-31
中文摘要
利用内存错误是远程攻击者试图侵入计算机系统时常用的策略。最近许多备受瞩目的勒索软件攻击(如WannaCry)和日常生活中断攻击(如NotPetya)利用内存错误造成了数十亿美元的损失。在针对个人的有针对性的攻击中,内存错误也经常被利用,就像最近的WhatsApp黑客攻击一样,该攻击利用了一种常见的内存错误(缓冲区溢出)来改变正常的程序流,以便让攻击者只需向手机所有者发出WhatsApp电话即可控制手机。
针对此类“运行时攻击”的纯软件解决方案更易于部署,但如果要确保足够的安全性,则会产生高昂的成本。基于硬件的解决方案更难部署。最近,主要的处理器供应商已经开始推出基于硬件的防御(例如,ARM指针身份验证(PA)),以抵御特定类别的运行时攻击。利用这样的防御来设计广泛适用的运行时保护解决方案是有吸引力的,因为这些解决方案可以提供有效的保护,而不会招致高昂的部署成本。然而,这样做涉及两大挑战:(1)了解这些防御的当前设计中固有的限制(例如,ARM PA容易受到“重用攻击”,即从代码中的一个位置获取的经过身份验证的指针在另一个位置被重用),以及(2)基于这些见解来设计有效的运行时保护机制,这些机制同时比最先进的更高效和更安全。
方法:我的长期目标是设计有效的硬件辅助方法来保护软件。为此,我试图了解如何使用新兴的商用现成(COTS)硬件安全防御来实现有效的运行时保护,并降低实际部署的障碍。为了应对上述挑战,我的目标是三个中短期目标:(O1)系统地分析这些COTS防御,以了解它们的局限性,并通过以新的方式(单独或联合使用)使用这些防御来开发有效的运行时保护技术,(O2)开发一个严格的框架来比较技术,以及(03)使用获得的经验来识别并在开源硬件平台RISC-V上实现一组最佳的硬件安全构建块(“原语”)。
预期结果和好处:该计划将产生:使开发人员能够轻松地在商用硬件上为他们的软件提供运行时保护的软件构件;可用于技术转让或进一步研究的选定原语的开源硬件实现;以及培训深入了解运行时攻击的错综复杂并具备开发有效防御能力的高资质人员。如果成功,该计划将显著加强现实世界中软件的安全性。
英文摘要
Exploiting memory errors is a popular tactic used by remote adversaries attempting to break into computer systems. Many recent high-profile attacks for ransomware (eg, WannaCry) and disruption of daily life (eg, NotPetya) exploited memory errors and caused billions of dollars in damages. Memory errors are also routinely exploited in targeted attacks against individuals, as in the recent WhatsApp hack, which exploited a common type of memory error (buffer overflows) altering the normal program flow in order to let the attacker control the phone just by making a WhatsApp call to the phone's owner.
Software-only solutions against such “run-time attacks” are easier to deploy but incur high costs if they are to ensure sufficient security. Hardware-based solutions are more difficult to deploy. Recently, major processor vendors have started to roll out hardware-based defenses (e.g., ARM Pointer Authentication (PA)), against specific classes of run-time attacks. Leveraging such defenses to design broadly applicable solutions for run-time protection is attractive because these solutions can provide effective protections without incurring high deployment costs. However, doing so involves two major challenges: (1) understanding the limitations inherent in the current designs of these defenses (e.g., ARM PA is susceptible to “reuse attacks” where an authenticated pointer taken from one location in the code is reused in another), and (2) building on these insights to design effective run-time protection mechanisms that are simultaneously more efficient and more secure than the state-of-the art.
Approach: My long term objective is to design effective hardware-assisted approaches to protect software. To this end, I seek to understand how to use emerging commercial off-the-shelf (COTS) hardware-security defenses to achieve effective run-time protection with a low-barrier for real-world deployment. To address the challenges above, I aim for three short- to medium-term objectives O1-O3: (O1) to systematically analyze these COTS defenses to understand their limitations and to develop effective techniques for run-time protection by using these defenses in new ways (individually or in conjunction), (O2) develop a rigorous framework to compare techniques, and (O3) use the experience gained to identify and realize a set of optimal hardware-security building blocks (“primitives”) on RISC-V, an open-source hardware platform.
Anticipated outcomes and benefits: The program will result in: software artifacts that allow developers to easily afford run-time protection for their software on commodity hardware, an open-source hardware implementation of selected primitives that can be used for technology transfer or further research, and train highly-qualified personnel with deep understanding of the intricacies of run-time attacks and equipped to develop effective defenses. If successful, this program will significantly strengthen security for software in the real world.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Hardware-assisted Security
-
批准号:RGPIN-2020-04744
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$4.01万
-
财政年份:2022
-
负责人:Asokan, Nadarajah
-
依托单位:
Hardware-assisted Security
-
批准号:RGPIN-2020-04744
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$4.01万
-
财政年份:2021
-
负责人:Asokan, Nadarajah
-
依托单位:
国内基金
海外基金
光辅助MOCVD法制备多层结构提高厚YBCO 外延膜电流承载能力的研究
-
批准号:51002063
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2010
-
负责人:李国兴
-
依托单位:
控制厚皮甜瓜花性型基因“A“的精细构图及标记辅助育种
-
批准号:30471113
-
项目类别:面上项目
-
资助金额:21.0万元
-
批准年份:2004
-
负责人:王志民
-
依托单位: