课题基金 / 基金详情

Hardware-assisted Security

Hardware-assisted Security
硬件辅助安全
批准号:
RGPIN-2020-04744
负责人:
Asokan, Nadarajah
金额:
$4.01万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2021
资助国家:
加拿大
项目状态:
已结题
起止时间:
2021-01-01 至 2022-12-31

项目摘要

项目成果

Asokan, Nadarajah的其他基金

相似基金

相关文献

中文摘要
翻译
利用内存错误是远程攻击者试图侵入计算机系统的常用策略。最近许多针对勒索软件(如WannaCry)和日常生活中断(如NotPetya)的高调攻击都利用了内存错误,造成了数十亿美元的损失。在针对个人的针对性攻击中,内存错误也经常被利用,就像最近对WhatsApp的攻击一样,它利用了一种常见的内存错误(缓冲区溢出),改变了正常的程序流程,目的是让攻击者通过向手机的所有者拨打WhatsApp电话来控制手机。针对此类“运行时攻击”的纯软件解决方案更容易部署,但如果要确保足够的安全性,则会产生高昂的成本。基于硬件的解决方案更难部署。最近,主要的处理器供应商已经开始推出基于硬件的防御(例如,ARM指针认证(PA)),以应对特定类别的运行时攻击。利用这种防御来设计广泛适用的运行时保护解决方案是很有吸引力的,因为这些解决方案可以提供有效的保护,而不会产生高昂的部署成本。然而,这样做涉及两个主要挑战:(1)理解这些防御的当前设计固有的局限性(例如,ARM PA容易受到“重用攻击”,从代码中的一个位置获取的经过身份验证的指针在另一个位置被重用),以及(2)建立在这些见解的基础上设计有效的运行时保护机制,同时比最先进的更高效和更安全。方法:我的长期目标是设计有效的硬件辅助方法来保护软件。为此,我试图了解如何使用新兴的商用现货(COTS)硬件安全防御,以低屏障实现对实际部署的有效运行时保护。为了应对上述挑战,我制定了三个中短期目标O1-O3:(O1)系统地分析这些COTS防御,了解它们的局限性,并通过以新的方式(单独或联合)使用这些防御来开发有效的运行时保护技术,(O2)开发一个严格的框架来比较技术,(O3)利用获得的经验来识别和实现RISC-V(一个开源硬件平台)上的一组最佳硬件安全构建块(“原语”)。预期结果和利益:该计划将导致:软件工件,允许开发人员在商品硬件上轻松地为他们的软件提供运行时保护,选择的原语的开源硬件实现,可用于技术转让或进一步研究,并培训对运行时攻击的复杂性有深刻理解的高素质人员,并装备开发有效的防御。如果成功,该计划将大大加强现实世界中软件的安全性。
英文摘要
Exploiting memory errors is a popular tactic used by remote adversaries attempting to break into computer systems. Many recent high-profile attacks for ransomware (eg, WannaCry) and disruption of daily life (eg, NotPetya) exploited memory errors and caused billions of dollars in damages. Memory errors are also routinely exploited in targeted attacks against individuals, as in the recent WhatsApp hack, which exploited a common type of memory error (buffer overflows) altering the normal program flow in order to let the attacker control the phone just by making a WhatsApp call to the phone's owner. Software-only solutions against such "run-time attacks" are easier to deploy but incur high costs if they are to ensure sufficient security. Hardware-based solutions are more difficult to deploy. Recently, major processor vendors have started to roll out hardware-based defenses (e.g., ARM Pointer Authentication (PA)), against specific classes of run-time attacks. Leveraging such defenses to design broadly applicable solutions for run-time protection is attractive because these solutions can provide effective protections without incurring high deployment costs. However, doing so involves two major challenges: (1) understanding the limitations inherent in the current designs of these defenses (e.g., ARM PA is susceptible to "reuse attacks" where an authenticated pointer taken from one location in the code is reused in another), and (2) building on these insights to design effective run-time protection mechanisms that are simultaneously more efficient and more secure than the state-of-the art. Approach: My long term objective is to design effective hardware-assisted approaches to protect software. To this end, I seek to understand how to use emerging commercial off-the-shelf (COTS) hardware-security defenses to achieve effective run-time protection with a low-barrier for real-world deployment. To address the challenges above, I aim for three short- to medium-term objectives O1-O3: (O1) to systematically analyze these COTS defenses to understand their limitations and to develop effective techniques for run-time protection by using these defenses in new ways (individually or in conjunction), (O2) develop a rigorous framework to compare techniques, and (O3) use the experience gained to identify and realize a set of optimal hardware-security building blocks ("primitives") on RISC-V, an open-source hardware platform. Anticipated outcomes and benefits: The program will result in: software artifacts that allow developers to easily afford run-time protection for their software on commodity hardware, an open-source hardware implementation of selected primitives that can be used for technology transfer or further research, and  train highly-qualified personnel with deep understanding of the intricacies of run-time attacks and equipped to develop effective defenses. If successful, this program will significantly strengthen security for software in the real world.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Hardware-assisted Security
  • 批准号:
    RGPIN-2020-04744
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $4.01万
  • 财政年份:
    2022
  • 负责人:
    Asokan, Nadarajah
  • 依托单位:
Hardware-assisted Security
  • 批准号:
    RGPIN-2020-04744
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $4.01万
  • 财政年份:
    2020
  • 负责人:
    Asokan, Nadarajah
  • 依托单位:
国内基金
海外基金
光辅助MOCVD法制备多层结构提高厚YBCO 外延膜电流承载能力的研究
  • 批准号:
    51002063
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2010
  • 负责人:
    李国兴
  • 依托单位:
控制厚皮甜瓜花性型基因“A“的精细构图及标记辅助育种
  • 批准号:
    30471113
  • 项目类别:
    面上项目
  • 资助金额:
    21.0万元
  • 批准年份:
    2004
  • 负责人:
    王志民
  • 依托单位: