课题基金 / 基金详情

Hardware-assisted Security

Hardware-assisted Security
硬件辅助安全
批准号:
RGPIN-2020-04744
负责人:
Asokan, Nadarajah
金额:
$4.01万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31

项目摘要

项目成果

Asokan, Nadarajah的其他基金

相似基金

相关文献

中文摘要
翻译
利用内存错误是远程攻击者试图闯入计算机系统时常用的策略。最近许多针对勒索软件(如WannaCry)和破坏日常生活(如NotPetya)的高调攻击利用了内存错误,造成了数十亿美元的损失。内存错误也经常在针对个人的攻击中被利用,就像最近的WhatsApp黑客一样,它利用了一种常见的内存错误(缓冲区溢出)来改变正常的程序流程,以便让攻击者通过向手机所有者拨打WhatsApp电话来控制手机。针对这种“运行时攻击”的纯软件解决方案更容易部署,但如果要确保足够的安全性,则成本很高。基于硬件的解决方案更难部署。最近,主要的处理器供应商已经开始推出基于硬件的防御(例如,ARM指针认证(PA)),针对特定类别的运行时攻击。利用这种防御来设计广泛适用的运行时保护解决方案是很有吸引力的,因为这些解决方案可以提供有效的保护,而不会产生高昂的部署成本。然而,这样做涉及两个主要挑战:(1)理解这些防御系统当前设计中固有的局限性(例如,ARM PA易受“重用攻击”的影响,即从代码中的一个位置获取的经过身份验证的指针在另一个位置被重用),以及(2)基于这些见解设计有效的运行时保护机制,这些机制比最先进的技术更有效,更安全。方法:我的长期目标是设计有效的硬件辅助方法来保护软件。为此,我试图了解如何使用新兴的商业现货(COTS)硬件安全防御来实现有效的运行时保护,并为实际部署提供低障碍。为了应对上述挑战,我打算实现三个中短期目标O 1-O3:(O 1)系统地分析这些COTS防御,以了解它们的局限性,并通过以新的方式使用这些防御来开发有效的运行时保护技术(单独或结合),(O2)制定一个严格的框架来比较技术,以及(O3)使用所获得的经验来识别并在RISC-V(一种开源硬件平台)上实现一组最佳硬件安全构建块(“原语”)。 预期成果和效益:该方案将导致:软件工件,使开发人员能够轻松地为他们的软件在商品硬件上提供运行时保护,选择原语的开源硬件实现,可用于技术转让或进一步研究,并培训对运行时攻击的复杂性有深刻理解的高素质人员,并配备开发有效防御的设备。如果成功,该计划将大大加强软件在真实的世界中的安全性。
英文摘要
Exploiting memory errors is a popular tactic used by remote adversaries attempting to break into computer systems. Many recent high-profile attacks for ransomware (eg, WannaCry) and disruption of daily life (eg, NotPetya) exploited memory errors and caused billions of dollars in damages. Memory errors are also routinely exploited in targeted attacks against individuals, as in the recent WhatsApp hack, which exploited a common type of memory error (buffer overflows) altering the normal program flow in order to let the attacker control the phone just by making a WhatsApp call to the phone's owner. Software-only solutions against such "run-time attacks" are easier to deploy but incur high costs if they are to ensure sufficient security. Hardware-based solutions are more difficult to deploy. Recently, major processor vendors have started to roll out hardware-based defenses (e.g., ARM Pointer Authentication (PA)), against specific classes of run-time attacks. Leveraging such defenses to design broadly applicable solutions for run-time protection is attractive because these solutions can provide effective protections without incurring high deployment costs. However, doing so involves two major challenges: (1) understanding the limitations inherent in the current designs of these defenses (e.g., ARM PA is susceptible to "reuse attacks" where an authenticated pointer taken from one location in the code is reused in another), and (2) building on these insights to design effective run-time protection mechanisms that are simultaneously more efficient and more secure than the state-of-the art. Approach: My long term objective is to design effective hardware-assisted approaches to protect software. To this end, I seek to understand how to use emerging commercial off-the-shelf (COTS) hardware-security defenses to achieve effective run-time protection with a low-barrier for real-world deployment. To address the challenges above, I aim for three short- to medium-term objectives O1-O3: (O1) to systematically analyze these COTS defenses to understand their limitations and to develop effective techniques for run-time protection by using these defenses in new ways (individually or in conjunction), (O2) develop a rigorous framework to compare techniques, and (O3) use the experience gained to identify and realize a set of optimal hardware-security building blocks ("primitives") on RISC-V, an open-source hardware platform. Anticipated outcomes and benefits: The program will result in: software artifacts that allow developers to easily afford run-time protection for their software on commodity hardware, an open-source hardware implementation of selected primitives that can be used for technology transfer or further research, and  train highly-qualified personnel with deep understanding of the intricacies of run-time attacks and equipped to develop effective defenses. If successful, this program will significantly strengthen security for software in the real world.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Hardware-assisted Security
  • 批准号:
    RGPIN-2020-04744
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $4.01万
  • 财政年份:
    2021
  • 负责人:
    Asokan, Nadarajah
  • 依托单位:
Hardware-assisted Security
  • 批准号:
    RGPIN-2020-04744
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $4.01万
  • 财政年份:
    2020
  • 负责人:
    Asokan, Nadarajah
  • 依托单位:
国内基金
海外基金
光辅助MOCVD法制备多层结构提高厚YBCO 外延膜电流承载能力的研究
  • 批准号:
    51002063
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2010
  • 负责人:
    李国兴
  • 依托单位:
控制厚皮甜瓜花性型基因“A“的精细构图及标记辅助育种
  • 批准号:
    30471113
  • 项目类别:
    面上项目
  • 资助金额:
    21.0万元
  • 批准年份:
    2004
  • 负责人:
    王志民
  • 依托单位: