Abstract & Details
Description
Award ID: 2011066
The broader impact of this I-Corps project is focused on exploring translation of proactive defense-in-depth technologies focused on leveraging moving target defense techniques. The global cybersecurity market is currently valued at $124 Billion with an estimated 8.7% CAGR over the next 5 years. Since most solutions focus on monitoring and reacting to attacks, an opportunity exists to explore a proactive approach. Identical software implementations for every system suggest that an attacker identifying critical vulnerabilities in one program can exploit this knowledge for every device running that program. This is the fundamental basis behind the execution of computer viruses, and the primary reason how cyber-espionage software, such as STUXNET and Pegasus, have been able to infiltrate and pivot within sensitive systems. The increased use of IoT devices in safety-critical applications creates risks beyond exfiltrating sensitive data, such as patient records and credit card information, to larger scale cyber-terrorist activities conducted remotely and inexpensively. This I-Corps project advances the development of new cybersecurity systems. The key avenue for exploiting safety-critical software is often stack-based exploits, most notably buffer overflows, which are directly responsible for over 60% of IoT device attacks. The key step for any stack-based cyber-attack to be successful is reconnaissance. The use of moving target defense to diversify the internal structure of applications is proposed, ensuring that every program will have a unique identity. Specifically, this project proposes mitigating stack-based vulnerabilities by utilizing stack segmentation, address space randomization, data encryption, function shuffling, dummy code insertion, stack canaries, and variable obfuscation. This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
NSF Program Director: Ruth Shuman
The broader impact of this I-Corps project is focused on exploring translation of proactive defense-in-depth technologies focused on leveraging moving target defense techniques. The global cybersecurity market is currently valued at $124 Billion with an estimated 8.7% CAGR over the next 5 years. Since most solutions focus on monitoring and reacting to attacks, an opportunity exists to explore a proactive approach. Identical software implementations for every system suggest that an attacker identifying critical vulnerabilities in one program can exploit this knowledge for every device running that program. This is the fundamental basis behind the execution of computer viruses, and the primary reason how cyber-espionage software, such as STUXNET and Pegasus, have been able to infiltrate and pivot within sensitive systems. The increased use of IoT devices in safety-critical applications creates risks beyond exfiltrating sensitive data, such as patient records and credit card information, to larger scale cyber-terrorist activities conducted remotely and inexpensively. This I-Corps project advances the development of new cybersecurity systems. The key avenue for exploiting safety-critical software is often stack-based exploits, most notably buffer overflows, which are directly responsible for over 60% of IoT device attacks. The key step for any stack-based cyber-attack to be successful is reconnaissance. The use of moving target defense to diversify the internal structure of applications is proposed, ensuring that every program will have a unique identity. Specifically, this project proposes mitigating stack-based vulnerabilities by utilizing stack segmentation, address space randomization, data encryption, function shuffling, dummy code insertion, stack canaries, and variable obfuscation. This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
NSF Program Director: Ruth Shuman
| Status | Closed |
|---|---|
| Effective start/end date | 06/01/20 → 09/30/22 |
Funding
- I-Corps Teams: $50,000.00
Active Fiscal Year
- FY2022
Start Fiscal Year
- FY2020
TIP Programs
- I-Corps Teams
Key Technology Areas
- Data and Cybersecurity
- (confidence score: 100%)
Technology Foci
- Cyber-security
- (confidence score: 100%)
Congressional District at Award
- District n. 05 of Tennessee
Current Congressional District
- District n. 07 of Tennessee
United States
- Tennessee
Core Based Statistical Area (CBSA)
- Nashville-Davidson--Murfreesboro--Franklin, TN
County
- County: Davidson, TN
Fingerprint
Explore the research topics touched on by this project. These labels are generated based on the underlying awards/grants. Together they form a unique fingerprint. Learn more about Elsevier's Fingerprint Engine here: https://beta.elsevier.com/products/elsevier-fingerprint-engine