Energy News  
CYBER WARS
Disrupting exploitable patterns in software to make systems safer
by Staff Writers
Washington DC (SPX) Sep 24, 2021

Program pushes secure system design by developing ways to stop cyber attackers' from executing unintended computations on critical systems

While much attention is paid to detecting and remedying flaws or vulnerabilities in software, the way a system is designed can also create large opportunities for attackers. System designers primarily focus on ensuring a program is adept at executing a specific task, focusing on how a design can best support intended features and behaviors and on how they will be implemented within the design.

Attackers have also discovered that these design structures and implementation behaviors can be repurposed for their own malicious purposes. Unexpected - or emergent - behaviors that these features could exhibit are not often taken into consideration at the time of design.

As a result, attackers often find that they can generate emergent behaviors by using what's already built into a system, providing a way to exploit flaws that are several layers down. In other words, systems are unknowingly being designed in ways that support adversarial programmability and combinations of features and unprotected abstractions. These amount to embedded exploit execution engines - creating what is colloquially known as "weird machines."

"When it comes to exploits, the common thinking is that there is a flaw in the program and then there is a crafted input that can trigger the flaw resulting in the program doing something it shouldn't like crashing or granting privileges to an attacker," said Sergey Bratus, a program manager in DARPA's Information Innovation Office (I2O).

"Today, the reality is somewhat different as those existing flaws aren't immediately exposed, so an attacker needs help getting to them. This help is unwittingly provided by the system's own features and design. Attackers are able to make use of these features and force them to operate in ways they were never intended to."

This challenge becomes increasingly problematic when observing a class of systems that rely on similar features. When an attacker discovers an exploit on one system, this can give a big hint on how to find similar exploits for other systems that have been developed independently by different vendors but make use of similar mechanisms. This creates persistent exploitable patterns that can be used across a whole host of programs.

The Hardening Development Toolchains Against Emergent Execution Engines (HARDEN) program seeks to give developers a way to understand emergent behaviors and thereby create opportunity to choose abstractions and implementations that limit an attacker's ability to reuse them for malicious purposes, thus stopping the unintentional creation of weird machines.

HARDEN will explore novel theories and approaches and develop practical tools to anticipate, isolate, and mitigate emergent behaviors in computing systems throughout the entire software development lifecycle (SDLC).

Notably, the program aims to create mitigation approaches that go well beyond patching. At present, patches tend to only address a particular exploit and do not disrupt the underlying exploit execution engine residing at the design-level.

HARDEN will also focus on validating the generated approaches by applying broad theories and generic tools to concrete technological use cases of general-purpose integrated software systems. Potential evaluation systems include the Unified Extended Firmware Interface (UEFI) architecture and boot-time chain of trust, as well as integrated software systems from the Air Force and Navy domains, such as pilots' tablets.

"There are many ways to theorize about addressing these challenges, but the test of the theory is how it will apply to an actual integrated system that we base trust on, or want to base trust on. We want to ensure we're creating models that will be of actual use to critical defense systems," noted Bratus.

Interested proposers have an opportunity to learn more about the HARDEN program during a Proposers Day on September 30, 2021, from 12:00 p.m. to 4:30 p.m. ET. The session will be held via Zoom and virtual check-in begins at 11:00 a.m. ET. Advance registration is required to attend. Learn more here.


Related Links
Defense Advanced Research Projects Agency
Cyberwar - Internet Security News - Systems and Policy Issues


Thanks for being here;
We need your help. The Space Media Network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceMediaNetwork Contributor
$5 Billed Once


credit card or paypal
SpaceMediaNetwork Monthly Supporter
$5 Billed Monthly


paypal only


CYBER WARS
A 15-user quantum secure direct communication network
Beijing, China (SPX) Sep 24, 2021
Quantum communication has presented a revolutionary step in secure communication due to its high security of the quantum information, and many communication protocols have been proposed, such as the quantum secure direct communication (QSDC) protocol. QSDC based on entanglement can directly transmit confidential information. Any attack of QSDC results to only random number, and cannot obtain any useful information from it. Therefore, QSDC has simple communication steps and reduces potential securi ... read more

Comment using your Disqus, Facebook, Google or Twitter login.



Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
Researchers want to breed a sorghum variety that captures more carbon

UMD to create sustainable biofuels and bioplastics from food waste with DOE grant

Zeolites make for efficient production of pentanoic biofuels

Marginal land available for bioenergy crops much scarcer than previously estimated

CYBER WARS
Solar cells with 30-year lifetimes for power-generating windows

Scientists explore the physics of perovskite, a material with many potential technological applications

PVpallet is ready to rethink solar shipping with game-changing solution

ITMO researchers create nanoparticle paste to make perovskite solar cells more efficient

CYBER WARS
How do wind turbines respond to winds, ground motion during earthquakes?

For golden eagles, habitat loss is main threat from wind farms

Wind turbines can be clustered while avoiding turbulent wakes of their neighbors

Shell, France's EDF to build US offshore windfarm

CYBER WARS
UK firms urge govt to quicken shift from fossil fuels

UN redoubles green energy push to save climate, boost electricity

EU looking at measures to tackle 'critical' energy crisis

Biden says US 'to double' contribution to climate finance

CYBER WARS
A new solid-state battery surprises the researchers who created it

Now everyone can build battery-free electronic devices

Fabricating MgB2 superconductors using spark plasma sintering and pulse magnetization

Researchers develop new tool for analyzing large superconducting circuits

CYBER WARS
What lies beneath: Swiss search for bombs at bottom of Lake Geneva

UK regulator to tackle false 'greenwashing' claims

Bitcoin mining generates substantial electronic waste: study

Indonesia court finds president negligent over pollution in landmark case

CYBER WARS
US warns against 'manipulation' of Europe gas prices

EU ministers meet on Europe's 'critical' energy crisis

S.Africa regulator approves controversial floating power plants

Iraqi cement-makers angry at fuel subsidy cut

CYBER WARS
Justin Simon Shepherds Perseverance through first phase of Martian rock sampling

Take a 3D Spin on Mars and track NASA's Perseverance Rover

NASA's Ingenuity Helicopter Captures a Mars Rock Feature in 3D

Flying On Mars is getting harder and harder









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.