290 research outputs found
Tarnhelm: Isolated, transparent and confidential execution of arbitrary code in ARM’s TrustZone
Recommended from our members
Protecting Smart Devices from the Bottom-Up
Modern systems are mainly composed of IoT devices and Smartphones. Most of these devices use ARM processors, which, along with flexible licensing, have new security architecture features, such as ARM TrustZone, that enables execution of a secure application in an untrusted environment. Furthermore, with well-supported, extensible, open-source embedded operating systems like Android allows the manufactures to quickly customize their operating system with device drivers, thus reducing the time-to-market. Unfortunately, the proliferation of device vendors and race to the market has resulted in poor quality device drivers containing critical security vulnerabilities. Furthermore, the patches for these vulnerabilities get merged into the end-products with a significant delay resulting in the Patch Gap, which causes privacy and security of billions of users to be at risk. In this dissertation, I will show how the new architecture features can lead to security issues by introducing new attack vectors. Second, I will show that the existing techniques are inadequate to find the security issues in Linux kernel drivers and how, with certain well-defined optimizations, we can precisely find security issues. Third, I will present my solution to the problem of Patch Gap by showing a principled approach to automatically port patches to vendor product repositories. Finally, I will present our on-going work to automatically port C to Checked C, which provides a low overhead, backward-compatible, and memory-safe C alternative that could be used on resource-constrained modern systems to prevent security vulnerabilities. Through this work, I presented effective ways to find, fix, propagate, and prevent vulnerabilities in modern system software, thus improving modern systems security
GitRDone : enabling fast patch propagation in related software repositories
LAUREA MAGISTRALENonostante gli sforzi degli sviluppatori software, le patch che vengono applicate ad un progetto open-source, sul suo repository principale, non vengono solitamente propagate in maniera rapida anche su tutti i progetti connessi ad esso (ad esempio, su tutte le fork del repository principale). Studi recenti mostrano che la stessa cosa vale anche per le patch di sicurezza, e in questi casi il problema risulta ancora più critico. Per velocizzare la propagazione delle patch di sicurezza sono nati dei database di vulnerabilità (ad esempio, quello contenente le CVE). Tuttavia, le patch che correggono CVE vengono tuttora propagate con un ritardo significativo e, in aggiunta, alcune vulnerabilità non sono presenti nei suddetti database.
In questa ricerca siamo i primi a dare una definizione di patch non dannose. Una patch è non dannosa se preserva le funzionalità originali del programma; in tal caso potrebbe essere applicata ad altri progetti in maniera rapida e senza bisogno di testarne meticolosamente gli effetti. La maggior parte delle patch di sicurezza rientra in questa categoria. In aggiunta, presentiamo una tecnica che può essere utilizzata per identificare patch non dannose e mostriamo i dettagli della progettazione e dello sviluppo di GitRDone: un programma basato sulla suddetta tecnica.
Abbiamo testato GitRDone su 39,191 patch, estratte da 10 differenti repository di progetti kernel, e su 191 patch che correggono CVE su Android e Linux. I risultati mostrano che GitRDone è in grado di identificare patch non dannose con una precisione del 96% e che la maggior parte delle patch che correggono CVE sono non dannose. In aggiunta, GitRDone ha identificato alcune istanze di patch che correggono vulnerabilità per le quali non esistono CVE; 5 di queste sono tuttora presenti, non corrette, in diversi kernel proprietari basati su Linux.Despite the efforts of software maintainers, patches on open-source repositories are propagated from the main codebase to all the related projects (e.g., forks) with a significant delay. Previous work shows that this is true also for security patches, for which it represents a critical problem. Vulnerability databases (e.g., CVEs) were born to speed up the diffusion of critical patches; however, CVE patches are still applied with a delay and some security fixes
lack corresponding CVE entries. Because of this, project maintainers could miss security patches when upgrading software, which is a huge problem.
In this paper we are the first to provide a definition of non-disruptive patches (ndps). An ndp is a patch that should not disrupt the original functionality of the program, meaning that it can be applied with a minimal testing effort; we argue that most of the security fixes fall into this category. Furthermore, we show a technique to identify ndps and implement GitRDone, a tool based on such a technique that works just by analyzing the source code of the original and patched versions of a file.
We run GitRDone on 39,191 patches, spanning over 10 different kernels repositories, and on 191 Android and Linux CVE patches. Results show that it can identify ndps with 96.00% precision and that most of the CVE patches are ndps. In addition, GitRDone identified patches that fix vulnerabilities that lack a CVE; 5 of these are still unpatched in different vendor kernels
POSTCOLONIALISM AS SPATIAL POLITICS IN ARAVIND ADIGA’S THE WHITE TIGER
Abstrak
Fiksi postkolonial memiliki kecenderungan untuk memberikan perlawanan terhadap orang yang dijajah, tetapi hal tersebut tidak sepenuhnya harus diyakini benar adanya, karena adakalanya penulis fiksi post-kolonial belum berhasil menawarkan ruang alternatif bagi yang dijajah. Oleh karena itu, perlu dipikirkan kembali bahwa penulis fiksi postkolonial tidak hanya menawarkan perlawanan tetapi juga kelangsungan proyek kolonial . Dengan teori politik spasial yang meliputi tempat (Place) , ruang (Space), kekacauan (Chaos) , mengganti (Overwrite), dan pasca – ruang (Post-Space) sehingga memunculkan gagasan. Dengan menggunakan salah satu novel karangan Aravind Adiga, The White Tiger . Dengan mengumpulkan serta berdasarkan fakta-fakta yang didapat. Sehingga dapat menggambarkan bagaimana perlawanan dari India pasca dijajah dan bagaimana postkolonialisme digambarkan sebagai politik spasial di dalam novel karya Aravind Adiga yang berjudul The White Tiger . Sehingga, politik spasial dapat ditemukan
Kata Kunci: Fiksi Postkolonial , Resistensi , dan Politik Spasial .
Abstract
Postcolonial fiction has tendency to give the resistance of post colonized people, but it does not have to be trusted at all because sometimes the author of postcolonial fiction fails to offer the alternative space for the post colonized. Therefore, it should be rethought that author of postcolonial fiction is not only offering the resistance but also the continuity of colonial project. With the theory of spatial politics which includes the place, space, chaos, overwrite, and post-space, this suspicion can be made true. One of the novels that can be studied is Aravind Adiga’s The White Tiger. From this can describe the resistance of post colonized Indian and how post colonialism described as spatial politics in Aravind Adiga’s The White Tiger. Therefore, the spatial politics can be truly uncovered.
Keywords: Postcolonial fiction, Resistance, and Spatial politics
An Ecocritical Reading of Aravind Adiga's The White Tiger
Why choose this novel for ecocritical investigation? Connections, that's where an ecocritic begins. Thematically the novel investigates how representations, from the Vedas to 'Sting', connect with, and influence actions in the material world. Extratextually (outside the novel) Aravind Adiga, the author of The White Tiger (2008), was born in Madras, in 1974. And as the target readers for this essay are students situated in Chennai, this novel seems likely to stimulate students' interest because of its author's place connections. On a practical note, a book by an Indiar, author of international fame (the novel won The Man Booker Prize in 2008) is likely to be available in Chennai. In keeping with accessibility for the students, and with the. novel's mischievous use of technology and web connections (see http:// www.whitetiger-technologydrivers.com/) this essay will include: source information from the internet. In addition, Adiga has Australian citizenship, which is where I come in. Connections. Interrelationships. Interdependencies. Ecocriticism, then, encourages connections between regions, histories, cultures, languages and so on, but always, it examines the way in which 'nature' is represented
SmartProvenance
Full text access from Treasures at UT Dallas is restricted to current UTD affiliates (use the provided Link to Article).Blockchain technology has evolved from being an immutable ledger of transactions for cryptocurrencies to a programmable interactive environment for building distributed reliable applications. Although the blockchain technology has been used to address various challenges, to our knowledge none of the previous work focused on using Blockchain to develop a secure and immutable scientific data provenance management framework that automatically verifies the provenance records. In this work, we leverage Blockchain as a platform to facilitate trustworthy data provenance collection, verification, and management. The developed system utilizes smart contracts and open provenance model (OPM) to record immutable data trails. We show that our proposed framework can securely capture and validate provenance data that prevents any malicious modification to the captured data as long as the majority of the participants are honest. ©2018 Copyright held by the owner/author(s). Publication rights licensed to Association for Computing Machinery.The research reported herein was supported in part by NIH award 1R01HG006844, NSF awards CNS-1111529, CICI-1547324, and IIS- 1633331 and ARO award W911NF-17-1-0356.Erik Jonsson School of Engineering and Computer Scienc
- …
