서브메뉴
검색
Emulation-Based Security Measurement with Applications in Avionics, Redaction, and Industrial Control
Emulation-Based Security Measurement with Applications in Avionics, Redaction, and Industrial Control
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20260209102851
- ISBN
- 9798291564103
- DDC
- 004
- 저자명
- Bland, Maxwell.
- 서명/저자
- Emulation-Based Security Measurement with Applications in Avionics, Redaction, and Industrial Control
- 발행사항
- [Sl] : University of Illinois at Urbana-Champaign, 2023
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2023
- 형태사항
- 119 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 87-02, Section: A.
- 주기사항
- Advisor: Levchenko, Kirill.
- 학위논문주기
- Thesis (Ph.D.)--University of Illinois at Urbana-Champaign, 2023.
- 초록/해제
- 요약The safety of critical systems and data is of paramount importance to society. Attacks on these systems can have catastrophic consequences, and the security of these systems is often difficult to measure. Existing methods often involve access to an operating version of the system, such as a physical device or executable specification, to provide ground-truth. However, access to a complete representation of the system is not always possible or practical. In this dissertation, we explore the use of emulation to measure the security of systems in the absence of this ground-truth information.Complex system emulation often requires sophisticated approaches to digital forensics and tactics for navigating undecidability resulting from uncertainty of the system's state. To address these challenges, we present intelligent guess-and-check strategies for deducing hidden information in executable code in the absence of original source code or other auxiliary information. Our core technical contributions are (1) the first symbolic execution based firmware rehosting system, used to generate emulations of embedded systems. (2) A novel system for the analysis and recovery of glyph positioning information in PDF documents. This system was used to recover redacted text information where the characters were removed in hundreds of sensitive documents. (3) A logic-based intermediate representation and framework for the extraction of lifted function summaries from binary firmware. This framework makes existing verification and synthesis techniques applicable to real-world systems by translating implemented code to mathematical models. Where appropriate, we justify our strategies through discussions of correctness, precision, and generalizability. Our results are never theoretical: we apply them to pre-existing, empirically validatable domain rather than models: among others, we study the Communication Management Unit used in Boeing 737 Aircraft, historically important redacted documents, and a programmable logic controller operating a Tennessee Eastman chemical plant reactor pressure valve.
- 일반주제명
- Computer science
- 일반주제명
- Logic
- 일반주제명
- Information science
- 키워드
- Security
- 키워드
- Privacy
- 키워드
- Redactions
- 키워드
- Avionics
- 키워드
- Emulation
- 키워드
- Rehosting
- 키워드
- Lifting
- 기타저자
- University of Illinois at Urbana-Champaign Computer Science
- 기본자료저록
- Dissertations Abstracts International. 87-02A.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260203s2023 us c eng d■001000017365899
■00520260209102851
■006m o d
■007cr#unu||||||||
■020 ▼a9798291564103
■035 ▼a(MiAaPQ)AAI32271394
■035 ▼a(MiAaPQ)httphdlhandlenet2142121481
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a004
■1001 ▼aBland, Maxwell.
■24510▼aEmulation-Based Security Measurement with Applications in Avionics, Redaction, and Industrial Control
■260 ▼a[Sl]▼bUniversity of Illinois at Urbana-Champaign▼c2023
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2023
■300 ▼a119 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 87-02, Section: A.
■500 ▼aAdvisor: Levchenko, Kirill.
■5021 ▼aThesis (Ph.D.)--University of Illinois at Urbana-Champaign, 2023.
■520 ▼aThe safety of critical systems and data is of paramount importance to society. Attacks on these systems can have catastrophic consequences, and the security of these systems is often difficult to measure. Existing methods often involve access to an operating version of the system, such as a physical device or executable specification, to provide ground-truth. However, access to a complete representation of the system is not always possible or practical. In this dissertation, we explore the use of emulation to measure the security of systems in the absence of this ground-truth information.Complex system emulation often requires sophisticated approaches to digital forensics and tactics for navigating undecidability resulting from uncertainty of the system's state. To address these challenges, we present intelligent guess-and-check strategies for deducing hidden information in executable code in the absence of original source code or other auxiliary information. Our core technical contributions are (1) the first symbolic execution based firmware rehosting system, used to generate emulations of embedded systems. (2) A novel system for the analysis and recovery of glyph positioning information in PDF documents. This system was used to recover redacted text information where the characters were removed in hundreds of sensitive documents. (3) A logic-based intermediate representation and framework for the extraction of lifted function summaries from binary firmware. This framework makes existing verification and synthesis techniques applicable to real-world systems by translating implemented code to mathematical models. Where appropriate, we justify our strategies through discussions of correctness, precision, and generalizability. Our results are never theoretical: we apply them to pre-existing, empirically validatable domain rather than models: among others, we study the Communication Management Unit used in Boeing 737 Aircraft, historically important redacted documents, and a programmable logic controller operating a Tennessee Eastman chemical plant reactor pressure valve.
■590 ▼aSchool code: 0090.
■650 4▼aComputer science
■650 4▼aLogic
■650 4▼aInformation science
■653 ▼aSecurity
■653 ▼aPrivacy
■653 ▼aRedactions
■653 ▼aAvionics
■653 ▼aEmulation
■653 ▼aIndustrial control
■653 ▼aRehosting
■653 ▼aInformation leaks
■653 ▼aLifting
■690 ▼a0984
■690 ▼a0800
■690 ▼a0723
■690 ▼a0395
■71020▼aUniversity of Illinois at Urbana-Champaign▼bComputer Science.
■7730 ▼tDissertations Abstracts International▼g87-02A.
■790 ▼a0090
■791 ▼aPh.D.
■792 ▼a2023
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17365899▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


