• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

On a secure software execution environment

Research Project

Project/Area Number 16300003
Research Category

Grant-in-Aid for Scientific Research (B)

Allocation TypeSingle-year Grants
Section一般
Research Field Software
Research InstitutionUniversity of Tsukuba

Principal Investigator

KATO Kazuhiko  University of Tsukuba, Graduate School of System and Information Engineering, Professor, 大学院システム情報工学研究科, 教授 (90224493)

Project Period (FY) 2004 – 2006
Project Status Completed (Fiscal Year 2006)
Budget Amount *help
¥14,800,000 (Direct Cost: ¥14,800,000)
Fiscal Year 2006: ¥4,600,000 (Direct Cost: ¥4,600,000)
Fiscal Year 2005: ¥4,900,000 (Direct Cost: ¥4,900,000)
Fiscal Year 2004: ¥5,300,000 (Direct Cost: ¥5,300,000)
KeywordsComputer Security / System Software / Reference Monitor / Sandbox / Intrusion Detection System / Virtual Private Server / UNIX / ptrace / オペレーティングシステム / IS / ミドルウェア / セキュリティ / 仮想計算環境 / PKI / アクセス制御 / 暗号技術 / IDS / ファイルシステム
Research Abstract

As open network environments become popular, the number of security incidents through attacks on vulnerabilities in software, which are often exploited through e-mail attachments with carefully-crafted communication messages and data files, is increasing. Many researchers and research institutes have been making efforts to prevent such security incidents. The objective of this research is to advance security enhancement techniques when using software with possible vulnerabilities by improving and combining existing approaches. In this research, we particularly focus on security systems that are utilized during runtime of software, including intrusion detection systems and sandboxing systems.
With regards to intrusion detection systems, we proposed and developed a novel scheme to build a behavioral model of software. Our proposed model has both characteristics of a vector-based model and a network-based model. Regarding sandboxing systems, we developed a scheme to introduce access contro … More l functionalities into the sandboxing environment and also developed a virtual private server system based on our sandboxing technique.
As well as advancing individual security systems, we also made efforts to realize a framework that enables the combination of multiple security systems. Runtime security systems, including intrusion detection systems and sandboxing systems, use a functional capability called 'reference monitor,' which is provided by popular operating systems. Reference monitors enable a program to control execution states of another program, as well as to give access to memory space allocated to the monitored program. However, such functional capabilities in existing operating systems do not allow multiple programs to monitor a single process at one time. This prevents one to combine multiple security systems simultaneously, for example, both intrusion detection systems and sandboxing systems. Therefore, in this research, we proposed and developed a scheme to enable such combinations through virtualizing the reference monitor interface. This virtualization is realized by re-forwarding signal messages from operating system to monitoring programs. Less

Report

(4 results)
  • 2006 Annual Research Report   Final Research Report Summary
  • 2005 Annual Research Report
  • 2004 Annual Research Report
  • Research Products

    (39 results)

All 2007 2006 2005 2004

All Journal Article (39 results)

  • [Journal Article] リファレンスモニタの多重化法の提案2007

    • Author(s)
      川崎仁嗣
    • Journal Title

      情報処理学会研究報告 Vol. 2007 No. 10

      Pages: 49-56

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Anomaly Detection Using Integration Model of Vector Space and Network Representation2007

    • Author(s)
      Mizuki Oka
    • Journal Title

      IPSJ Journal Vol. 48 No. 6

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] A proposal for the method of nested reference monitor2007

    • Author(s)
      Satoshi Kawasaki
    • Journal Title

      IPSJ SIG Technical Reports Vol. 2007, No. 10

      Pages: 49-56

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Anomaly Detection Using Integration Model of Vector Space and Network Representation2007

    • Author(s)
      Mizuki Oka
    • Journal Title

      IPSJ Journal Vol. 48, No. 6

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] リファレンスモニタの多重化法の提案2007

    • Author(s)
      川崎仁嗣, 鈴木勝博, 阿部洋丈, 加藤和彦
    • Journal Title

      情報処理学会研究報告 Vol.2007 No.10

      Pages: 49-56

    • NAID

      110006203225

    • Related Report
      2006 Annual Research Report
  • [Journal Article] Anomaly Detection Using Integration Model of Vector Space and Network Representation2007

    • Author(s)
      Mizuki Oka, Kazuhiko Kato
    • Journal Title

      IPSJ Journal(採録決定) Vol.48 No.6

    • NAID

      130000058270

    • Related Report
      2006 Annual Research Report
  • [Journal Article] Virtual Machine Streaming and its Applications2006

    • Author(s)
      Richard Potter
    • Journal Title

      情報処理学会第101回システムソフトウェアとオペレーティング・システム研究会 Vol. 2006 No. 15

      Pages: 1-8

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] インターネットを介した協調作業のためのファイル同期システム2006

    • Author(s)
      塚田 大
    • Journal Title

      日本ソフトウェア科学会第9回プログラミングおよび応用のシステムに関するワークショップ

      Pages: 8-8

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary 2005 Annual Research Report
  • [Journal Article] Virtual Machine Streaming and its Applications2006

    • Author(s)
      Richard Potter
    • Journal Title

      IPSJ SIG Technical Reports Vol. 2006, No. 15

      Pages: 1-8

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] A File Synchronization System for Cooperative Work via the Internet2006

    • Author(s)
      Hiroshi Tsukada
    • Journal Title

      The 9th JSSST SIGSYS Workshop on Systems for Programming and Applications

      Pages: 8-8

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Virtual Machine Streaming and its Applications2006

    • Author(s)
      Richard Potter
    • Journal Title

      情報処理学会第101回システムソフトウェアとオペレーティング・システム研究会 Vol.2006 NO.15

      Pages: 1-8

    • Related Report
      2005 Annual Research Report
  • [Journal Article] General Virtual Hosting via Lightweight User-mode Virtualization2005

    • Author(s)
      Peter Suranyi
    • Journal Title

      The 2005 International Symposium on Applications and the Internet

      Pages: 229-236

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Aerie : WWWのための完全分散型プロキシ2005

    • Author(s)
      阿部 洋丈
    • Journal Title

      情報処理学会論文誌 : コンピューティングシステム Vol. 46 No. SIG 3

      Pages: 51-61

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Sustainable Serviceの実現構想2005

    • Author(s)
      鈴木 与範
    • Journal Title

      情報処理学会研究報告 Vol. 2005 No. 48

      Pages: 9-14

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] インターネットを介した協調作業のためのファイル同期システム2005

    • Author(s)
      塚田 大
    • Journal Title

      情報処理学会研究報告 Vol. 2005 No. 79

      Pages: 33-40

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] System Support for Software Updates on Virtual Private Servers2005

    • Author(s)
      Peter Suranyi
    • Journal Title

      情報処理学会コンピュータシステム・シンポジウム論文集 Vol. 2005 No. 18

      Pages: 21-28

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] General Virtual Hosting via Lightweight User-mode Virtualization2005

    • Author(s)
      Peter Surany
    • Journal Title

      The 2005 International Symposium on Applications and the Internet

      Pages: 229-236

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Aerie : Fully Distributed Anonymizing Proxy for WWW2005

    • Author(s)
      Hirotake Abe
    • Journal Title

      IPSJ Transactions on Advanced Computing Systems Vol.46, No. SIG 3

      Pages: 51-61

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] A Plan of Realizing Sustainable Service2005

    • Author(s)
      Tomonori Suzuki
    • Journal Title

      IPSJ SIG Technical Reports Vol.2005 No.48

      Pages: 9-14

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] A File Synchronization System for Cooperative Work via the Internet2005

    • Author(s)
      Hiroshi Tsukada
    • Journal Title

      IPSJ SIG Technical Reports Vol.2005, No.79

      Pages: 33-40

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] System Support for Software Updates on Virtual Private Servers2005

    • Author(s)
      Peter Suranyi
    • Journal Title

      IPSJ Symposium Series Vol. 2005, No. 18

      Pages: 21-28

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] System support for Software Updates on Virtual Private Servers2005

    • Author(s)
      Peter Suranyi
    • Journal Title

      情報処理学会コンピュータシステムシンポジウム論文集 Vol.2005 No.18

      Pages: 21-28

    • Related Report
      2005 Annual Research Report
  • [Journal Article] インターネットを介した協調作業のためのファイル同期システム2005

    • Author(s)
      塚田 大
    • Journal Title

      情報処理学会研究報告 Vol.2005 No.79

      Pages: 33-40

    • Related Report
      2005 Annual Research Report
  • [Journal Article] Sustainable Serviceの実現構想2005

    • Author(s)
      鈴木 与範
    • Journal Title

      情報処理学会研究報告 Vol.2005 No.48

      Pages: 9-14

    • Related Report
      2005 Annual Research Report
  • [Journal Article] Aerie:WWWのための完全分散型プロキシ2005

    • Author(s)
      阿部 洋丈
    • Journal Title

      情報処理学会論文誌:コンピューティングシステム Vol.46 No.SIG 3

      Pages: 51-61

    • Related Report
      2004 Annual Research Report
  • [Journal Article] General Virtual Hosting via Lightweight User-mode Virtualization2005

    • Author(s)
      P.Suranyi
    • Journal Title

      The 2005 International Symposium on Applications and the Internet

    • Related Report
      2004 Annual Research Report
  • [Journal Article] ソフトウェア流通実行システムSoftwarePotにおけるアクセス制御機構の実現2004

    • Author(s)
      中村 理
    • Journal Title

      情報処理学会コンピュータシステム・シンポジウム論文集 Vol. 2004 No. 13

      Pages: 65-74

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] 静的解析に基づく侵入検知システムの最適化2004

    • Author(s)
      阿部 洋丈
    • Journal Title

      情報処理学会 : コンピューティングシステム Vol. 45 No. SIG 3

      Pages: 11-20

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Eigen Co-occurrence Matrix (ECM) : 時系列データからの多層ネットワーク特徴抽出手法の提案2004

    • Author(s)
      岡 瑞起
    • Journal Title

      日本データベース学会Letters DBSJ Letters Vol. 3 No. 2

      Pages: 9-12

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Extracting Features of Patients using the Eigen Co-occurrence Matrix Algorithm2004

    • Author(s)
      Mizuki Oka
    • Journal Title

      In Proc. of ECML/PKDD Discovery Challenge 2004

      Pages: 86-97

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Anomaly Detection Using Layered Networks Based on Eigen Co-occurrence Matrix2004

    • Author(s)
      Mizuki Oka
    • Journal Title

      Proc. of Seventh International Symposium on Recent Advances in Intrusion Detection (RAID) LNCS-3224

      Pages: 229-236

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Realization of Access Control in the Software Pot Secure Software Circulation System2004

    • Author(s)
      Osamu Nakamura
    • Journal Title

      IPSJ Symposium Series. Vol.2004, No. 13

      Pages: 65-74

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Optimization of Intrusion Detection System Based on Static Analyses2004

    • Author(s)
      Hirotake Abe
    • Journal Title

      IPSJ Transactions on Advanced Computing Systems Vol. 45, No. SIG 3

      Pages: 11-20

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Eigen Co-occurrence Matrix (ECM) Method for Extracting Features of Sequential Data as Layered Networks2004

    • Author(s)
      Mizuki Oka
    • Journal Title

      The Database Society of Japan Letters DBSJ Letters Vol. 3, No. 2

      Pages: 9-12

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2006 Final Research Report Summary
  • [Journal Article] Anomaly Detection Using Layered Networks Based on Eigen Co-occurrence Matrix2004

    • Author(s)
      M.Oka
    • Journal Title

      Proc.of Seventh International Symposium on Recent Advances in Intrusion Detection (RAID) LNCS-3224

      Pages: 223-237

    • Related Report
      2004 Annual Research Report
  • [Journal Article] Extracting Features of Patients using the Eigen Co-occurrence Matrix Algorithm2004

    • Author(s)
      M.Oka
    • Journal Title

      In Proc.of ECML/PKDD Discovery Challenge 2004

      Pages: 86-97

    • Related Report
      2004 Annual Research Report
  • [Journal Article] Eigen Co-occurrence Matrix (ECM):時系列データからの多層ネットワーク特徴抽出手法の提案2004

    • Author(s)
      岡 瑞起
    • Journal Title

      日本データベース学会Letters DBSJ Letters Vol.3、No.2

      Pages: 9-12

    • Related Report
      2004 Annual Research Report
  • [Journal Article] 静的解析に基づく侵入検知システムの最適化2004

    • Author(s)
      阿部 洋丈
    • Journal Title

      情報処理学会:コンピューティングシステム Vol.45 No.SIG 3

      Pages: 11-20

    • Related Report
      2004 Annual Research Report
  • [Journal Article] ソフトウェア流通実行システムSoftwarePotにおけるアクセス制御機構の実現2004

    • Author(s)
      中村 理
    • Journal Title

      情報処理学会コンピュータシステム・シンポジウム論文集 Vol.2004 No.13

      Pages: 65-74

    • Related Report
      2004 Annual Research Report

URL: 

Published: 2004-04-01   Modified: 2016-04-21  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi