PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

Making our computers more secure

Columbia Engineering researchers design new techniques to bolster memory safety; ideas are now being used by Air Force Research Lab

Making our computers more secure
2021-06-23
(Press-News.org) New York, NY--June 22, 2021--Because corporations and governments rely on computers and the internet to run everything from the electric grid, healthcare, and water systems, computer security is extremely important to all of us. It is increasingly being breached: Numerous security hacks just this past month include the Colonial Pipeline security breach and the JBS Foods ransomware attacks where hackers took over the organization's computer systems and demanded payment to unlock and release it back to the owners. The White House is strongly urging companies to take ransomware threats seriously and update their systems to protect themselves. Yet these attacks continue to threaten all of us on an almost daily basis.

Columbia Engineering researchers who are leading experts in computer security recently presented two major papers that make computer systems more secure at the International Symposium on Computer Architecture (ISCA), the premier forum for new ideas and research results in computer architecture. This new research, which has zero to little effect on system performance, is already being used to create a processor for the Air Force Research Lab.

"Memory safety has been a problem for nearly 40 years and numerous solutions have been proposed. We believe that memory safety continues to be a problem because it does not distribute the burden in a fair manner among software engineers and end-users," said Simha Sethumadhavan, associate professor of computer science, whose research focuses on how computer architecture can be used to improve computer security. "With these two papers, we believe we have found the right balance of burdens."

Computer security has been a long-standing issue, with many proposed systems workable in research settings but not in real-world situations. Sethumadhavan believes that the way to secure a system is to first start with the hardware and then, in turn, the software. The urgency of his research is underscored by the fact that he has significant grants from both the Office of Naval Research and the U.S. Airforce, and his PhD students have received a Qualcomm Innovation Fellowship to create practical security solutions.

Sethumadhavan's group noticed that most security issues occur within a computer's memory, specifically pointers. Pointers are used for managing memory and can lead to memory corruption that can open up the system to hackers who hijack the program. Current techniques to mitigate memory attacks use up a lot of energy and can break software. These methods also greatly affect a system's performance--cellphone batteries drain quickly, apps run slowly, and computers crash.

The team set out to address these issues and created a security solution that protects memory without affecting a system's performance. They call their novel memory security solution, ZeRØ: Zero-Overhead Resilient Operation Under Pointer Integrity Attacks.

ZeRO Overview VIDEO - https://www.youtube.com/watch?v=yoQ4HaQ0Bzc

ZeRO features a set of memory instructions and a metadata encoding scheme that protects the code and data pointers of a system. This combination eliminates performance overhead--it will not affect the speed of a system. ZeRO requires minor changes to a system's architecture and it can easily be added to modern processors. Especially critical is that, even when under attack, ZeRO can perform all these functions and avoid crashing a system.

"Zero offers memory security at no cost and it is a perfect complement to systems that mitigate memory attacks," said Mohamed Tarek, a fourth-year PhD student and co-lead author of the studies. "The keys to widespread adoption of security techniques are low-performance overhead and convenience."

The second paper that Sethumadhavan's team will present, No-FAT: Architectural Support for Low Overhead Memory Safety Checks, is a system that makes security checks faster with only a small--8%--effect on the computer's performance which is 10x faster than current software technique for detecting memory errors. The name is an allusion to no-fat milk, which, as the ads say, "has all the goodness of milk with fewer calories."

No-FAT Overview VIDEO - https://www.youtube.com/watch?v=XDGaYZioJBQ

No-FAT speeds up fuzz testing, a type of automated software testing method, and it is very easy for developers to add it when building a system. The technique builds on a recent trend in software towards binning memory allocators, which uses buckets of different sizes to store memory until it is needed by the software. The researchers found that when binning memory allocation is used by the software, it is possible to achieve memory security with little impact on performance and is compatible with existing software.

Both ZeRO and No-Fat are targeted at beefing up memory systems to be more resilient against attacks while having little to no effect on a computer system's speed or power consumption. The bonus is that with both systems, programmers need to do little to nothing to harden their programs. These ideas could transform how memory safety features are currently supported in processors.

"No-FAT & ZeRO are two major steps toward putting an end to a long-standing problem," said Miguel Arroyo PhD '21, who was a co-lead author of the papers. "Memory safety attacks cost the cyber community millions of dollars. Now we can avoid that and keep everyone's data safe--it's a win-win!"

INFORMATION:

About the Studies

Publication:
Both papers were presented at the International Symposium on Computer Architecture (ISCA), June 16, 2021.

"No-FAT: Architectural Support for Low Overhead Memory Safety Checks"

Authors are: Mohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Ryan Piersma, and Simha Sethumadhavan Department of Computer Science Columbia Engineering

The study was supported by an Air Force contract FA8750-20-C-0210, an unrestricted gift from Bloomberg, and the Qualcomm Innovation Fellowship.

"ZeRØ: Zero-Overhead Resilient Operation Under Pointer Integrity Attacks"

Authors are: Mohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, and Simha Sethumadhavan Department of Computer Science, Columbia Engineering

The study was partially supported by FA8750-20-C-0210, a Qualcomm Innovation Fellowship, and a gift from Bloomberg.

Any opinions, findings, conclusions, and recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the US government or commercial entities. Simha Sethumadhavan has a significant financial interest in Chip Scan Inc.

LINKS: Paper: http://www.cs.columbia.edu/~simha/preprint_isca20_zero.pdf DOI: 10.1109/ISCA52012.2021.00082 Paper: http://www.cs.columbia.edu/~simha/preprint_isca20_nofat.pdf DOI: 10.1109/ISCA52012.2021.00076 ZeRO Overview VIDEO - https://www.youtube.com/watch?v=yoQ4HaQ0Bzc No-FAT Overview VIDEO - https://www.youtube.com/watch?v=XDGaYZioJBQ http://engineering.columbia.edu/ https://www.cnn.com/2021/06/03/politics/white-house-open-letter-ransomware-attacks-businesses/index.html https://iscaconf.org/isca2021/ https://www.afrl.af.mil/RI/ http://www.cs.columbia.edu/~simha/ https://www.qualcomm.com/research/research/university-relations/innovation-fellowship/winners https://www.cs.columbia.edu/~mtarek/ https://miguel.arroyo.me/ https://www.youtube.com/watch?v=yoQ4HaQ0Bzc https://www.youtube.com/watch?v=XDGaYZioJBQ https://www.cs.columbia.edu

Columbia Engineering
Columbia Engineering, based in New York City, is one of the top engineering schools in the U.S. and one of the oldest in the nation. Also known as The Fu Foundation School of Engineering and Applied Science, the School expands knowledge and advances technology through the pioneering research of its more than 220 faculty, while educating undergraduate and graduate students in a collaborative environment to become leaders informed by a firm foundation in engineering. The School's faculty are at the center of the University's cross-disciplinary research, contributing to the Data Science Institute, Earth Institute, Zuckerman Mind Brain Behavior Institute, Precision Medicine Initiative, and the Columbia Nano Initiative. Guided by its strategic vision, "Columbia Engineering for Humanity," the School aims to translate ideas into innovations that foster a sustainable, healthy, secure, connected, and creative humanity.


[Attachments] See images for this press release:
Making our computers more secure

ELSE PRESS RELEASES FROM THIS DATE:

Salton Sea aerosol exposure triggers unique and mysterious pulmonary response

Salton Sea aerosol exposure triggers unique and mysterious pulmonary response
2021-06-23
RIVERSIDE, Calif. -- Communities surrounding the Salton Sea, the inland body of water straddling California's Riverside and Imperial counties, show high rates of asthma due, possibly, to high aerosol dust levels resulting from the sea shrinking over time. Scientists suspect, however, the Salton Sea plays an additional role in pulmonary health. A University of California, Riverside study performed on mice has found Salton Sea aerosol turns on nonallergic inflammation genes and may also promote lung inflammation. For comparison, aerosolized fungal allergen (Alternaria) -- a common household fungal allergen -- produces an allergic inflammation in the lungs of mice. "Our ...

Health care leaders call for national focus on preventing hospital-acquired pneumonia

Health care leaders call for national focus on preventing hospital-acquired pneumonia
2021-06-23
A group of health care leaders, including a University of Massachusetts Amherst nurse innovator, has published a national call to action to prevent non-ventilator-associated, hospital-acquired pneumonia (NVHAP). This call to action was developed by a joint task force of key national healthcare stakeholders, including the Centers for Disease Control and Prevention (CDC), the Veterans Health Administration, The Joint Commission on Accreditation of Healthcare Organizations, the American Dental Association, the Patient Safety Movement Foundation, Oral Health Nursing Education and Practice, Teaching Oral-Systemic Health and academia. In a commentary paper published in the journal Infection Control & Hospital Epidemiology (ICHE), the joint ...

Atmospheric water vapor in the city of Tel Aviv is suitable for drinking

Atmospheric water vapor in the city of Tel Aviv is suitable for drinking
2021-06-23
In a first-of-its-kind study in the world conducted at Tel Aviv University, researchers found that water generated from the air in the heart of an urban area, the city of Tel Aviv, complied with all of the strict drinking water standards set both by the State of Israel and by the World Health Organization. The researchers examined the quality of the water produced from the water vapor in the urban atmosphere, which is characterized by industry and massive construction, and found that it was suitable for drinking. The test was performed using a dedicated facility of the Israeli company Watergen, which partnered in the study. The study was conducted by a team of experts from the hydrochemistry laboratory at the Porter ...

Advancing research on environmentally friendly, hydrogen-enriched fuel

2021-06-23
As you drive down the highway, you may notice an increasing number of hybrid and electric vehicles. Alternative energy automobiles are on the rise contributing to the global effort to reduce carbon emissions. As we move together down this road, researchers are looking to determine new solutions to this ongoing problem. Dr. Muzammil Arshad, instructional assistant professor for the Department of Multidisciplinary Engineering at Texas A&M University, and a team of multidisciplinary student researchers conducted a study to analyze the performance of hydrogen-enriched fuel on spark engine performance and efficiency. This solution could make significant contributions to helping automobiles ...

Sound-induced electric fields control the tiniest particles

Sound-induced electric fields control the tiniest particles
2021-06-23
Engineers at Duke University have devised a system for manipulating particles approaching the miniscule 2.5 nanometer diameter of DNA using sound-induced electric fields. Dubbed "acoustoelectronic nanotweezers," the approach provides a label-free, dynamically controllable method of moving and trapping nanoparticles over a large area. The technology holds promise for applications in the fields ranging from condensed matter physics to biomedicine. The research appears online on June 22 in Nature Communications. Precisely controlling nanoparticles is a crucial ...

Foreign-born status, but not acquired US citizenship, protects many immigrants from criminal victimization

2021-06-23
Until recently, data on criminal victimization did not include information on the status--immigrant or citizen--of respondents. In a recent study, researchers used new data that include respondents' status to explore the association between citizenship status and risk of victimization. They found that for many, a person's foreign-born status, but not their acquired U.S. citizenship, protects against criminal victimization. The study, by researchers at the University of Maryland (UMD) at College Park and the Pennsylvania State University (PSU), is forthcoming in Criminology, a publication of the American Society of Criminology. "Understanding how patterns of victimization vary ...

Study provides MIS-C treatment guidance

2021-06-23
New Orleans, LA - An analysis conducted by a group of investigators including Tamara Bradford, MD, Associate Professor of Pediatrics at LSU Health New Orleans School of Medicine, found that children and adolescents with Multisystem inflammatory syndrome in children (MIS-C) initially treated with intravenous immune globulin (IVIG) plus glucocorticoids had a lower risk of new or persistent cardiovascular dysfunction than IVIG alone. The research was part of the Overcoming COVID-19 Study, a nationwide collaboration of physicians at pediatric hospitals and the Centers for Disease ...

Nightside radio could help reveal exoplanet details

Nightside radio could help reveal exoplanet details
2021-06-23
HOUSTON - (June 22, 2021) - We can't detect them yet, but radio signals from distant solar systems could provide valuable information about the characteristics of their planets. A paper by Rice University scientists describes a way to better determine which exoplanets are most likely to produce detectable signals based on magnetosphere activity on exoplanets' previously discounted nightsides. The study by Rice alumnus Anthony Sciola, who earned his Ph.D. this spring and was mentored by co-author and space plasma physicist Frank Toffoletto, shows that while radio emissions from the daysides of exoplanets appear to max out during high solar activity, those that emerge from the nightside are likely to add significantly to the signal. This interests the exoplanet ...

Parental monitoring and consistency in adolescence can reduce young Black men's likelihood of criminal behavior

2021-06-23
New research examined the effect of different parenting styles during adolescence on crime among African American men. The study found that parenting styles characterized by little behavioral control placed youth at significant risk for adult crime, even though some of those styles included high levels of nurturance. In contrast, youth whose parents monitored them, were consistent in their parenting, and had high levels of behavioral control were at lowest risk for adult crime. The study, by researchers at the University of Georgia and Mississippi State University, is forthcoming in Criminology, a publication of the American Society of Criminology. "We examined parenting styles rather than parenting ...

WVU research finds 'excess deaths' in Amish and Mennonite communities during pandemic

WVU research finds excess deaths in Amish and Mennonite communities during pandemic
2021-06-23
MORGANTOWN, W.Va. - Sunday church service in Amish country is more than just belting out hymns, reading Bible passages and returning home an hour later to catch a football game or nap. It's an all-day affair: A host family welcomes church members - between 20 to 40 families - into their home to worship and have fellowship with one another from morning to night. Church is a biweekly activity; each gathering takes place in a member's home and is a key ritual in the Amish community which values in-person communication. New research from West Virginia University sociologists suggests this face-to-face interaction, coupled with a distrust ...

LAST 30 PRESS RELEASES:

Exploring factors affecting workers' acquisition of exercise habits using machine learning approaches

Nano-patterned copper oxide sensor for ultra-low hydrogen detection

Maintaining bridge safer; Digital sensing-based monitoring system

A novel approach for the composition design of high-entropy fluorite oxides with low thermal conductivity

A groundbreaking new approach to treating chronic abdominal pain

ECOG-ACRIN appoints seven researchers to scientific committee leadership positions

New model of neuronal circuit provides insight on eye movement

Cooking up a breakthrough: Penn engineers refine lipid nanoparticles for better mRNA therapies

CD Laboratory at Graz University of Technology researches new semiconductor materials

Animal characters can boost young children’s psychological development, study suggests

South Korea completes delivery of ITER vacuum vessel sectors

Global research team develops advanced H5N1 detection kit to tackle avian flu

From food crops to cancer clinics: Lessons in extermination resistance

Scientists develop novel high-fidelity quantum computing gate

Novel detection technology alerts health risks from TNT metabolites

New XR simulator improves pediatric nursing education

New copper metal-organic framework nanozymes enable intelligent food detection

The Lancet: Deeply entrenched racial and geographic health disparities in the USA have increased over the last two decades—as life expectancy gap widens to 20 years

2 MILLION mph galaxy smash-up seen in unprecedented detail

Scientists find a region of the mouse gut tightly regulated by the immune system

How school eligibility influences the spread of infectious diseases: Insights for future outbreaks

UM School of Medicine researchers link snoring to behavioral problems in adolescents without declines in cognition

The Parasaurolophus’ pipes: Modeling the dinosaur’s crest to study its sound #ASA187

St. Jude appoints leading scientist to create groundbreaking Center of Excellence for Structural Cell Biology

Hear this! Transforming health care with speech-to-text technology #ASA187

Exploring the impact of offshore wind on whale deaths #ASA187

Mass General Brigham and BIDMC researchers unveil an AI protein engineer capable of making proteins ‘better, faster, stronger’

Metabolic and bariatric surgery safe and effective for patients with severe obesity

Smarter city planning: MSU researchers use brain activity to predict visits to urban areas

Using the world’s fastest exascale computer, ACM Gordon Bell Prize-winning team presents record-breaking algorithm to advance understanding of chemistry and biology

[Press-News.org] Making our computers more secure
Columbia Engineering researchers design new techniques to bolster memory safety; ideas are now being used by Air Force Research Lab