PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

Making our computers more secure

Columbia Engineering researchers design new techniques to bolster memory safety; ideas are now being used by Air Force Research Lab

Making our computers more secure
2021-06-23
(Press-News.org) New York, NY--June 22, 2021--Because corporations and governments rely on computers and the internet to run everything from the electric grid, healthcare, and water systems, computer security is extremely important to all of us. It is increasingly being breached: Numerous security hacks just this past month include the Colonial Pipeline security breach and the JBS Foods ransomware attacks where hackers took over the organization's computer systems and demanded payment to unlock and release it back to the owners. The White House is strongly urging companies to take ransomware threats seriously and update their systems to protect themselves. Yet these attacks continue to threaten all of us on an almost daily basis.

Columbia Engineering researchers who are leading experts in computer security recently presented two major papers that make computer systems more secure at the International Symposium on Computer Architecture (ISCA), the premier forum for new ideas and research results in computer architecture. This new research, which has zero to little effect on system performance, is already being used to create a processor for the Air Force Research Lab.

"Memory safety has been a problem for nearly 40 years and numerous solutions have been proposed. We believe that memory safety continues to be a problem because it does not distribute the burden in a fair manner among software engineers and end-users," said Simha Sethumadhavan, associate professor of computer science, whose research focuses on how computer architecture can be used to improve computer security. "With these two papers, we believe we have found the right balance of burdens."

Computer security has been a long-standing issue, with many proposed systems workable in research settings but not in real-world situations. Sethumadhavan believes that the way to secure a system is to first start with the hardware and then, in turn, the software. The urgency of his research is underscored by the fact that he has significant grants from both the Office of Naval Research and the U.S. Airforce, and his PhD students have received a Qualcomm Innovation Fellowship to create practical security solutions.

Sethumadhavan's group noticed that most security issues occur within a computer's memory, specifically pointers. Pointers are used for managing memory and can lead to memory corruption that can open up the system to hackers who hijack the program. Current techniques to mitigate memory attacks use up a lot of energy and can break software. These methods also greatly affect a system's performance--cellphone batteries drain quickly, apps run slowly, and computers crash.

The team set out to address these issues and created a security solution that protects memory without affecting a system's performance. They call their novel memory security solution, ZeRØ: Zero-Overhead Resilient Operation Under Pointer Integrity Attacks.

ZeRO Overview VIDEO - https://www.youtube.com/watch?v=yoQ4HaQ0Bzc

ZeRO features a set of memory instructions and a metadata encoding scheme that protects the code and data pointers of a system. This combination eliminates performance overhead--it will not affect the speed of a system. ZeRO requires minor changes to a system's architecture and it can easily be added to modern processors. Especially critical is that, even when under attack, ZeRO can perform all these functions and avoid crashing a system.

"Zero offers memory security at no cost and it is a perfect complement to systems that mitigate memory attacks," said Mohamed Tarek, a fourth-year PhD student and co-lead author of the studies. "The keys to widespread adoption of security techniques are low-performance overhead and convenience."

The second paper that Sethumadhavan's team will present, No-FAT: Architectural Support for Low Overhead Memory Safety Checks, is a system that makes security checks faster with only a small--8%--effect on the computer's performance which is 10x faster than current software technique for detecting memory errors. The name is an allusion to no-fat milk, which, as the ads say, "has all the goodness of milk with fewer calories."

No-FAT Overview VIDEO - https://www.youtube.com/watch?v=XDGaYZioJBQ

No-FAT speeds up fuzz testing, a type of automated software testing method, and it is very easy for developers to add it when building a system. The technique builds on a recent trend in software towards binning memory allocators, which uses buckets of different sizes to store memory until it is needed by the software. The researchers found that when binning memory allocation is used by the software, it is possible to achieve memory security with little impact on performance and is compatible with existing software.

Both ZeRO and No-Fat are targeted at beefing up memory systems to be more resilient against attacks while having little to no effect on a computer system's speed or power consumption. The bonus is that with both systems, programmers need to do little to nothing to harden their programs. These ideas could transform how memory safety features are currently supported in processors.

"No-FAT & ZeRO are two major steps toward putting an end to a long-standing problem," said Miguel Arroyo PhD '21, who was a co-lead author of the papers. "Memory safety attacks cost the cyber community millions of dollars. Now we can avoid that and keep everyone's data safe--it's a win-win!"

INFORMATION:

About the Studies

Publication:
Both papers were presented at the International Symposium on Computer Architecture (ISCA), June 16, 2021.

"No-FAT: Architectural Support for Low Overhead Memory Safety Checks"

Authors are: Mohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, Ryan Piersma, and Simha Sethumadhavan Department of Computer Science Columbia Engineering

The study was supported by an Air Force contract FA8750-20-C-0210, an unrestricted gift from Bloomberg, and the Qualcomm Innovation Fellowship.

"ZeRØ: Zero-Overhead Resilient Operation Under Pointer Integrity Attacks"

Authors are: Mohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov, and Simha Sethumadhavan Department of Computer Science, Columbia Engineering

The study was partially supported by FA8750-20-C-0210, a Qualcomm Innovation Fellowship, and a gift from Bloomberg.

Any opinions, findings, conclusions, and recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the US government or commercial entities. Simha Sethumadhavan has a significant financial interest in Chip Scan Inc.

LINKS: Paper: http://www.cs.columbia.edu/~simha/preprint_isca20_zero.pdf DOI: 10.1109/ISCA52012.2021.00082 Paper: http://www.cs.columbia.edu/~simha/preprint_isca20_nofat.pdf DOI: 10.1109/ISCA52012.2021.00076 ZeRO Overview VIDEO - https://www.youtube.com/watch?v=yoQ4HaQ0Bzc No-FAT Overview VIDEO - https://www.youtube.com/watch?v=XDGaYZioJBQ http://engineering.columbia.edu/ https://www.cnn.com/2021/06/03/politics/white-house-open-letter-ransomware-attacks-businesses/index.html https://iscaconf.org/isca2021/ https://www.afrl.af.mil/RI/ http://www.cs.columbia.edu/~simha/ https://www.qualcomm.com/research/research/university-relations/innovation-fellowship/winners https://www.cs.columbia.edu/~mtarek/ https://miguel.arroyo.me/ https://www.youtube.com/watch?v=yoQ4HaQ0Bzc https://www.youtube.com/watch?v=XDGaYZioJBQ https://www.cs.columbia.edu

Columbia Engineering
Columbia Engineering, based in New York City, is one of the top engineering schools in the U.S. and one of the oldest in the nation. Also known as The Fu Foundation School of Engineering and Applied Science, the School expands knowledge and advances technology through the pioneering research of its more than 220 faculty, while educating undergraduate and graduate students in a collaborative environment to become leaders informed by a firm foundation in engineering. The School's faculty are at the center of the University's cross-disciplinary research, contributing to the Data Science Institute, Earth Institute, Zuckerman Mind Brain Behavior Institute, Precision Medicine Initiative, and the Columbia Nano Initiative. Guided by its strategic vision, "Columbia Engineering for Humanity," the School aims to translate ideas into innovations that foster a sustainable, healthy, secure, connected, and creative humanity.


[Attachments] See images for this press release:
Making our computers more secure

ELSE PRESS RELEASES FROM THIS DATE:

Salton Sea aerosol exposure triggers unique and mysterious pulmonary response

Salton Sea aerosol exposure triggers unique and mysterious pulmonary response
2021-06-23
RIVERSIDE, Calif. -- Communities surrounding the Salton Sea, the inland body of water straddling California's Riverside and Imperial counties, show high rates of asthma due, possibly, to high aerosol dust levels resulting from the sea shrinking over time. Scientists suspect, however, the Salton Sea plays an additional role in pulmonary health. A University of California, Riverside study performed on mice has found Salton Sea aerosol turns on nonallergic inflammation genes and may also promote lung inflammation. For comparison, aerosolized fungal allergen (Alternaria) -- a common household fungal allergen -- produces an allergic inflammation in the lungs of mice. "Our ...

Health care leaders call for national focus on preventing hospital-acquired pneumonia

Health care leaders call for national focus on preventing hospital-acquired pneumonia
2021-06-23
A group of health care leaders, including a University of Massachusetts Amherst nurse innovator, has published a national call to action to prevent non-ventilator-associated, hospital-acquired pneumonia (NVHAP). This call to action was developed by a joint task force of key national healthcare stakeholders, including the Centers for Disease Control and Prevention (CDC), the Veterans Health Administration, The Joint Commission on Accreditation of Healthcare Organizations, the American Dental Association, the Patient Safety Movement Foundation, Oral Health Nursing Education and Practice, Teaching Oral-Systemic Health and academia. In a commentary paper published in the journal Infection Control & Hospital Epidemiology (ICHE), the joint ...

Atmospheric water vapor in the city of Tel Aviv is suitable for drinking

Atmospheric water vapor in the city of Tel Aviv is suitable for drinking
2021-06-23
In a first-of-its-kind study in the world conducted at Tel Aviv University, researchers found that water generated from the air in the heart of an urban area, the city of Tel Aviv, complied with all of the strict drinking water standards set both by the State of Israel and by the World Health Organization. The researchers examined the quality of the water produced from the water vapor in the urban atmosphere, which is characterized by industry and massive construction, and found that it was suitable for drinking. The test was performed using a dedicated facility of the Israeli company Watergen, which partnered in the study. The study was conducted by a team of experts from the hydrochemistry laboratory at the Porter ...

Advancing research on environmentally friendly, hydrogen-enriched fuel

2021-06-23
As you drive down the highway, you may notice an increasing number of hybrid and electric vehicles. Alternative energy automobiles are on the rise contributing to the global effort to reduce carbon emissions. As we move together down this road, researchers are looking to determine new solutions to this ongoing problem. Dr. Muzammil Arshad, instructional assistant professor for the Department of Multidisciplinary Engineering at Texas A&M University, and a team of multidisciplinary student researchers conducted a study to analyze the performance of hydrogen-enriched fuel on spark engine performance and efficiency. This solution could make significant contributions to helping automobiles ...

Sound-induced electric fields control the tiniest particles

Sound-induced electric fields control the tiniest particles
2021-06-23
Engineers at Duke University have devised a system for manipulating particles approaching the miniscule 2.5 nanometer diameter of DNA using sound-induced electric fields. Dubbed "acoustoelectronic nanotweezers," the approach provides a label-free, dynamically controllable method of moving and trapping nanoparticles over a large area. The technology holds promise for applications in the fields ranging from condensed matter physics to biomedicine. The research appears online on June 22 in Nature Communications. Precisely controlling nanoparticles is a crucial ...

Foreign-born status, but not acquired US citizenship, protects many immigrants from criminal victimization

2021-06-23
Until recently, data on criminal victimization did not include information on the status--immigrant or citizen--of respondents. In a recent study, researchers used new data that include respondents' status to explore the association between citizenship status and risk of victimization. They found that for many, a person's foreign-born status, but not their acquired U.S. citizenship, protects against criminal victimization. The study, by researchers at the University of Maryland (UMD) at College Park and the Pennsylvania State University (PSU), is forthcoming in Criminology, a publication of the American Society of Criminology. "Understanding how patterns of victimization vary ...

Study provides MIS-C treatment guidance

2021-06-23
New Orleans, LA - An analysis conducted by a group of investigators including Tamara Bradford, MD, Associate Professor of Pediatrics at LSU Health New Orleans School of Medicine, found that children and adolescents with Multisystem inflammatory syndrome in children (MIS-C) initially treated with intravenous immune globulin (IVIG) plus glucocorticoids had a lower risk of new or persistent cardiovascular dysfunction than IVIG alone. The research was part of the Overcoming COVID-19 Study, a nationwide collaboration of physicians at pediatric hospitals and the Centers for Disease ...

Nightside radio could help reveal exoplanet details

Nightside radio could help reveal exoplanet details
2021-06-23
HOUSTON - (June 22, 2021) - We can't detect them yet, but radio signals from distant solar systems could provide valuable information about the characteristics of their planets. A paper by Rice University scientists describes a way to better determine which exoplanets are most likely to produce detectable signals based on magnetosphere activity on exoplanets' previously discounted nightsides. The study by Rice alumnus Anthony Sciola, who earned his Ph.D. this spring and was mentored by co-author and space plasma physicist Frank Toffoletto, shows that while radio emissions from the daysides of exoplanets appear to max out during high solar activity, those that emerge from the nightside are likely to add significantly to the signal. This interests the exoplanet ...

Parental monitoring and consistency in adolescence can reduce young Black men's likelihood of criminal behavior

2021-06-23
New research examined the effect of different parenting styles during adolescence on crime among African American men. The study found that parenting styles characterized by little behavioral control placed youth at significant risk for adult crime, even though some of those styles included high levels of nurturance. In contrast, youth whose parents monitored them, were consistent in their parenting, and had high levels of behavioral control were at lowest risk for adult crime. The study, by researchers at the University of Georgia and Mississippi State University, is forthcoming in Criminology, a publication of the American Society of Criminology. "We examined parenting styles rather than parenting ...

WVU research finds 'excess deaths' in Amish and Mennonite communities during pandemic

WVU research finds excess deaths in Amish and Mennonite communities during pandemic
2021-06-23
MORGANTOWN, W.Va. - Sunday church service in Amish country is more than just belting out hymns, reading Bible passages and returning home an hour later to catch a football game or nap. It's an all-day affair: A host family welcomes church members - between 20 to 40 families - into their home to worship and have fellowship with one another from morning to night. Church is a biweekly activity; each gathering takes place in a member's home and is a key ritual in the Amish community which values in-person communication. New research from West Virginia University sociologists suggests this face-to-face interaction, coupled with a distrust ...

LAST 30 PRESS RELEASES:

U of T researchers discover compounds produced by gut bacteria that can treat inflammation

Aligned peptide ‘noodles’ could enable lab-grown biological tissues

Law fails victims of financial abuse from their partner, research warns

Mental health first-aid training may enhance mental health support in prison settings

Tweaking isotopes sheds light on promising approach to engineer semiconductors

How E. coli get the power to cause urinary tract infections

Quantifying U.S. health impacts from gas stoves

Physics confirms that the enemy of your enemy is, indeed, your friend

Stony coral tissue loss disease is shifting the ecological balance of Caribbean reefs

Newly discovered mechanism of T-cell control can interfere with cancer immunotherapies

Wistar scientists discover new immunosuppressive mechanism in brain cancer

ADA Forsyth ranks number 1 on the East Coast in oral health research

The American Ornithological Society (AOS) names Judit Szabo as new Ornithological Applications editor-in-chief

Catheter-directed mechanical thrombectomy system demonstrates safety and effectiveness in patients with pulmonary embolism

Novel thrombectomy system demonstrates positive safety and feasibility results in treating acute pulmonary embolism

Biomimetic transcatheter aortic heart valve offers new option for aortic stenosis patients

SMART trial reaffirms hemodynamic superiority of TAVR self-expanding valve in aortic stenosis patients with a small annulus over time and regardless of age

Metastatic prostate cancer research: PSMAfore follow-on study favors radioligand therapy over change to androgen receptor pathway inhibition

Studies highlight need for tailored treatment options for women with peripheral artery disease

Women and Black patients less likely to receive catheter-based treatment for pulmonary embolism

Pilot program improves well-being of families during advanced care planning

The key role of Galectin-3 in brain tumour development

Announcing Junevity as Tier 3 Sponsor of ARDD 2024

Climate change amplifies severity of combined wind-rain extremes over the UK and Ireland

Exeter announces new £3.4 million global funding for solutions to antifungal drug resistance

In medieval England, leprosy spread between red squirrels and people, genome evidence shows

Source of pregnancy complications from infections revealed by placenta map

Lepra in the middle ages: New insights on transmission pathways through squirrels

The Foundational Questions Institute, FQxI, appoints Pinar Emirdag to Board of Directors

Stretchable e-skin could give robots human-level touch sensitivity

[Press-News.org] Making our computers more secure
Columbia Engineering researchers design new techniques to bolster memory safety; ideas are now being used by Air Force Research Lab