课题基金 / 基金详情

ITR: Intrusion Detection and Intrusion Prevention Through Dynamic Binary Translation

ITR: Intrusion Detection and Intrusion Prevention Through Dynamic Binary Translation
ITR:通过动态二进制翻译进行入侵检测和入侵防御
批准号:
0219587
负责人:
Darko Stefanovic
金额:
$13.22万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-09-01 至 2005-08-31

项目摘要

项目成果

Darko Stefanovic的其他基金

相似基金

相关文献

中文摘要
翻译
恶意代码对我们的社会构成了重大威胁,我们的社会越来越依赖网络计算机系统进行商业和通信。 恶意软件,包括病毒、蠕虫和特洛伊木马,有可能破坏通信并威胁整个互联网的稳定性。 因此,本研究的目的是分析、检测和缓解恶意代码。 正在对多种类型的恶意代码进行调查,并根据所利用的漏洞和影响进行分组。这使得可以有选择地分别针对每个漏洞利用类别。 以前的恶意代码分析方法依赖于静态逆向工程、受限执行(通过程序语言沙箱)或网络跟踪。 这些方法通常不足以应对日益复杂的恶意代码,这些代码可能会使用运行时加密或动态多态性进行自我修改。 动态恶意代码需要动态工具来分析、检测和缓解。 因此,正在开发允许此类分析的新动态工具,以及允许检测和缓解已知恶意代码类型的安全增强功能。 研究方法是利用运行时二进制翻译来实现透明的代码监控和重写。正在开发基于二进制翻译的软件保证和安全系统的原型实现,并且正在研究该解决方案的有效性及其潜在的部署成本。
英文摘要
Malicious code poses a significant threat to our society, which is becoming increasingly reliant on networked computer systems for commerce and communication. Malicious software, including viruses, worms, and Trojan Horses, has the potential to disrupt communications and threaten the stability of the Internet as a whole. Therefore the objective of this research is analysis, detection, and mitigation of malicious code. The many types of malicious code are being investigated and grouped by exploited vulnerability and effect. This makes it possible selectively to target each exploit class separately. Previous approaches to the analysis of malicious code relied on static reverse engineering, confined execution (via program language sandboxing), or network traces. These approaches are often inadequate for increasingly complex malicious code that may be self-modifying, using run-time encryption or dynamic polymorphism. Dynamic malicious code requires dynamic tools for analysis, detection, and mitigation. Therefore new dynamic tools to permit such analysis are being developed, together with security enhancements to allow detection and mitigation of known malicious code types. The research approach is to use run-time binary translation to achieve transparent code monitoring and rewriting. A prototype implementation of a system for software assurance and security based on binary translation is being developed, and the effectiveness of the solution and its potential deployment cost are being investigated.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Student and Postdoc Travel Support for DNA28
  • 批准号:
    2202396
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.0万
  • 财政年份:
    2022
  • 负责人:
    Darko Stefanovic
  • 依托单位:
SHF: Collaborative Research: Biocompatible I/O Interfaces for Robust Bioorthogonal Molecular Computing
  • 批准号:
    1763718
  • 项目类别:
    Standard Grant
  • 资助金额:
    $20.0万
  • 财政年份:
    2018
  • 负责人:
    Darko Stefanovic
  • 依托单位:
SHF: Large: Collaborative Research: Molecular computing for the real world
  • 批准号:
    1518861
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $93.44万
  • 财政年份:
    2015
  • 负责人:
    Darko Stefanovic
  • 依托单位:
AF: Small: Programmable Nanowalkers:Models and Simulations
  • 批准号:
    1422840
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2014
  • 负责人:
    Darko Stefanovic
  • 依托单位:
海外基金