课题基金 / 基金详情

SBIR Phase I: A New Approach for Effective Detection of Cyber Attacks Based on Anomalous Program Behaviors

SBIR Phase I: A New Approach for Effective Detection of Cyber Attacks Based on Anomalous Program Behaviors
SBIR第一阶段:基于异常程序行为的有效检测网络攻击的新方法
批准号:
0232877
负责人:
Umamaheswari Ganapathy
金额:
$10.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-01-01 至 2003-07-31

项目摘要

项目成果

Umamaheswari Ganapathy的其他基金

相似基金

相关文献

中文摘要
翻译
这个小企业创新研究(SBIR)第一阶段项目的重点是开发一个基于通过有限状态机识别异常系统调用模式的入侵检测系统(IDS)。网络信息系统在发电和配电、交通、商业和国家安全等基础设施中发挥着至关重要的作用。来自CERT协调中心(CERT/CC最初是计算机应急响应小组)的持续安全事件表明,现有的保护系统免受网络攻击的方法是无效的。这些方法几乎只关注以前利用过的漏洞,而不提供任何保护,防止可能利用目标系统上继续存在的无数(尚未发现的)漏洞的攻击。当前的威胁主要是由不熟练的黑客(脚本小子)造成的,而未来的威胁则是网络战争、网络恐怖主义和网络犯罪的迅速升级。在这些情况下,攻击者技术娴熟,有组织,资金充足,可以很快开发出新的攻击类型。因此,迫切需要开发能够防止高技能攻击者发起的未知攻击的方法。在之前在纽约州立大学石溪分校进行的研究中,关键人员开发了一种保护系统免受未知攻击的新方法。Immunet Security的方法基于一种新的算法,该算法使用有限状态自动机模型来学习程序行为,并检测偏离该模型的攻击。该方法已被证明在检测已知和未知攻击方面非常有效,并且比以前的方法产生更少的假警报。本提案旨在将该方法发展成为商业入侵检测系统(IDS)。商业入侵检测系统(IDS)的市场很大,达到数十亿美元,并且正在快速增长。鉴于IDS的市场和国家对安全的高度关注,这项技术提供了比目前存在的更敏感的检测的可能性。
英文摘要
This Small Business Innovation Research (SBIR) Phase I project focuses on the development of an Intrusion Detection System (IDS) based on recognizing anomalous system call patterns via finite state machines. Networked information systems play critical roles in essential infrastructures such as power generation and distribution, transportation, commerce, and national security. The continuing spate of security incidents from the CERT Coordination Center (the CERT/CC was originally the Computer Emergency Response Team) demonstrates that existing approaches for securing systems against cyber attacks are not effective. These approaches are focused almost exclusively on previously exploited vulnerabilities, and offer no protection against attacks that may exploit countless (as-yet-undiscovered) vulnerabilities that continue to exist on the target systems. Whereas current threats are largely attributed to unskilled hackers (script kiddies), the future holds the threat of rapid escalation of cyber-warfare, cyber-terrorism and cyber-crime. Attackers in these cases are highly skilled, organized and well funded, and can develop new kinds of attacks very quickly. Thus there is an urgent need for developing approaches that can protect against unknown attacks launched by highly skilled attackers. In previous research conducted at SUNY, Stony Brook, the key personnel have developed a new approach for securing systems against unknown attacks. Immunet Security's approach is based on a new algorithm for learning program behaviors using finite-state automata models and detecting attacks as deviations from this model. The approach has been show to be very effective in detecting known as well as unknown attacks and produces significantly fewer false alarms than previous approaches. This proposal seeks to develop the approach into a commercial intrusion detection system (IDS). The market for commercial Intrusion Detection Systems (IDS) is large, running into billions of dollars, and is growing fast. Given the market for IDS and the heightened national interest in security, this technology offers the possibility of more sensitive detection than currently exists.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SBIR Phase I: Securing Operating Systems Against Intruder Attacks
国内基金
海外基金
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark Supercooled Phase Transition
  • 批准号:
    24ZR1429700
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    YUICHIRO NAKAI
  • 依托单位:
ATLAS实验探测器Phase 2升级
  • 批准号:
    11961141014
  • 项目类别:
    国际(地区)合作与交流项目
  • 资助金额:
    3350万元
  • 批准年份:
    2019
  • 负责人:
    刘衍文
  • 依托单位:
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
  • 批准号:
    41802035
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    12.0万元
  • 批准年份:
    2018
  • 负责人:
    张里
  • 依托单位:
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究