课题基金 / 基金详情

SBIR Phase I: A New Approach for Effective Detection of Cyber Attacks Based on Anomalous Program Behaviors

SBIR Phase I: A New Approach for Effective Detection of Cyber Attacks Based on Anomalous Program Behaviors
SBIR第一阶段:基于异常程序行为的有效检测网络攻击的新方法
批准号:
0232877
负责人:
Umamaheswari Ganapathy
金额:
$10.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-01-01 至 2003-07-31

项目摘要

项目成果

Umamaheswari Ganapathy的其他基金

相似基金

相关文献

中文摘要
翻译
该小型企业创新研究(SBIR)第一阶段项目专注于开发基于有限状态机识别异常系统调用模式的入侵检测系统(IDS)。网络化信息系统在发电、配电、交通、商业、国家安全等基础设施中发挥着至关重要的作用。应急协调中心(应急协调中心最初是计算机应急小组)接二连三发生的安全事件表明,保护系统免受网络攻击的现有方法并不有效。这些方法几乎完全集中在以前利用的漏洞上,并且不提供针对可能利用目标系统上继续存在的无数(尚未发现的)漏洞的攻击的保护。虽然目前的威胁主要归因于不熟练的黑客(剧本儿童),但未来面临着网络战、网络恐怖主义和网络犯罪迅速升级的威胁。这些案件中的攻击者技术高超、组织严密、资金充足,可以非常迅速地开发出新的攻击类型。因此,迫切需要开发能够防范高技能攻击者发动的未知攻击的方法。在纽约州立大学石溪分校之前进行的研究中,关键人员开发了一种新的方法来保护系统免受未知攻击。免疫安全的方法是基于一种新的算法,该算法使用有限状态自动机模型学习程序行为,并检测偏离该模型的攻击。该方法已被证明在检测已知和未知攻击方面非常有效,并且产生的错误警报比以前的方法要少得多。该提案旨在将该方法发展为商业入侵检测系统(IDS)。商用入侵检测系统(IDS)的市场很大,价值数十亿美元,而且还在快速增长。鉴于入侵检测系统的市场和国家对安全的高度关注,这项技术提供了比目前存在的更灵敏的检测的可能性。
英文摘要
This Small Business Innovation Research (SBIR) Phase I project focuses on the development of an Intrusion Detection System (IDS) based on recognizing anomalous system call patterns via finite state machines. Networked information systems play critical roles in essential infrastructures such as power generation and distribution, transportation, commerce, and national security. The continuing spate of security incidents from the CERT Coordination Center (the CERT/CC was originally the Computer Emergency Response Team) demonstrates that existing approaches for securing systems against cyber attacks are not effective. These approaches are focused almost exclusively on previously exploited vulnerabilities, and offer no protection against attacks that may exploit countless (as-yet-undiscovered) vulnerabilities that continue to exist on the target systems. Whereas current threats are largely attributed to unskilled hackers (script kiddies), the future holds the threat of rapid escalation of cyber-warfare, cyber-terrorism and cyber-crime. Attackers in these cases are highly skilled, organized and well funded, and can develop new kinds of attacks very quickly. Thus there is an urgent need for developing approaches that can protect against unknown attacks launched by highly skilled attackers. In previous research conducted at SUNY, Stony Brook, the key personnel have developed a new approach for securing systems against unknown attacks. Immunet Security's approach is based on a new algorithm for learning program behaviors using finite-state automata models and detecting attacks as deviations from this model. The approach has been show to be very effective in detecting known as well as unknown attacks and produces significantly fewer false alarms than previous approaches. This proposal seeks to develop the approach into a commercial intrusion detection system (IDS). The market for commercial Intrusion Detection Systems (IDS) is large, running into billions of dollars, and is growing fast. Given the market for IDS and the heightened national interest in security, this technology offers the possibility of more sensitive detection than currently exists.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SBIR Phase I: Securing Operating Systems Against Intruder Attacks
国内基金
海外基金
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark Supercooled Phase Transition
  • 批准号:
    24ZR1429700
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    YUICHIRO NAKAI
  • 依托单位:
ATLAS实验探测器Phase 2升级
  • 批准号:
    11961141014
  • 项目类别:
    国际(地区)合作与交流项目
  • 资助金额:
    3350万元
  • 批准年份:
    2019
  • 负责人:
    刘衍文
  • 依托单位:
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
  • 批准号:
    41802035
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    12.0万元
  • 批准年份:
    2018
  • 负责人:
    张里
  • 依托单位:
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究