CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
批准号:
0238492
负责人:
Giovanni Vigna
金额:
$39.99万
依托单位国家:
美国
项目类别:
Continuing grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-07-01 至 2010-06-30
中文摘要
移动代码可以定义为传输到远程环境并在那里自动执行的可执行内容。通过分析与代码执行相关的信息并识别恶意行为,可以检测来自恶意移动代码的攻击。这种分析过程被称为入侵检测,而收集必要信息的过程被称为审计。遗憾的是,大多数支持代码移动性的系统没有提供审计机制,或者只能产生关于移动代码活动的不完整信息。该方法依赖于移动代码执行体系结构的不同组件的插装,以收集有关移动代码操作的完整信息。在不同抽象级别收集的事件被用作多数据流入侵检测分析的输入。入侵检测过程使用融合和关联技术来检测攻击并执行主动响应程序,以限制攻击的影响。特别是,这项研究的重点是遏制蠕虫应用程序的传播。这项研究的结果将用于改造现有系统和保护未来的应用程序。特别是,在不久的将来,移动代码将成为移动设备升级和管理的基本机制,因为IP连接将带给今天使用的数百万蜂窝电话。多级入侵检测的使用将提供保护基础设施和用户终端免受恶意移动代码攻击的技术。
英文摘要
Mobile code can be defined as executable content that is transferred to aremote environment and executed there automatically. Attacks from maliciousmobile code can be detected by analyzing the information associated with theexecution of code and identifying malicious behavior. This analysis process iscalled intrusion detection while the process of collecting the necessaryinformation is called auditing.Unfortunately, most systems that support code mobility provide no auditingmechanisms or are able to produce only incomplete information about theactivity of mobile code.To overcome these problems, a multi-level approach to malicious mobile codedetection is proposed. The approach relies on the instrumentation of thedifferent components of the mobile code execution architecture to gathercomplete information about the actions of the mobile code. The eventscollected at different abstraction levels are used as input to multi-streamintrusion detection analysis. The intrusion detection process uses both fusionand correlation techniques to detect attacks and perform proactive responseprocedures that limit the impact of an attack. In particular, the researchfocuses on the containment of the spread of worm applications.The results of this research will be used both to retrofit existing systemsand to secure future applications. In particular, in the near future mobilecode will become a fundamental mechanism for the upgrade and management ofmobile devices, as IP connectivity is brought to the millions of cellularphones in use today. The use of multi-level intrusion detection will providetechniques to protect both the infrastructure and the user terminals againstmalicious mobile code.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
AI Institute for Agent-based Cyber Threat Intelligence and Operation
-
批准号:2229876
-
项目类别:Cooperative Agreement
-
资助金额:$1999.42万
-
财政年份:2023
-
负责人:Giovanni Vigna
-
依托单位:
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
-
批准号:1704253
-
项目类别:Continuing Grant
-
资助金额:$110.16万
-
财政年份:2017
-
负责人:Giovanni Vigna
-
依托单位:
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
-
批准号:1623246
-
项目类别:Standard Grant
-
资助金额:$14.54万
-
财政年份:2016
-
负责人:Giovanni Vigna
-
依托单位:
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
-
批准号:1408632
-
项目类别:Standard Grant
-
资助金额:$106.61万
-
财政年份:2014
-
负责人:Giovanni Vigna
-
依托单位:
Organization of Grand Challenges in Cyber Security
-
批准号:0939188
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2009
-
负责人:Giovanni Vigna
-
依托单位:
SGER: Grand Challenges in Cyber Security
-
批准号:0820907
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2008
-
负责人:Giovanni Vigna
-
依托单位:
CT-ER: A Framework for Live Security Exercises and Challenges
-
批准号:0716753
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Modeling and Analyzing Trust in Service-Oriented Architectures
-
批准号:0716095
-
项目类别:Standard Grant
-
资助金额:$85.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Using Structural and Behavioral Models to Detect Malware
-
批准号:0627783
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2006
-
负责人:Giovanni Vigna
-
依托单位:
CT-ISG: Multi-Model Anomaly Detection for Web-Based Applications
-
批准号:0524853
-
项目类别:Continuing grant
-
资助金额:$45.0万
-
财政年份:2005
-
负责人:Giovanni Vigna
-
依托单位:
Collaborative Research: MASSA: Mobile Agent System Security Through Analysis
-
批准号:0209065
-
项目类别:Continuing grant
-
资助金额:$23.01万
-
财政年份:2002
-
负责人:Giovanni Vigna
-
依托单位:
国内基金
海外基金
登录
查看更多内容
基于Multi-Pass Cell的高功率皮秒激光脉冲非线性压缩关键技术研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:宋贾俊
-
依托单位:
Multi-decadeurbansubsidencemonitoringwithmulti-temporaryPStechnique
-
批准号:--
-
项目类别:--
-
资助金额:80万元
-
批准年份:2022
-
负责人:Timo Balz
-
依托单位:
High-precision force-reflected bilateral teleoperation of multi-DOF hydraulic robotic manipulators
-
批准号:52111530069
-
项目类别:国际(地区)合作与交流项目
-
资助金额:10万元
-
批准年份:2021
-
负责人:徐兵
-
依托单位:
大地电磁强噪音压制的Multi-RRMC技术及其在青藏高原东南缘-印支块体地壳流追踪中的应用
-
批准号:--
-
项目类别:--
-
资助金额:15万元
-
批准年份:2021
-
负责人:白登海
-
依托单位:
基于8色荧光标记的Multi-InDel复合检测体系在降解混合检材鉴定的应用研究
-
批准号:82101976
-
项目类别:青年科学基金项目(C类)
-
资助金额:30.0万元
-
批准年份:2021
-
负责人:李介男
-
依托单位:
大规模非确定图数据分析及其Multi-Accelerator并行系统架构研究
-
批准号:62002350
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:张珩
-
依托单位:
3D multi-parameters CEST联合DKI对椎间盘退变机制中微环境微结构改变的定量研究
-
批准号:82001782
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:李丽
-
依托单位:
基于multi-SNP标记及不拆分策略的复杂混合样本身份溯源研究
-
批准号:--
-
项目类别:面上项目
-
资助金额:56万元
-
批准年份:2020
-
负责人:张素华
-
依托单位:
高速Multi-bit/cycle SAR ADC性能优化理论研究
-
批准号:62004023
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:庄浩宇
-
依托单位:
大地电磁强噪音压制的Multi-RRMC技术及其在青藏高原东南缘—印支块体地壳流追踪中的应用
-
批准号:--
-
项目类别:国际(地区)合作与交流项目
-
资助金额:--
-
批准年份:2020
-
负责人:白登海
-
依托单位: