课题基金 / 基金详情

CAREER: A Multi-Level Approach to Malicious Mobile Code Detection

CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
职业生涯:恶意移动代码检测的多层次方法
批准号:
0238492
负责人:
Giovanni Vigna
金额:
$39.99万
依托单位国家:
美国
项目类别:
Continuing grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-07-01 至 2010-06-30

项目摘要

项目成果

Giovanni Vigna的其他基金

相似基金

相关文献

中文摘要
翻译
移动代码可以定义为传输到远程环境并在那里自动执行的可执行内容。通过分析与代码执行相关的信息并识别恶意行为,可以检测来自恶意移动代码的攻击。这种分析过程被称为入侵检测,而收集必要信息的过程被称为审计。遗憾的是,大多数支持代码移动性的系统没有提供审计机制,或者只能产生关于移动代码活动的不完整信息。该方法依赖于移动代码执行体系结构的不同组件的插装,以收集有关移动代码操作的完整信息。在不同抽象级别收集的事件被用作多数据流入侵检测分析的输入。入侵检测过程使用融合和关联技术来检测攻击并执行主动响应程序,以限制攻击的影响。特别是,这项研究的重点是遏制蠕虫应用程序的传播。这项研究的结果将用于改造现有系统和保护未来的应用程序。特别是,在不久的将来,移动代码将成为移动设备升级和管理的基本机制,因为IP连接将带给今天使用的数百万蜂窝电话。多级入侵检测的使用将提供保护基础设施和用户终端免受恶意移动代码攻击的技术。
英文摘要
Mobile code can be defined as executable content that is transferred to aremote environment and executed there automatically. Attacks from maliciousmobile code can be detected by analyzing the information associated with theexecution of code and identifying malicious behavior. This analysis process iscalled intrusion detection while the process of collecting the necessaryinformation is called auditing.Unfortunately, most systems that support code mobility provide no auditingmechanisms or are able to produce only incomplete information about theactivity of mobile code.To overcome these problems, a multi-level approach to malicious mobile codedetection is proposed. The approach relies on the instrumentation of thedifferent components of the mobile code execution architecture to gathercomplete information about the actions of the mobile code. The eventscollected at different abstraction levels are used as input to multi-streamintrusion detection analysis. The intrusion detection process uses both fusionand correlation techniques to detect attacks and perform proactive responseprocedures that limit the impact of an attack. In particular, the researchfocuses on the containment of the spread of worm applications.The results of this research will be used both to retrofit existing systemsand to secure future applications. In particular, in the near future mobilecode will become a fundamental mechanism for the upgrade and management ofmobile devices, as IP connectivity is brought to the millions of cellularphones in use today. The use of multi-level intrusion detection will providetechniques to protect both the infrastructure and the user terminals againstmalicious mobile code.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
AI Institute for Agent-based Cyber Threat Intelligence and Operation
  • 批准号:
    2229876
  • 项目类别:
    Cooperative Agreement
  • 资助金额:
    $1999.42万
  • 财政年份:
    2023
  • 负责人:
    Giovanni Vigna
  • 依托单位:
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
国内基金
海外基金
基于Multi-Pass Cell的高功率皮秒激光脉冲非线性压缩关键技术研究
Multi-decadeurbansubsidencemonitoringwithmulti-temporaryPStechnique
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    80万元
  • 批准年份:
    2022
  • 负责人:
    Timo Balz
  • 依托单位:
High-precision force-reflected bilateral teleoperation of multi-DOF hydraulic robotic manipulators
  • 批准号:
    52111530069
  • 项目类别:
    国际(地区)合作与交流项目
  • 资助金额:
    10万元
  • 批准年份:
    2021
  • 负责人:
    徐兵
  • 依托单位:
大地电磁强噪音压制的Multi-RRMC技术及其在青藏高原东南缘-印支块体地壳流追踪中的应用