Collaborative Research: CT-ISG: Modeling and Measuring Botnets
合作研究:CT-ISG:僵尸网络建模和测量
基本信息
- 批准号:0627477
- 负责人:
- 金额:$ 17.5万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2006
- 资助国家:美国
- 起止时间:2006-09-01 至 2009-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
"A botnet is a network of compromised computers, or bots, commandeered by an adversarial botmaster. Botnets are responsible for many attacks, including spam, phishing, key logging, and denial of service. This project aims to develop techniques to model and measure botnet propagation and on-line population dynamics. Knowing the trend, size, and locations of the population of a botnet can help estimate the potential threat of a botnet, and select and prioritize the appropriate response actions.Although Internet worms are often used to create botnets, there is fundamental difference between them. Worms are typically designed to infect as many machines as possible, and are in general "noisy" and easily detected (and thus removed); whereas botnets are designed to evade detection, and control and make use of the compromised machines for as long as possible. The existing worm models focus on the initial/short propagation phase of a worm. But a good botnet model needs to track the dynamics of botnet online population in the long run.This project has three main tasks. The first is to develop diurnal models to track the grow-and-decline trend of botnet on-line population using factors such as time zones and distribution of vulnerable systems. The second is to develop sampling and measurement approaches including capture-and-recapture and DNS cache snooping to estimate the total population of a botnet. The third is to develop measures for threat assessment, e.g., its aggregated bandwidth and resilience to response, based on the system, location and topology information of the bots."
“僵尸网络是由敌对的僵尸主机控制的受感染计算机或机器人组成的网络。僵尸网络负责许多攻击,包括垃圾邮件、网络钓鱼、密钥记录和拒绝服务。这个项目的目的是开发技术来模拟和测量僵尸网络的传播和在线人口动态。了解僵尸网络人口的趋势、规模和位置可以帮助估计僵尸网络的潜在威胁,并选择适当的响应行动并确定优先级。虽然互联网蠕虫经常被用来创建僵尸网络,但它们之间有根本的区别。蠕虫通常被设计成感染尽可能多的机器,通常是“嘈杂的”,很容易被发现(因此被清除);而僵尸网络的设计目的是逃避检测,并尽可能长时间地控制和利用受感染的机器。现有的蠕虫模型关注的是蠕虫的初始/短传播阶段。但是一个好的僵尸网络模型需要长期跟踪僵尸网络在线人口的动态。这个项目有三个主要任务。首先,利用时区和易受攻击系统分布等因素,建立僵尸网络在线人口增长和下降趋势的日模型。第二是开发采样和测量方法,包括捕获和重新捕获和DNS缓存窥探,以估计僵尸网络的总数。第三是制定威胁评估措施,例如,基于机器人的系统、位置和拓扑信息,其聚合带宽和响应弹性。”
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Wenke Lee其他文献
Security in Mobile Ad-Hoc Networks
移动自组织网络的安全性
- DOI:
10.1007/0-387-22690-7_9 - 发表时间:
2005 - 期刊:
- 影响因子:0
- 作者:
Yongguang Zhang;Wenke Lee - 通讯作者:
Wenke Lee
Connected Colors: Unveiling the Structure of Criminal Networks
连接的颜色:揭示犯罪网络的结构
- DOI:
10.1007/978-3-642-41284-4_20 - 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Yacin Nadji;M. Antonakakis;R. Perdisci;Wenke Lee - 通讯作者:
Wenke Lee
Principled reasoning and practical applications of alert fusion in intrusion detection systems
入侵检测系统中警报融合的原理推理和实际应用
- DOI:
10.1145/1368310.1368332 - 发表时间:
2008 - 期刊:
- 影响因子:10.4
- 作者:
G. Gu;A. Cárdenas;Wenke Lee - 通讯作者:
Wenke Lee
Beheading hydras: performing effective botnet takedowns
斩首九头蛇:有效摧毁僵尸网络
- DOI:
- 发表时间:
2013 - 期刊:
- 影响因子:0
- 作者:
Yacin Nadji;M. Antonakakis;R. Perdisci;D. Dagon;Wenke Lee - 通讯作者:
Wenke Lee
Wenke Lee的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Wenke Lee', 18)}}的其他基金
2015 Cyber Security Education Workshop
2015年网络安全教育研讨会
- 批准号:
1544099 - 财政年份:2015
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Automated Reverse Engineering of Commodity Software
TWC:媒介:协作:商品软件的自动逆向工程
- 批准号:
1409807 - 财政年份:2014
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
TWC SBE: TTP Option: Medium: Collaborative: EPICA: Empowering People to Overcome Information Controls and Attacks
TWC SBE:TTP 选项:中:协作:EPICA:赋予人们克服信息控制和攻击的能力
- 批准号:
1409635 - 财政年份:2014
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
EAGER: The Conceptual Landscape of Information Manipulation
EAGER:信息操纵的概念图景
- 批准号:
1255453 - 财政年份:2012
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
TC: Small: A Foundational and Practical Platform for Host Security Applications
TC:小型:主机安全应用程序的基础实用平台
- 批准号:
1017265 - 财政年份:2010
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
合作研究:CT-L:CLEANSE:跨层大规模有效分析网络活动以保护互联网安全
- 批准号:
0831300 - 财政年份:2008
- 资助金额:
$ 17.5万 - 项目类别:
Continuing Grant
Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
协作研究:CT-T:实时且知情的恶意软件执行的逻辑和数据流提取
- 批准号:
0716570 - 财政年份:2007
- 资助金额:
$ 17.5万 - 项目类别:
Continuing Grant
Intrusion Detection Techniques for Mobile Ad Hoc Networks
移动自组织网络的入侵检测技术
- 批准号:
0311024 - 财政年份:2003
- 资助金额:
$ 17.5万 - 项目类别:
Continuing Grant
CAREER: Adaptive Intrusion Detection Systems
职业:自适应入侵检测系统
- 批准号:
0133629 - 财政年份:2002
- 资助金额:
$ 17.5万 - 项目类别:
Continuing Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: Districts Helping Districts: Scaling Inclusive CT Pathways
合作研究:地区帮助地区:扩大包容性 CT 路径
- 批准号:
2219350 - 财政年份:2022
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
Collaborative Research: Districts Helping Districts: Scaling Inclusive CT Pathways
合作研究:地区帮助地区:扩大包容性 CT 路径
- 批准号:
2219351 - 财政年份:2022
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
Collaborative Research: Uncovering the Multiscale Determinants of Atypical Femoral Fracture using MRI and CT-Based Modeling
合作研究:利用 MRI 和 CT 建模揭示非典型股骨骨折的多尺度决定因素
- 批准号:
2025923 - 财政年份:2020
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
Collaborative Research: Uncovering the Multiscale Determinants of Atypical Femoral Fracture using MRI and CT-Based Modeling
合作研究:利用 MRI 和 CT 建模揭示非典型股骨骨折的多尺度决定因素
- 批准号:
2026906 - 财政年份:2020
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
RAPID: Collaborative Research: Independent Component Analysis Inspired Statistical Neural Networks for 3D CT Scan Based Edge Screening of COVID-19
RAPID:协作研究:独立成分分析启发的统计神经网络,用于基于 3D CT 扫描的 COVID-19 边缘筛查
- 批准号:
2027539 - 财政年份:2020
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
Collaborative research: A histological and CT study of midfacial growth trajectories in subadult primates
合作研究:亚成年灵长类动物中面部生长轨迹的组织学和 CT 研究
- 批准号:
1728263 - 财政年份:2016
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
Collaborative Research: Iodine-enhanced micro-CT Imaging: Repeated Measures Design to Improve Visualization of Vertebrate Soft-tissue Anatomy
合作研究:碘增强显微 CT 成像:重复测量设计以改善脊椎动物软组织解剖学的可视化
- 批准号:
1450850 - 财政年份:2015
- 资助金额:
$ 17.5万 - 项目类别:
Continuing Grant
Collaborative Research: Iodine-enhanced micro-CT Imaging: Repeated Measures Design to Improve Visualization of Vertebrate Soft-tissue Anatomy
合作研究:碘增强显微 CT 成像:重复测量设计以改善脊椎动物软组织解剖学的可视化
- 批准号:
1450842 - 财政年份:2015
- 资助金额:
$ 17.5万 - 项目类别:
Continuing Grant
CT-ISG: Collaborative Research: Towards Trustworthy Database Systems
CT-ISG:协作研究:迈向可信赖的数据库系统
- 批准号:
1243971 - 财政年份:2012
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
Collaborative research: A histological and CT study of midfacial growth trajectories in subadult primates
合作研究:亚成年灵长类动物中面部生长轨迹的组织学和 CT 研究
- 批准号:
1231350 - 财政年份:2012
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant