课题基金 / 基金详情

Collaborative Research: CT-T: Towards Behavior-Based Malware Detection

Collaborative Research: CT-T: Towards Behavior-Based Malware Detection
合作研究:CT-T:迈向基于行为的恶意软件检测
批准号:
0627501
负责人:
Somesh Jha
金额:
$57.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2007
资助国家:
美国
项目状态:
已结题
起止时间:
2007-01-01 至 2011-12-31

项目摘要

项目成果

Somesh Jha的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Somesh JhaUniversity of Wisconsin, MadisonCollaborative Research: CT T Towards Behavior-Based Malware Detection0627501Panel P060975AbstractMalware is code with malicious intent that can adversely affect thehost on which it executes or the network over which they aretransmitted. A malware detector classifies a program as malware orbenign. Malware writers continuously test the limitations of malwaredetectors in an attempt to discover techniques to evadedetection. This leads to an arms race, where malware writers find newways to create malware that are undetected by commercial malwaredetectors, and where researchers working on malware detection respondby devising new detection techniques. Attackers create new malwareusing two main approaches: program obfuscation and evolution. There isstrong evidence that malware writers are using obfuscation andevolution because the number of new malware families is growing at amuch slower rate than the number of malware instances. For example,according to Symantec threat reports, in the first half of 2005 therewere 10,866 new virus and worm variants but only 170 new families ofmalware. This data also indicates that signature-based techniques formalware detection will not be able to cope with the increase in thenumber of malware instances. Recent results by one of the PIs alsosuggests that current commercial malware detectors are not resilientto obfuscation and evolution techniques used by malware writers. Allthis evidence clearly suggests that we need a new approach to malwaredetection.We propose to explore behavior-based malware detection: our algorithmfocuses on detecting malicious behavior (such as mass-mailing behaviorused by certain worms) rather than searching for syntacticpatterns. We specify malicious behavior in a formal language and thenperform static analysis on the code to determine whether it containsthe specified behavior. Prior work by the investigators demonstratedthat this behavior-based malware detector can detect families ofmalware using a single specification. However, there are challengesthat need to be addressed in the context of behavior-based malwaredetection. We propose tasks to address these challenges. Solutions tothe proposed tasks will lead to malware detection techniques that willresist evasion techniques used by malware writers better than existingmalware detectors. Behavior-based malware detectors can also detectnew malware that are variants of old malware..
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Collaborative: User-Centered Deployment of Differential Privacy
  • 批准号:
    1931364
  • 项目类别:
    Standard Grant
  • 资助金额:
    $7.67万
  • 财政年份:
    2020
  • 负责人:
    Somesh Jha
  • 依托单位:
SaTC: CORE: Frontier: Collaborative: End-to-End Trustworthiness of Machine-Learning Systems
  • 批准号:
    1804648
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $69.55万
  • 财政年份:
    2018
  • 负责人:
    Somesh Jha
  • 依托单位:
FMitF: Collaborative Research: Formal Methods for Machine Learning System Design
  • 批准号:
    1836978
  • 项目类别:
    Standard Grant
  • 资助金额:
    $40.6万
  • 财政年份:
    2018
  • 负责人:
    Somesh Jha
  • 依托单位:
TWC: Medium: Collaborative: Scaling and Prioritizing Market-Sized Application Analysis
  • 批准号:
    1563831
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $59.97万
  • 财政年份:
    2016
  • 负责人:
    Somesh Jha
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)