课题基金 / 基金详情

CT: Automatic Generation of High-Quality Attack Signatures and Patches

CT: Automatic Generation of High-Quality Attack Signatures and Patches
CT:自动生成高质量的攻击签名和补丁
批准号:
0627672
负责人:
Tzi-Cker Chiueh
金额:
$38.45万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-09-01 至 2012-08-31

项目摘要

项目成果

Tzi-Cker Chiueh的其他基金

相似基金

相关文献

中文摘要
翻译
高质量攻击特征和补丁的自动生成Tzi-CherChiueh State University of纽约,Stony BrookAbstract全面的网络攻击防御应该包括(1)攻击检测组件,可以确定网络应用程序是否已经受到危害并防止攻击进一步蔓延,(二)攻击识别组件,其可以识别对应的攻击分组并生成相关联的攻击签名,以便防止这样的攻击(3)攻击修复组件,可以将受损应用程序的状态恢复到攻击前的状态,并允许其正常继续,如果可能的话,永久消除被利用的漏洞。该项目旨在构建一个名为DIRA的程序转换系统,该系统可以自动嵌入到网络应用程序中,以抵御控制劫持攻击,这些攻击允许远程攻击者劫持远程程序并最终劫持其底层系统。控制权劫持攻击是近年来许多网络蠕虫的主要攻击手段,包括缓冲区溢出、整数溢出和格式字符串攻击等。给定一个网络应用程序的源代码或二进制代码,DIRA可以将其转换为这样一种方式,即生成的程序可以自动检测任何传入的控制劫持攻击,修复攻击留下的内存损坏,导出相应的攻击签名并相应地通知前端防火墙,并创建一个永久的补丁来密封被利用的安全漏洞,所有这些都不需要对操作系统或硬件进行任何修改。为了将这些安全增强程序转换技术扩展到商业分发的Win32/X86二进制文件,DIRA项目将开发一种新的二进制分析和仪器基础设施,使用静态和动态反汇编的组合。
英文摘要
Automatic Generation of High-Quality Attack Signatures and PatchesTzi-CherChiuehState University of New York, Stony BrookAbstract A comprehensive cyber attack defense should include (1) an attack detection component that can determine if a network application has been compromised and prevent the attack from further spreading, (2) an attack identification component that can identify the corresponding attack packets and generate the associated attack signatures so as to prevent such attacks from taking place in the future, and (3) an attack repair component that can restore the compromised application's state to that before the attack and allow it to continue normally, and if possible permanently eliminate the vulnerability being exploited. This project aims to build a program transformation system called DIRA that can automatically embed into network applications a comprehensive cyber defense against control-hijacking attacks, which allow remote attackers to hijack a remote program and eventually its underlying system. Control-hijacking attacks have been used as building blocks for many recent Internet worms, and include such attacks as buffer overflow, integer overflow and format string attacks. Given a network application's source or binary code, DIRA can convert it in such a way that the resulting program can automatically detect any incoming control-hijacking attack, repair the memory damage left by the attack, derive the corresponding attack signature and inform the front-end firewall accordingly, and create a permanent patch that seals the security hole being exploited, all without requiring any modifications to the operating system or hardware. To extend these security-enhancing program transformation techniques to commercially distributed Win32/X86 binaries, the DIRA project will develop a novel binary analysis and instrumentation infrastructure using a combination of static and dynamic disassembling.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CRI: IAD A Miniaturized Robotic Testbed for Development, Testing, and Evaluation of Protocols for Multi-Hop Wireless Networks
  • 批准号:
    0751121
  • 项目类别:
    Standard Grant
  • 资助金额:
    $15.0万
  • 财政年份:
    2008
  • 负责人:
    Tzi-Cker Chiueh
  • 依托单位:
Quality of Service Guarantee for Scalable Parallel Storage Systems
  • 批准号:
    0621512
  • 项目类别:
    Standard Grant
  • 资助金额:
    $38.49万
  • 财政年份:
    2006
  • 负责人:
    Tzi-Cker Chiueh
  • 依托单位:
Design Techniques for Repairable Data Systems
  • 批准号:
    0410694
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2004
  • 负责人:
    Tzi-Cker Chiueh
  • 依托单位:
NeTS-ProWiN: Implementation Techniques for Last-Mile Wireless Mesh Networks
  • 批准号:
    0435373
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2004
  • 负责人:
    Tzi-Cker Chiueh
  • 依托单位:
海外基金