Collaborative Research: CT-T: Towards Behavior-Based Malware Detection
Collaborative Research: CT-T: Towards Behavior-Based Malware Detection
批准号:
0627734
负责人:
Sanjit Seshia
金额:
$27.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2007
资助国家:
美国
项目状态:
已结题
起止时间:
2007-01-01 至 2011-12-31
中文摘要
加州大学伯克利分校Sanjit Seshia大学协作研究:CT T基于行为的恶意软件检测0627734面板P060975摘要恶意软件是具有恶意的代码,可能对其执行的主机或其传输所通过的网络产生不利影响。恶意软件检测器将程序分类为恶意软件或良性程序。恶意软件编写者不断测试恶意软件检测器的局限性,试图发现逃避检测的技术。这导致了一场军备竞赛,恶意软件编写者找到了新的方法来创建商业恶意软件检测器没有检测到的恶意软件,致力于恶意软件检测的研究人员通过设计新的检测技术来回应。攻击者使用两种主要方法创建新的恶意软件:程序混淆和进化。有强有力的证据表明,恶意软件编写者正在使用混淆和转移,因为新的恶意软件家族的数量增长速度远远慢于恶意软件实例的数量。例如,根据赛门铁克威胁报告,2005年上半年有10,866个新的病毒和蠕虫变种,但只有170个新的恶意软件家族。这些数据还表明,基于签名的形式软件检测技术将无法应对恶意软件实例数量的增加。其中一个PI的最新结果也表明,当前的商业恶意软件检测器对恶意软件编写者使用的混淆和进化技术没有弹性。所有这些证据都清楚地表明,我们需要一种新的恶意软件检测方法。我们建议探索基于行为的恶意软件检测:我们的算法专注于检测恶意行为(如某些蠕虫使用的群发邮件行为),而不是搜索语法模式。我们用一种形式语言指定恶意行为,然后对代码执行静态分析,以确定它是否包含指定的行为。调查人员之前的工作表明,这种基于行为的恶意软件检测器可以使用单一规范检测恶意软件家族。然而,在基于行为的恶意软件检测的背景下,仍有一些挑战需要解决。我们提出了应对这些挑战的任务。对拟议任务的解决方案将导致恶意软件检测技术,这种技术将比现有的恶意软件检测器更好地抵抗恶意软件编写者使用的规避技术。基于行为的恶意软件检测器还可以检测新的恶意软件,这些恶意软件是旧恶意软件的变体。
英文摘要
Sanjit SeshiaUniversity of California, BerkeleyCollaborative Research: CT T Towards Behavior-Based Malware Detection0627734Panel P060975AbstractMalware is code with malicious intent that can adversely affect thehost on which it executes or the network over which they aretransmitted. A malware detector classifies a program as malware orbenign. Malware writers continuously test the limitations of malwaredetectors in an attempt to discover techniques to evadedetection. This leads to an arms race, where malware writers find newways to create malware that are undetected by commercial malwaredetectors, and where researchers working on malware detection respondby devising new detection techniques. Attackers create new malwareusing two main approaches: program obfuscation and evolution. There isstrong evidence that malware writers are using obfuscation andevolution because the number of new malware families is growing at amuch slower rate than the number of malware instances. For example,according to Symantec threat reports, in the first half of 2005 therewere 10,866 new virus and worm variants but only 170 new families ofmalware. This data also indicates that signature-based techniques formalware detection will not be able to cope with the increase in thenumber of malware instances. Recent results by one of the PIs alsosuggests that current commercial malware detectors are not resilientto obfuscation and evolution techniques used by malware writers. Allthis evidence clearly suggests that we need a new approach to malwaredetection.We propose to explore behavior-based malware detection: our algorithmfocuses on detecting malicious behavior (such as mass-mailing behaviorused by certain worms) rather than searching for syntacticpatterns. We specify malicious behavior in a formal language and thenperform static analysis on the code to determine whether it containsthe specified behavior. Prior work by the investigators demonstratedthat this behavior-based malware detector can detect families ofmalware using a single specification. However, there are challengesthat need to be addressed in the context of behavior-based malwaredetection. We propose tasks to address these challenges. Solutions tothe proposed tasks will lead to malware detection techniques that willresist evasion techniques used by malware writers better than existingmalware detectors. Behavior-based malware detectors can also detectnew malware that are variants of old malware..
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
POSE: Phase II: An Open-Source Ecosystem for Scenic
-
批准号:2303564
-
项目类别:Standard Grant
-
资助金额:$150.0万
-
财政年份:2023
-
负责人:Sanjit Seshia
-
依托单位:
FMitF: Collaborative Research: Formal Methods for Machine Learning System Design
-
批准号:1837132
-
项目类别:Standard Grant
-
资助金额:$29.4万
-
财政年份:2018
-
负责人:Sanjit Seshia
-
依托单位:
CPS: Breakthrough: Control Improvisation for Cyber-Physical Systems
-
批准号:1646208
-
项目类别:Standard Grant
-
资助金额:$42.5万
-
财政年份:2017
-
负责人:Sanjit Seshia
-
依托单位:
I-Corps: VeriSight CPS: Enhancing the Design and Operation of Cyber-Physical Systems with Verified Insight
-
批准号:1628832
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2016
-
负责人:Sanjit Seshia
-
依托单位:
CPS: Frontier: Collaborative Research: VeHICaL: Verified Human Interfaces, Control, and Learning for Semi-Autonomous Systems
-
批准号:1545126
-
项目类别:Continuing Grant
-
资助金额:$359.0万
-
财政年份:2016
-
负责人:Sanjit Seshia
-
依托单位:
STARSS: Small: Collaborative: Specification and Verification for Secure Hardware
-
批准号:1528108
-
项目类别:Standard Grant
-
资助金额:$14.67万
-
财政年份:2015
-
负责人:Sanjit Seshia
-
依托单位:
Collaborative Research: Expeditions in Computer Augmented Program Engineering (ExCAPE): Harnessing Synthesis for Software Design
-
批准号:1139138
-
项目类别:Continuing Grant
-
资助金额:$225.0万
-
财政年份:2012
-
负责人:Sanjit Seshia
-
依托单位:
SHF: CSR: Small: Integrated Design and Verification of High-Confidence Interactive Systems
-
批准号:1116993
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2011
-
负责人:Sanjit Seshia
-
依托单位:
CAREER: Robust Reactive Systems through Verification and Learning
-
批准号:0644436
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2007
-
负责人:Sanjit Seshia
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: