CT-T: Using Structural and Behavioral Models to Detect Malware
CT-T: Using Structural and Behavioral Models to Detect Malware
批准号:
0627783
负责人:
Giovanni Vigna
金额:
$23.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-10-01 至 2008-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Proposal Number: 0627783PI: Giovanni Vigna Institution: University of California, Santa Barbara Title: Using Structural and Behavioral Models to Detect Malware AbstractIn the past few years, malicious software (malware) has evolved and diversified. Simple viruses that attach to existing programs and require action on behalf of a user to execute have evolved into worms that can infectthousands of hosts and disrupt entire networks. Rootkits and Trojan horses have evolved from simple programs that mimic legitimate applications for malicious purposes into sophisticated software components that operate at the OS kernel level, making it difficult to detect and eradicate them. In addition, completely new types of malware, such as spyware and adware, have emerged.Unfortunately, the evolution of malware has not been matched by a corresponding evolution in defense tools. Most malware detection tools are syntax-based and use relatively simple pattern matching techniques. Thesetechniques can only recognize known malware, and, in addition, they can be easily fooled by sophisticated malware that uses obfuscation and polymorphic techniques.To be able to reliably detect sophisticated malware it is necessary to develop analysis techniques that rely on information other than the syntactic structure of the program. Therefore, this research effort will focus ondeveloping novel binary analysis techniques that use structural and behavioral models to detect sophisticated malware. More precisely, the proposed techniques use a composition of static and dynamic analysis to identify code whose behavior is similar to the behavior of malware such as viruses, worms, spyware programs, or rootkits. This approach will allow one to detect previously unseen malware and identify mutations of known malware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
AI Institute for Agent-based Cyber Threat Intelligence and Operation
-
批准号:2229876
-
项目类别:Cooperative Agreement
-
资助金额:$1999.42万
-
财政年份:2023
-
负责人:Giovanni Vigna
-
依托单位:
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
-
批准号:1704253
-
项目类别:Continuing Grant
-
资助金额:$110.16万
-
财政年份:2017
-
负责人:Giovanni Vigna
-
依托单位:
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
-
批准号:1623246
-
项目类别:Standard Grant
-
资助金额:$14.54万
-
财政年份:2016
-
负责人:Giovanni Vigna
-
依托单位:
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
-
批准号:1408632
-
项目类别:Standard Grant
-
资助金额:$106.61万
-
财政年份:2014
-
负责人:Giovanni Vigna
-
依托单位:
Organization of Grand Challenges in Cyber Security
-
批准号:0939188
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2009
-
负责人:Giovanni Vigna
-
依托单位:
SGER: Grand Challenges in Cyber Security
-
批准号:0820907
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2008
-
负责人:Giovanni Vigna
-
依托单位:
CT-ER: A Framework for Live Security Exercises and Challenges
-
批准号:0716753
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Modeling and Analyzing Trust in Service-Oriented Architectures
-
批准号:0716095
-
项目类别:Standard Grant
-
资助金额:$85.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-ISG: Multi-Model Anomaly Detection for Web-Based Applications
-
批准号:0524853
-
项目类别:Continuing grant
-
资助金额:$45.0万
-
财政年份:2005
-
负责人:Giovanni Vigna
-
依托单位:
CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
-
批准号:0238492
-
项目类别:Continuing grant
-
资助金额:$39.99万
-
财政年份:2003
-
负责人:Giovanni Vigna
-
依托单位:
Collaborative Research: MASSA: Mobile Agent System Security Through Analysis
-
批准号:0209065
-
项目类别:Continuing grant
-
资助金额:$23.01万
-
财政年份:2002
-
负责人:Giovanni Vigna
-
依托单位:
国内基金
海外基金
Capture and Release of Droplets Using Advanced Materials for High Technology Applications
-
批准号:52073127
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2020
-
负责人:Alidad Amirfazli
-
依托单位:
Molecular Interaction Reconstruction of Rheumatoid Arthritis Therapies Using Clinical Data
-
批准号:31070748
-
项目类别:面上项目
-
资助金额:34.0万元
-
批准年份:2010
-
负责人:Christine Nardini
-
依托单位: