课题基金 / 基金详情

CT-T: Using Structural and Behavioral Models to Detect Malware

CT-T: Using Structural and Behavioral Models to Detect Malware
CT-T:使用结构和行为模型检测恶意软件
批准号:
0627783
负责人:
Giovanni Vigna
金额:
$23.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-10-01 至 2008-09-30

项目摘要

项目成果

Giovanni Vigna的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Proposal Number: 0627783PI: Giovanni Vigna Institution: University of California, Santa Barbara Title: Using Structural and Behavioral Models to Detect Malware AbstractIn the past few years, malicious software (malware) has evolved and diversified. Simple viruses that attach to existing programs and require action on behalf of a user to execute have evolved into worms that can infectthousands of hosts and disrupt entire networks. Rootkits and Trojan horses have evolved from simple programs that mimic legitimate applications for malicious purposes into sophisticated software components that operate at the OS kernel level, making it difficult to detect and eradicate them. In addition, completely new types of malware, such as spyware and adware, have emerged.Unfortunately, the evolution of malware has not been matched by a corresponding evolution in defense tools. Most malware detection tools are syntax-based and use relatively simple pattern matching techniques. Thesetechniques can only recognize known malware, and, in addition, they can be easily fooled by sophisticated malware that uses obfuscation and polymorphic techniques.To be able to reliably detect sophisticated malware it is necessary to develop analysis techniques that rely on information other than the syntactic structure of the program. Therefore, this research effort will focus ondeveloping novel binary analysis techniques that use structural and behavioral models to detect sophisticated malware. More precisely, the proposed techniques use a composition of static and dynamic analysis to identify code whose behavior is similar to the behavior of malware such as viruses, worms, spyware programs, or rootkits. This approach will allow one to detect previously unseen malware and identify mutations of known malware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
AI Institute for Agent-based Cyber Threat Intelligence and Operation
  • 批准号:
    2229876
  • 项目类别:
    Cooperative Agreement
  • 资助金额:
    $1999.42万
  • 财政年份:
    2023
  • 负责人:
    Giovanni Vigna
  • 依托单位:
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
国内基金
海外基金
Capture and Release of Droplets Using Advanced Materials for High Technology Applications
  • 批准号:
    52073127
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2020
  • 负责人:
    Alidad Amirfazli
  • 依托单位:
Molecular Interaction Reconstruction of Rheumatoid Arthritis Therapies Using Clinical Data