Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
协作研究:CT-T:实时且知情的恶意软件执行的逻辑和数据流提取
基本信息
- 批准号:0716460
- 负责人:
- 金额:$ 44万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2007
- 资助国家:美国
- 起止时间:2007-09-01 至 2011-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Malicious activity on the Internet is a significant threat to both individuals and institutions. Over the past few years, network honeypots have emerged as an important tool for measuring and understanding the details of cyber attacks. The objective of the proposed research is to stimulate the development of next generation Internet security systems and forensic tools based on automated, indepth analysis of malicious activity and malicious software (malware) observed in network honeypots. The research program to achieve these capabilities will address four critical challenges: (1) efficient malware collection, (2) identification of evasion and obfuscation techniques embedded in the malware, (3) full understanding of malware intent and logic, and (4) the full exercise of malware functionality during runtime execution. The technical approach to address these challenges, which is referred to as Informed Malware Execution (IME), is comprehensive in its use of techniques drawn from a variety of disciplines including network security, forensic analysis, static and dynamic program analysis, and binary instrumentation. The broader impacts of this project are that it will enable a deep understanding of malware logic and execution, and lead to more effective, generalized (non-instance-specific) network security. The expected results of this work include research papers describing new malware analysis methods, prototype software for malware collection and analysis, and datasets collected from network honeypots. The project also includes education and outreach activities that will develop course materials on practical aspects of network security, and provide training for graduate students involved in all aspects of the research.
互联网上的恶意活动是对个人和机构的重大威胁。在过去的几年里,网络蜜罐已经成为衡量和了解网络攻击细节的重要工具。拟议的研究的目的是刺激下一代互联网安全系统和取证工具的发展的基础上,自动化,深入分析的恶意活动和恶意软件(恶意软件)在网络蜜罐观察。实现这些功能的研究计划将解决四个关键挑战:(1)有效的恶意软件收集,(2)识别恶意软件中嵌入的规避和混淆技术,(3)充分理解恶意软件的意图和逻辑,以及(4)在运行时执行期间充分行使恶意软件功能。解决这些挑战的技术方法被称为知情恶意软件执行(IME),它综合使用了来自各种学科的技术,包括网络安全,取证分析,静态和动态程序分析以及二进制插装。该项目的更广泛的影响是,它将使人们能够深入了解恶意软件的逻辑和执行,并导致更有效的,通用的(非特定于实例的)网络安全。这项工作的预期成果包括描述新的恶意软件分析方法的研究论文,用于恶意软件收集和分析的原型软件,以及从网络蜜罐收集的数据集。该项目还包括教育和推广活动,将编制关于网络安全实际方面的课程材料,并为参与研究所有方面的研究生提供培训。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Paul Barford其他文献
Changes in Web client access patterns: Characteristics and caching implications
- DOI:
10.1023/a:1019236319752 - 发表时间:
1999-01-01 - 期刊:
- 影响因子:3.400
- 作者:
Paul Barford;Azer Bestavros;Adam Bradley;Mark Crovella - 通讯作者:
Mark Crovella
POWERPING: MEASURING THE IMPACT OF POWER OUTAGES ON INTERNET HOSTS IN THE US
POWERPING:测量断电对美国互联网主机的影响
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
Scott Anderson;Tucker Bell;Patrick Egan;Nathan Weinshenker;Paul Barford - 通讯作者:
Paul Barford
Homebrew: Optical Polarization Change Detection for Ground Motion Sensing
Homebrew:用于地面运动传感的光学偏振变化检测
- DOI:
10.1364/ofc.2024.m2k.4 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Joe Catudal;Zhenhao Zhou;Weijun Pan;Paul Barford;Dante Fratta;Herbert Wang - 通讯作者:
Herbert Wang
Assessing the Expansion of Ground-Motion Sensing Capability in Smart Cities via Internet Fiber-Optic Infrastructure
评估通过互联网光纤基础设施扩展智慧城市中的地面运动传感能力
- DOI:
10.1785/0220240049 - 发表时间:
2024 - 期刊:
- 影响因子:3.3
- 作者:
Scott Anderson;Erin Cunningham;Paul Barford;Dante Fratta;T. Nissen‐Meyer;Herbert Wang - 通讯作者:
Herbert Wang
Honeynet games: a game theoretic approach to defending network monitors
- DOI:
10.1007/s10878-009-9285-y - 发表时间:
2010-02-03 - 期刊:
- 影响因子:1.100
- 作者:
Jin-Yi Cai;Vinod Yegneswaran;Chris Alfeld;Paul Barford - 通讯作者:
Paul Barford
Paul Barford的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Paul Barford', 18)}}的其他基金
Collaborative Research: IMR: MM-1C: Methods for Active Measurement of the Domain Name System
合作研究:IMR:MM-1C:域名系统主动测量方法
- 批准号:
2319367 - 财政年份:2023
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
Collaborative Research: NeTS: Medium: Large Scale Analysis of Configurations and Management Practices in the Domain Name System
合作研究:NetS:中型:域名系统配置和管理实践的大规模分析
- 批准号:
2312709 - 财政年份:2023
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Conference: on Emerging Research Opportunities at the Intersection of Statistics and Internet Measurement
会议:统计与互联网测量交叉点的新兴研究机会
- 批准号:
2234288 - 财政年份:2022
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: Medium: On the Criticality of the Submarine Cable Network
合作研究:CNS 核心:媒介:论海底电缆网络的重要性
- 批准号:
2106517 - 财政年份:2021
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
EAGER: Internet Measurement Capability for FABRIC
EAGER:FABRIC 的互联网测量能力
- 批准号:
2039146 - 财政年份:2020
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
SaTC: CORE: Large: Collaborative: Investigating the Susceptibility of the Internet Topology to Country-level Connectivity Disruption and Manipulation
SaTC:核心:大型:协作:调查互联网拓扑对国家级连接中断和操纵的敏感性
- 批准号:
1703592 - 财政年份:2017
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
TC: Medium: Collaborative Research: Wide-Aperture Traffic Analysis for Internet Security
TC:媒介:协作研究:互联网安全的大孔径流量分析
- 批准号:
0905186 - 财政年份:2009
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
CT-M: Meta-Environments for Experiments on Diverse Topics in Network Security
CT-M:网络安全不同主题实验的元环境
- 批准号:
0831427 - 财政年份:2008
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
Collaborative Research: CRI: CRD Synthetic Traffic Generation Tools and Resources: A Community Resource for Experimental Networking Research
合作研究:CRI:CRD 综合流量生成工具和资源:实验网络研究的社区资源
- 批准号:
0708828 - 财政年份:2007
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
NeTS-FIND: Design for Manageability in the Next Generation Internet
NeTS-FIND:下一代互联网的可管理性设计
- 批准号:
0627102 - 财政年份:2006
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: Districts Helping Districts: Scaling Inclusive CT Pathways
合作研究:地区帮助地区:扩大包容性 CT 路径
- 批准号:
2219350 - 财政年份:2022
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Districts Helping Districts: Scaling Inclusive CT Pathways
合作研究:地区帮助地区:扩大包容性 CT 路径
- 批准号:
2219351 - 财政年份:2022
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Uncovering the Multiscale Determinants of Atypical Femoral Fracture using MRI and CT-Based Modeling
合作研究:利用 MRI 和 CT 建模揭示非典型股骨骨折的多尺度决定因素
- 批准号:
2025923 - 财政年份:2020
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Uncovering the Multiscale Determinants of Atypical Femoral Fracture using MRI and CT-Based Modeling
合作研究:利用 MRI 和 CT 建模揭示非典型股骨骨折的多尺度决定因素
- 批准号:
2026906 - 财政年份:2020
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
RAPID: Collaborative Research: Independent Component Analysis Inspired Statistical Neural Networks for 3D CT Scan Based Edge Screening of COVID-19
RAPID:协作研究:独立成分分析启发的统计神经网络,用于基于 3D CT 扫描的 COVID-19 边缘筛查
- 批准号:
2027539 - 财政年份:2020
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative research: A histological and CT study of midfacial growth trajectories in subadult primates
合作研究:亚成年灵长类动物中面部生长轨迹的组织学和 CT 研究
- 批准号:
1728263 - 财政年份:2016
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Iodine-enhanced micro-CT Imaging: Repeated Measures Design to Improve Visualization of Vertebrate Soft-tissue Anatomy
合作研究:碘增强显微 CT 成像:重复测量设计以改善脊椎动物软组织解剖学的可视化
- 批准号:
1450850 - 财政年份:2015
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
Collaborative Research: Iodine-enhanced micro-CT Imaging: Repeated Measures Design to Improve Visualization of Vertebrate Soft-tissue Anatomy
合作研究:碘增强显微 CT 成像:重复测量设计以改善脊椎动物软组织解剖学的可视化
- 批准号:
1450842 - 财政年份:2015
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
CT-ISG: Collaborative Research: Towards Trustworthy Database Systems
CT-ISG:协作研究:迈向可信赖的数据库系统
- 批准号:
1243971 - 财政年份:2012
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative research: A histological and CT study of midfacial growth trajectories in subadult primates
合作研究:亚成年灵长类动物中面部生长轨迹的组织学和 CT 研究
- 批准号:
1231350 - 财政年份:2012
- 资助金额:
$ 44万 - 项目类别:
Standard Grant