Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
协作研究:CT-T:实时且知情的恶意软件执行的逻辑和数据流提取
基本信息
- 批准号:0716612
- 负责人:
- 金额:$ 44万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Continuing Grant
- 财政年份:2007
- 资助国家:美国
- 起止时间:2007-09-01 至 2011-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Malicious activity on the Internet is a significant threat to both individuals and institutions. Over the past few years, network honeypots have emerged as an important tool for measuring and understanding the details of cyber attacks. The objective of the proposed research is to stimulate the development of next generation Internet security systems and forensic tools based on automated, indepth analysis of malicious activity and malicious software (malware) observed in network honeypots. The research program to achieve these capabilities will address four critical challenges: (1) efficient malware collection, (2) identification of evasion and obfuscation techniques embedded in the malware, (3) full understanding of malware intent and logic, and (4) the full exercise of malware functionality during runtime execution. The technical approach to address these challenges, which is referred to as Informed Malware Execution (IME), is comprehensive in its use of techniques drawn from a variety of disciplines including network security, forensic analysis, static and dynamic program analysis, and binary instrumentation. The broader impacts of this project are that it will enable a deep understanding of malware logic and execution, and lead to more effective, generalized (non-instance-specific) network security. The expected results of this work include research papers describing new malware analysis methods, prototype software for malware collection and analysis, and datasets collected from network honeypots. The project also includes education and outreach activities that will develop course materials on practical aspects of network security, and provide training for graduate students involved in all aspects of the research.
互联网上的恶意活动对个人和机构都是一个重大威胁。在过去的几年里,网络蜜罐已经成为衡量和了解网络攻击细节的重要工具。拟议研究的目标是促进下一代互联网安全系统和取证工具的发展,这些系统和取证工具基于对网络蜜罐中观察到的恶意活动和恶意软件(恶意软件)的自动、深入分析。实现这些能力的研究计划将解决四个关键挑战:(1)有效的恶意软件收集,(2)识别恶意软件中嵌入的规避和混淆技术,(3)充分了解恶意软件的意图和逻辑,以及(4)在运行时执行期间充分行使恶意软件功能。解决这些挑战的技术方法被称为知情恶意软件执行(IME),它在使用各种学科的技术方面是全面的,包括网络安全、取证分析、静态和动态程序分析以及二进制工具。此项目的更广泛影响是,它将使您能够深入了解恶意软件的逻辑和执行,并导致更有效、更通用(非实例特定)的网络安全。这项工作的预期结果包括描述新的恶意软件分析方法的研究论文,用于恶意软件收集和分析的原型软件,以及从网络蜜罐收集的数据集。该项目还包括教育和外联活动,这些活动将编写关于网络安全实际方面的课程材料,并为参与研究各个方面的研究生提供培训。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Phillip Porras其他文献
LANTERN: Layered Adaptive Network Telemetry Collection for Programmable Dataplanes
LANTERN:可编程数据平面的分层自适应网络遥测收集
- DOI:
10.1145/3630047.3630194 - 发表时间:
2023 - 期刊:
- 影响因子:0
- 作者:
Kaiyu Hou;Dhiraj Saharia;V. Yegneswaran;Phillip Porras - 通讯作者:
Phillip Porras
Coordinated dataflow protection for ultra-high bandwidth science networks
超高带宽科学网络的协调数据流保护
- DOI:
- 发表时间:
2019 - 期刊:
- 影响因子:0
- 作者:
Vasudevan Nagendra;V. Yegneswaran;Phillip Porras;Samir Ranjan Das - 通讯作者:
Samir Ranjan Das
Phillip Porras的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Phillip Porras', 18)}}的其他基金
NSF Convergence Accelerator Track: G: The Security-Enhanced Radio Access Network (SE-RAN)
NSF 融合加速器轨道:G:安全增强型无线接入网络 (SE-RAN)
- 批准号:
2326882 - 财政年份:2023
- 资助金额:
$ 44万 - 项目类别:
Cooperative Agreement
NSF Convergence Accelerator Track: G: Security Services for the 5G Software-Defined Edge
NSF 融合加速器轨道:G:5G 软件定义边缘的安全服务
- 批准号:
2226443 - 财政年份:2022
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
EAGER: Visualizing Cyber Defense Networks
EAGER:可视化网络防御网络
- 批准号:
1824258 - 财政年份:2018
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Exploring the Transition of Research-Derived Cyber-Threat Data
探索研究衍生的网络威胁数据的转变
- 批准号:
1640386 - 财政年份:2016
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
合作研究:CICI:安全和弹性架构:S3D:用于科学 DMZ 的新的基于 SDN 的安全框架
- 批准号:
1642150 - 财政年份:2016
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
EAGER: ACI: A Software-Defined Network (SDN) WAN Security Testbed
EAGER:ACI:软件定义网络 (SDN) WAN 安全测试平台
- 批准号:
1547206 - 财政年份:2015
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
EAGER: ACI: Secure and Effective Policy Enforcement in Software-Defined WANs
EAGER:ACI:软件定义的 WAN 中安全有效的策略执行
- 批准号:
1446426 - 财政年份:2014
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
TC: Medium: Collaborative Research: Multi-Perspective Bayesian Learning for Automated Diagnosis of Advanced Malware
TC:媒介:协作研究:用于高级恶意软件自动诊断的多视角贝叶斯学习
- 批准号:
0905518 - 财政年份:2009
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
合作研究:CT-L:CLEANSE:跨层大规模有效分析网络活动以保护互联网安全
- 批准号:
0831170 - 财政年份:2008
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: Districts Helping Districts: Scaling Inclusive CT Pathways
合作研究:地区帮助地区:扩大包容性 CT 路径
- 批准号:
2219350 - 财政年份:2022
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Districts Helping Districts: Scaling Inclusive CT Pathways
合作研究:地区帮助地区:扩大包容性 CT 路径
- 批准号:
2219351 - 财政年份:2022
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Uncovering the Multiscale Determinants of Atypical Femoral Fracture using MRI and CT-Based Modeling
合作研究:利用 MRI 和 CT 建模揭示非典型股骨骨折的多尺度决定因素
- 批准号:
2025923 - 财政年份:2020
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Uncovering the Multiscale Determinants of Atypical Femoral Fracture using MRI and CT-Based Modeling
合作研究:利用 MRI 和 CT 建模揭示非典型股骨骨折的多尺度决定因素
- 批准号:
2026906 - 财政年份:2020
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
RAPID: Collaborative Research: Independent Component Analysis Inspired Statistical Neural Networks for 3D CT Scan Based Edge Screening of COVID-19
RAPID:协作研究:独立成分分析启发的统计神经网络,用于基于 3D CT 扫描的 COVID-19 边缘筛查
- 批准号:
2027539 - 财政年份:2020
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative research: A histological and CT study of midfacial growth trajectories in subadult primates
合作研究:亚成年灵长类动物中面部生长轨迹的组织学和 CT 研究
- 批准号:
1728263 - 财政年份:2016
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative Research: Iodine-enhanced micro-CT Imaging: Repeated Measures Design to Improve Visualization of Vertebrate Soft-tissue Anatomy
合作研究:碘增强显微 CT 成像:重复测量设计以改善脊椎动物软组织解剖学的可视化
- 批准号:
1450850 - 财政年份:2015
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
Collaborative Research: Iodine-enhanced micro-CT Imaging: Repeated Measures Design to Improve Visualization of Vertebrate Soft-tissue Anatomy
合作研究:碘增强显微 CT 成像:重复测量设计以改善脊椎动物软组织解剖学的可视化
- 批准号:
1450842 - 财政年份:2015
- 资助金额:
$ 44万 - 项目类别:
Continuing Grant
CT-ISG: Collaborative Research: Towards Trustworthy Database Systems
CT-ISG:协作研究:迈向可信赖的数据库系统
- 批准号:
1243971 - 财政年份:2012
- 资助金额:
$ 44万 - 项目类别:
Standard Grant
Collaborative research: A histological and CT study of midfacial growth trajectories in subadult primates
合作研究:亚成年灵长类动物中面部生长轨迹的组织学和 CT 研究
- 批准号:
1231350 - 财政年份:2012
- 资助金额:
$ 44万 - 项目类别:
Standard Grant