SBIR Phase II: SAFE: Behavior-based Malware Detection and Prevention
SBIR 第二阶段:SAFE:基于行为的恶意软件检测和预防
基本信息
- 批准号:0750299
- 负责人:
- 金额:--
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2008
- 资助国家:美国
- 起止时间:2008-03-01 至 2011-02-28
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This SBIR Phase II project has the objective of implementing a commercially-competitive, host-based, malware detection and prevention system. During Phase I, a host-based malware detection system that demonstrated the practicality of detecting a malicious process by dynamically monitoring its system events was developed. The prototype called SAFE (Secure Activity Filtering Engine) filters system events using a stateful policy engine whose policies specify malicious behavior and the appropriate response. Because the technology does not rely upon the detection of "signatures" (i.e. patterns of bytes), it can detect previously unseen malware. During Phase II a number of significant enhancements to the policy engine including a checkpoint/rollback capability will be developed. The proposed functionality removes file system and registry changes associated with a process when a policy violation is detected. The ability to delay detection of malicious behavior until detailed system events are observed provides a just-in-time detection capability that increases the accuracy of the detection process while reducing false positives. The SAFE technology has the potential to demonstrate an effective approach to combating at least two of the dominant trends in the threat landscape. One such trend is the crafting of blended threats which use multiple infections vectors like email readers, web browsers, and messaging software to infect a host computer. Another trend is the popularity of "malware toolkits" which can be used by malware writers to quickly generate multiple variants of the same virus. The rapid proliferation of obfuscated variants is a potent threat to traditional signature-based solutions on two fronts: the rate of malware infection may overwhelm efforts to produce signatures to detect these variants and the logarithmic increase in the size of signatures databases reduces the performance of signature scanning. The SAFE technology addresses both of these trends. The stateful policy engine can correlate non simultaneous events across multiple sub systems and processes and thus detect and block blended threats. If successful, the architecture of the proposed system will have the potential to address a myriad of security threats and make a commercially-significant impact.
SBIR二期项目的目标是实现一个具有商业竞争力的、基于主机的恶意软件检测和预防系统。在第一阶段,开发了一个基于主机的恶意软件检测系统,该系统展示了通过动态监控其系统事件来检测恶意进程的实用性。称为SAFE(安全活动过滤引擎)的原型使用有状态策略引擎过滤系统事件,该引擎的策略指定恶意行为和适当的响应。由于该技术不依赖于检测“签名”(即字节模式),因此它可以检测到以前未见过的恶意软件。在第二阶段,将开发对策略引擎的许多重要增强,包括检查点/回滚功能。当检测到策略违反时,建议的功能将删除与进程相关的文件系统和注册表更改。在观察到详细的系统事件之前延迟检测恶意行为的能力提供了实时检测功能,提高了检测过程的准确性,同时减少了误报。SAFE技术有潜力展示一种有效的方法,至少可以对抗威胁领域的两种主要趋势。其中一个趋势是混合威胁,它使用多种感染媒介,如电子邮件阅读器、网络浏览器和消息软件来感染主机。另一个趋势是“恶意软件工具包”的流行,恶意软件编写者可以使用它来快速生成同一病毒的多个变体。混淆变体的快速扩散在两个方面对传统的基于签名的解决方案构成了严重威胁:恶意软件感染的速度可能会超过生成检测这些变体的签名的努力;签名数据库大小的对数增长降低了签名扫描的性能。SAFE技术解决了这两种趋势。有状态策略引擎可以跨多个子系统和进程关联非同步事件,从而检测和阻止混合威胁。如果成功,所提议的系统架构将有可能解决无数的安全威胁,并产生重大的商业影响。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Hao Wang其他文献
A Three-Transistor Energy Management Circuit for Energy-Harvesting-Powered IoT Devices
用于能量收集供电的物联网设备的三晶体管能量管理电路
- DOI:
10.1109/jiot.2023.3289091 - 发表时间:
2024 - 期刊:
- 影响因子:10.6
- 作者:
Li Teng;Hao Wang;Yu Liu;Minfan Fu;Junrui Liang - 通讯作者:
Junrui Liang
Influence of the feedback links of connected and automated vehicle on rear-end collision risks with vehicle-to-vehicle communication
通过车对车通信,联网和自动驾驶车辆的反馈链路对追尾碰撞风险的影响
- DOI:
10.1080/15389588.2018.1527469 - 发表时间:
2019-01 - 期刊:
- 影响因子:2
- 作者:
Yanyan Qin;Hao Wang - 通讯作者:
Hao Wang
Lithium Fluoride Assisted Preparation of High-Performance All-Inorganic CsPbI3 Perovskite Solar Cells
氟化锂辅助制备高性能全无机CsPbI3钙钛矿太阳能电池
- DOI:
- 发表时间:
2022 - 期刊:
- 影响因子:0
- 作者:
Jin Huang;Kewang Shi;Chunyang Chen;Hao Wang;Shengzhong Liu - 通讯作者:
Shengzhong Liu
Simultaneously Homogenized Electric Field and Ionic Flux for Reversible Ultrahigh-Areal-Capacity Li Deposition
同时均匀化电场和离子通量用于可逆超高面积容量锂沉积
- DOI:
10.1021/acs.nanolett.0c00797 - 发表时间:
2020 - 期刊:
- 影响因子:10.8
- 作者:
Lihan Zhang;Xiaoguang Yin;Sibo Shen;Yang Liu;Tong Li;Hao Wang;Xiaohui Lv;Xianying Qin;Sum Wai Chiang;Yongzhu Fu;Feiyu Kang;Baohua Li - 通讯作者:
Baohua Li
Male spiders avoid sexual cannibalism with a catapult mechanism
雄性蜘蛛通过弹射机制避免性同类相食
- DOI:
10.1016/j.cub.2022.03.051 - 发表时间:
2022-04 - 期刊:
- 影响因子:9.2
- 作者:
Shichang Zhang;Yangjié Liu;Yubing Ma;Hao Wang;Yao Zhao;Matjaž Kuntner;Daiqin Li - 通讯作者:
Daiqin Li
Hao Wang的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Hao Wang', 18)}}的其他基金
RII Track-4:NSF: Federated Analytics Systems with Fine-grained Knowledge Comprehension: Achieving Accuracy with Privacy
RII Track-4:NSF:具有细粒度知识理解的联合分析系统:通过隐私实现准确性
- 批准号:
2327480 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Standard Grant
Collaborative Research: OAC: Core: Harvesting Idle Resources Safely and Timely for Large-scale AI Applications in High-Performance Computing Systems
合作研究:OAC:核心:安全及时地收集闲置资源,用于高性能计算系统中的大规模人工智能应用
- 批准号:
2403398 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Critical Learning Periods Augmented Robust Federated Learning
协作研究:SaTC:核心:小型:关键学习期增强鲁棒联邦学习
- 批准号:
2315612 - 财政年份:2023
- 资助金额:
-- - 项目类别:
Standard Grant
CRII: OAC: High-Efficiency Serverless Computing Systems for Deep Learning: A Hybrid CPU/GPU Architecture
CRII:OAC:用于深度学习的高效无服务器计算系统:混合 CPU/GPU 架构
- 批准号:
2153502 - 财政年份:2022
- 资助金额:
-- - 项目类别:
Standard Grant
RI: Small: Enabling Interpretable AI via Bayesian Deep Learning
RI:小型:通过贝叶斯深度学习实现可解释的人工智能
- 批准号:
2127918 - 财政年份:2021
- 资助金额:
-- - 项目类别:
Continuing Grant
US-China planning visit: Development of High Performance and Multifunctional Infrastructure Material
中美计划访问:高性能多功能基础设施材料的开发
- 批准号:
1338297 - 财政年份:2013
- 资助金额:
-- - 项目类别:
Standard Grant
SBIR Phase I: SpiderWeb - Self-Healing Networks for Spyware Detection
SBIR 第一阶段:SpiderWeb - 用于间谍软件检测的自我修复网络
- 批准号:
0638170 - 财政年份:2007
- 资助金额:
-- - 项目类别:
Standard Grant
相似国自然基金
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark
Supercooled Phase Transition
- 批准号:24ZR1429700
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
ATLAS实验探测器Phase 2升级
- 批准号:11961141014
- 批准年份:2019
- 资助金额:3350 万元
- 项目类别:国际(地区)合作与交流项目
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
- 批准号:41802035
- 批准年份:2018
- 资助金额:12.0 万元
- 项目类别:青年科学基金项目
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究
- 批准号:61675216
- 批准年份:2016
- 资助金额:60.0 万元
- 项目类别:面上项目
基于Phase-type分布的多状态系统可靠性模型研究
- 批准号:71501183
- 批准年份:2015
- 资助金额:17.4 万元
- 项目类别:青年科学基金项目
纳米(I-Phase+α-Mg)准共晶的临界半固态形成条件及生长机制
- 批准号:51201142
- 批准年份:2012
- 资助金额:25.0 万元
- 项目类别:青年科学基金项目
连续Phase-Type分布数据拟合方法及其应用研究
- 批准号:11101428
- 批准年份:2011
- 资助金额:23.0 万元
- 项目类别:青年科学基金项目
D-Phase准晶体的电子行为各向异性的研究
- 批准号:19374069
- 批准年份:1993
- 资助金额:6.4 万元
- 项目类别:面上项目
相似海外基金
SBIR Phase II: Innovative Two-Phase Cooling with Micro Closed Loop Pulsating Heat Pipes for High Power Density Electronics
SBIR 第二阶段:用于高功率密度电子产品的创新两相冷却微闭环脉动热管
- 批准号:
2321862 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: Innovative Glass Inspection for Advanced Semiconductor Packaging
SBIR 第二阶段:先进半导体封装的创新玻璃检测
- 批准号:
2335175 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: Intelligent Language Learning Environment
SBIR第二阶段:智能语言学习环境
- 批准号:
2335265 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: FlashPCB Service Commercialization and AI Component Package Identification
SBIR第二阶段:FlashPCB服务商业化和AI组件封装识别
- 批准号:
2335464 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: Thermally-optimized power amplifiers for next-generation telecommunication and radar
SBIR 第二阶段:用于下一代电信和雷达的热优化功率放大器
- 批准号:
2335504 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: Sodium-Based Solid-State Batteries for Stationary Energy Storage
SBIR第二阶段:用于固定储能的钠基固态电池
- 批准号:
2331724 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: A mesh-free, sling-free, minimally invasive treatment for stress urinary incontinence in women
SBIR II 期:无网、无吊带的微创治疗女性压力性尿失禁
- 批准号:
2233106 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: Zero Trust Solution for Precision Medicine and Precision Health Data Exchanges
SBIR 第二阶段:精准医疗和精准健康数据交换的零信任解决方案
- 批准号:
2226026 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: Computer-based co-reading for students with reading disabilities
SBIR 第二阶段:为有阅读障碍的学生提供基于计算机的共同阅读
- 批准号:
2321439 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement
SBIR Phase II: Development of a Novel Measurement Technology to Enable Longitudinal Multiomic Investigations of the Gut Microbiome
SBIR 第二阶段:开发新型测量技术以实现肠道微生物组的纵向多组学研究
- 批准号:
2314685 - 财政年份:2024
- 资助金额:
-- - 项目类别:
Cooperative Agreement