课题基金 / 基金详情

TC: Medium: Self-Securing Services for Mobile Handsets

TC: Medium: Self-Securing Services for Mobile Handsets
TC:中:手机的自我保护服务
批准号:
0905143
负责人:
Kang Shin
金额:
$30.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-03-01 至 2015-02-28

项目摘要

项目成果

Kang Shin的其他基金

相似基金

相关文献

中文摘要
翻译
这项研究的主要目的是为智能手机开发一种名为S3Mobile(手机自安全服务)的自安全框架,以保护手机免受已知和未知恶意软件的侵害。S3Mobile的关键研究组件包括:(1)收集手机恶意软件样本;(2)记录代表相应运行时行为的样本的硬件和软件使用日志;(3)开发从日志中提取特征的算法;(4)分析相似性、特征和攻击向量;(5)在Android平台上实现和评估S3Mobile。解决这个问题的一般方法是在手机上进行一些监控,但是,认识到在手机上可用的计算和电气资源更有限,因此使用远程服务器进行更多的计算密集型活动,并维护恶意软件和正常应用程序行为的存储库。服务器端设施被称为第二道防线。工作中指出了四个特殊的挑战:准确地指定恶意软件行为,准确地检测此类行为,测试构建的系统以正确评估其性能,以及获取恶意软件样本的难度。该提案记录了应对这些挑战的方法,包括使用基于时间逻辑的符号来描述恶意软件行为,以及结合蜜罐和工业协作来提供恶意软件样本。如果成功,这项工作可能会导致手机/智能手机基础设施对旨在窃取信息或从手机中消耗电量的基于软件的攻击的弹性大大提高。
英文摘要
The main objective of the proposed research is to develop a self-securing framework for smart mobile handsets, called S3Mobile (Self Securing Services for Mobile handsets), that protects the handsets against known and unknown malware. The key research components of S3Mobile include: (1) collect malware samples for mobile handsets, (2) record the hardware and software usage logs of the samples that represent the corresponding run-time behavior, (3) develop an algorithm for extracting features from the logs, (4) analyze similarities, features, and exploit vectors, and (5) implement and evaluate S3Mobile on the Android platform. The general approach to the problem is to conduct some monitoring on the handset, but, recognizing the more limited computational and electrical resources available there, to use a remote server to conduct more computationally intensive activities and to maintain repositories of malware and normal application behavior. The server side facilities are referred to as a second line of defense. Four particular challenges are noted for the work: accurately specifying malware behavior, accurately detecting such behavior, testing the constructed system to evaluate its performance correctly, and the difficulty of obtaining malware samples. The proposal documents approaches to each of these challenges, including the use of a temporal logic based notation for describing malware behavior and a combination of honeypots and industrial collaboration to provide malware samples. If successful, the work could lead to a cellphone / smartphone infrastructure with much improved resilience to software-based attacks that aim to steal information or drain power from the phone.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Securing Interactions between Driver and Vehicle Using Batteries
CPS:Small: Imposing Recovery Period for Battery Health Monitoring, Prognosis, and Optimization
CPS: Breakthrough: Secure Interactions with Internet of Things
CPS: Synergy: Adaptive Management of Large Energy Storage Systems for Vehicle Electrification
海外基金