课题基金 / 基金详情

TC: Small: Collaborative Research: Scalable Malware Analysis Using Lightweight Virtualization

TC: Small: Collaborative Research: Scalable Malware Analysis Using Lightweight Virtualization
TC:小型:协作研究:使用轻量级虚拟化进行可扩展恶意软件分析
批准号:
0915291
负责人:
Angelos Stavrou
金额:
$23.99万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2013-08-31

项目摘要

项目成果

Angelos Stavrou的其他基金

相似基金

相关文献

中文摘要
翻译
随着网络继续在信息交流中发挥越来越大的作用,它也正在成为感染易受攻击主机的主流平台。一种常见的网络恶意软件交付策略涉及一种狡猾的策略,即瞄准浏览器服务能力,以便在访问网站时自动下载和运行恶意软件。当流行网站被利用时,这些所谓的路过下载的受害者基础可能比其他形式的利用要大得多,因为传统的防御措施(例如防火墙)不会对感染构成障碍。不幸的是,随着今天过多的(不安全的)Web应用程序的部署,在可预见的未来,Web服务器很可能仍然是流行的攻击目标。我们的主要目标之一是通过构建可扩展的恶意软件执行和分析基础设施来深入研究Web上的恶意软件保留网络。具体地说,我们计划构建一个资源高效型主机体系结构,通过跟踪与操作系统的交互来实现轻量级进程监控。我们研究方向的一个重要方面是探索一种将虚拟化和日志记录相结合的事务框架,以实现高效的分析。在该框架中,记录的事务的粒度根据执行上下文动态调整,尽可能将多个事务聚合为单个汇总的事务。该项目的更广泛影响将来自对基于Web的恶意软件提出的问题的不同方面的全面分析,以及最终允许安全社区进行大规模恶意软件分析的工具、方法和分析技术。
英文摘要
As the web continues to play an increasing role in informationexchange, so too is it becoming the prevailing platform for infectingvulnerable hosts. One commonly deployed strategy for deliveringweb-malware involves the underhanded tactic of targeting browservulnerabilities to automatically download and run malicious softwareupon visiting a website. When popular websites are exploited, thevictim base from these so-called drive-by downloads can be far greaterthan other forms of exploitation because traditional defenses (e.g.,firewalls) pose no barrier to infection. Unfortunately, with theplethora of (insecure) web applications being deployed today, it islikely that web servers will continue to be popular targets forexploitation for the foreseeable future.One of our primary goals is to take an in-depth look at the malwareserving network on the Web by building a scalable malware executionand analysis infrastructure. Specifically, we plan to build aresource-efficient host architecture that permits lightweight processmonitoring via tracking of interactions with the OS. An importantfacet of our research direction is to explore a transactionalframework that unifies virtualization and logging to allow efficientanalysis. In this framework, the granularity of recorded transactionsis dynamically adjusted based on execution contexts, aggregatingmultiple transactions to a single, summarized, transaction wheneverpossible. Broader impats of this project will result from thecomprehensive analysis of the different aspects of the problem posedby web-based malware, and the tools, methods, and analyticaltechniques that will ultimately allow for large-scale malware analysisby the security community at large.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TWC: TTP Option: Small: Collaborative: Scalable Techniques for Better Situational Awareness: Algorithmic Frameworks and Large-Scale Empirical Analyses
  • 批准号:
    1421747
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.49万
  • 财政年份:
    2014
  • 负责人:
    Angelos Stavrou
  • 依托单位:
Bridging the Cybersecurity Leadership Gap: Assessment, Competencies and Capacity Building
  • 批准号:
    1303299
  • 项目类别:
    Standard Grant
  • 资助金额:
    $48.49万
  • 财政年份:
    2013
  • 负责人:
    Angelos Stavrou
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: