课题基金 / 基金详情

TC: Small: Discovering Designer Intent through Dynamic Analysis of Malware

TC: Small: Discovering Designer Intent through Dynamic Analysis of Malware
TC:小:通过恶意软件的动态分析发现设计者的意图
批准号:
0916061
负责人:
Michel Cukier
金额:
$15.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-01 至 2011-08-31

项目摘要

项目成果

Michel Cukier的其他基金

相似基金

相关文献

中文摘要
翻译
这项拟议的研究解决了识别和提供基于源代码的对困扰互联网的混淆恶意代码的理解的问题。被混淆的恶意代码给今天的社会带来了一个明确而现实的危险?S在个人隐私、安全以及互联网方面的危险?S的整体可信度。攻击者继续使用混淆来成功挫败防御者防止感染或传播恶意代码的企图。这项研究的目标将是为互联网蠕虫可执行文件开发动态二进制分析过程。这些过程将被用来创建反向工程框架,以从蠕虫机器代码创建汇编代码,并进而创建相关的控制和数据流图。使用部分基于程序切片的新技术从这些图中提取被称为Motif的指令序列的泛化,并将其应用于以状态机、决策树或家谱树模型描述的蠕虫行为模型;与这些模型的部分或完全匹配将产生关于蠕虫与其目标环境的交互、其混淆技术以及攻击者的命令、控制和更新手段的知识。该研究将有助于评估控制和数据流图是否能够表示任何混淆的恶意代码。如果某些恶意代码不能使用这些图形表示,则将调查其他表示。将评估恶意代码表示的准确性,因为表示将主要基于系统调用分析。最后,将研究静态和动态分析的几种组合,以评估对恶意代码表示细节的影响。
英文摘要
The proposed research addresses the problem of identifying and providing source code-based understanding of obfuscated malcode plaguing the Internet. Obfuscated malcode presents a clear and present danger to today?s society in terms of individual privacy, security as well as to the Internet?s overall trustworthiness. Attackers continue to use obfuscation to successfully defeat attempts by defenders to prevent infection or spread of the malcode. The goal of the research will be to develop dynamic binary analysis processes for Internet worm executables. These processes will be used to create a reverse engineering framework to create assembly code from worm machine code and in turn create associated control and data flow graphs. Generalizations of instruction sequences, known as motifs, are extracted from these graphs using new techniques based in part on program slicing and will be applied against models of worm behavior described in terms of state machine, decision tree or family tree models; partial or complete matching against these models will yield knowledge of worm interactions with its target environment, its obfuscation techniques and its means of command, control and update by the attacker.This research will help to assess if control and data flow graphs can represent any obfuscated malcode. In case some malcode cannot be represented using these graphs, other representations will be investigated. The accuracy of the malcode representation will be evaluated since the representation will be based mainly on system call analysis. Finally, several combinations of static and dynamic analyses will be studied to assess the impact on the malcode representation details.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Proposal: SaTC: Frontiers: Enabling a Secure and Trustworthy Software Supply Chain
  • 批准号:
    2206921
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $100.14万
  • 财政年份:
    2022
  • 负责人:
    Michel Cukier
  • 依托单位:
SFS for ACES
  • 批准号:
    1753857
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $504.63万
  • 财政年份:
    2018
  • 负责人:
    Michel Cukier
  • 依托单位:
REU Site: Undergraduates Engaged in Cyber Security Research
  • 批准号:
    1062820
  • 项目类别:
    Standard Grant
  • 资助金额:
    $35.45万
  • 财政年份:
    2011
  • 负责人:
    Michel Cukier
  • 依托单位:
REU Sites: Undergraduates Engaged in the Experimental Evaluation of Computer Security
  • 批准号:
    0647321
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.86万
  • 财政年份:
    2007
  • 负责人:
    Michel Cukier
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: