CAREER: Towards Exterminating Stealthy Rootkits - A Systematic Immunization Approach

事业:消灭隐形 Rootkit - 系统免疫方法

基本信息

  • 批准号:
    0952640
  • 负责人:
  • 金额:
    $ 42.42万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2010
  • 资助国家:
    美国
  • 起止时间:
    2010-02-15 至 2015-01-31
  • 项目状态:
    已结题

项目摘要

The rampant growth of stealthy rootkits poses a serious security threat to cyberspace. Specifically, with the capability of directly subverting the software root of trust of a computer system, a rootkit can surreptitiously take over the control of the system and maintain a hidden presence thereafter. To effectively defend against them, researchers have explored various anti-rootkit solutions. Unfortunately, to our disadvantage, the state-of-the-art defense is mainly reactive and cannot meet the challenges in the arms-race against them.This project is developing a systematic immunization approach to proactively prevent and exterminate rootkit attacks. This goal is being achieved in three key steps. First, we are developing a fundamental immunization capability self-nonself discrimination to reliably discern and prevent malicious rootkit code execution. Second, we are investigating a kernel shepherding technique to enforce kernel control-flow integrity. Third, we are designing and implementing a high-assurance hypervisor with a minimal trusted computing base to establish and sustain the root-of-trust of the entire computer system. We expect the results from this research will substantially elevate our defense capability against elusive rootkits as well as more generic malware. We will disseminate our results by releasing the tools developed as well as associated education materials appropriate for undergraduate and graduate courses and IT staff training in industry and government agencies.
隐形rootkit的猖獗增长对网络空间构成了严重的安全威胁。具体地说,通过直接颠覆计算机系统的软件信任根的能力,Rootkit可以秘密地接管系统的控制,并在此后保持隐藏的存在。为了有效地防御它们,研究人员探索了各种反Rootkit的解决方案。不幸的是,对我们不利的是,最先进的防御主要是反应性的,无法应对军备竞赛中的挑战。该项目正在开发一种系统的免疫方法,以主动预防和消灭rootkit攻击。这一目标正在通过三个关键步骤实现。首先,我们正在开发一种基本的免疫能力-自我非自我识别,以可靠地识别和防止恶意Rootkit代码执行。其次,我们正在研究一种内核引导技术,以加强内核控制流完整性。第三,我们正在设计和实施一个具有最低可信计算基础的高保证管理程序,以建立和维护整个计算机系统的信任根。我们预计,这项研究的结果将大幅提升我们对难以捉摸的Rootkit以及更通用的恶意软件的防御能力。我们将通过发布开发的工具以及适用于本科生和研究生课程以及行业和政府机构的信息技术人员培训的相关教育材料来传播我们的结果。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Xuxian Jiang其他文献

Time-Traveling Forensic Analysis of VM-Based High-Interaction Honeypots
基于虚拟机的高交互蜜罐的时间旅行取证分析
  • DOI:
    10.1007/978-3-642-31909-9_12
  • 发表时间:
    2011
  • 期刊:
  • 影响因子:
    0
  • 作者:
    D. Srinivasan;Xuxian Jiang
  • 通讯作者:
    Xuxian Jiang
Tracking the Trackers: Fast and Scalable Dynamic Analysis of Web Content for Privacy Violations
跟踪跟踪者:对 Web 内容进行快速且可扩展的隐私侵犯动态分析
Behavioral Footprinting for Self-Propagating Worm Detection and Profiling
用于自我传播蠕虫检测和分析的行为足迹
vBET: a VM-based emulation testbed
vBET:基于虚拟机的仿真测试平台
  • DOI:
    10.1145/944773.944789
  • 发表时间:
    2003
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Xuxian Jiang;Dongyan Xu
  • 通讯作者:
    Dongyan Xu
A middleware system that integrates and elevates virtual machine and virtual network technologies facilitates the creation of virtual distributed environments in a shared infrastructure
集成和提升虚拟机和虚拟网络技术的中间件系统有助于在共享基础设施中创建虚拟分布式环境
  • DOI:
  • 发表时间:
    2005
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Paul Ruth;Xuxian Jiang;Dongyan Xu;Sébastien;Goasguen
  • 通讯作者:
    Goasguen

Xuxian Jiang的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Xuxian Jiang', 18)}}的其他基金

Collaborative Research: II-NEW: OpenVMI: A Software Instrument for Virtual Machine Introspection
协作研究:II-新:OpenVMI:用于虚拟机自省的软件工具
  • 批准号:
    0855036
  • 财政年份:
    2009
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant
CT-ISG: Understanding Botnet Command and Control (C&C) Communication
CT-ISG:了解僵尸网络命令和控制(C
  • 批准号:
    0831160
  • 财政年份:
    2008
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant
CT-ISG: Collaborative: Enabling Detection of Elusive Malware by by Going Out of the Box with Semantically Reconstructed View (OBSERV)
CT-ISG:协作:通过开箱即用的语义重建视图 (OBSERV) 来检测难以捉摸的恶意软件
  • 批准号:
    0852131
  • 财政年份:
    2008
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant
CT-ISG: Understanding Botnet Command and Control (C&C) Communication
CT-ISG:了解僵尸网络命令和控制(C
  • 批准号:
    0855297
  • 财政年份:
    2008
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant
CT-ISG: Collaborative: Enabling Detection of Elusive Malware by by Going Out of the Box with Semantically Reconstructed View (OBSERV)
CT-ISG:协作:通过开箱即用的语义重建视图 (OBSERV) 来检测难以捉摸的恶意软件
  • 批准号:
    0716376
  • 财政年份:
    2007
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant

相似海外基金

Sexual offence interviewing: Towards victim-survivor well-being and justice
性犯罪面谈:为了受害者-幸存者的福祉和正义
  • 批准号:
    DE240100109
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Discovery Early Career Researcher Award
Unlocking the sensory secrets of predatory wasps: towards predictive tools for managing wasps' ecosystem services in the Anthropocene
解开掠食性黄蜂的感官秘密:开发用于管理人类世黄蜂生态系统服务的预测工具
  • 批准号:
    NE/Y001397/1
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Research Grant
Development of programmable nanomachines towards the enzymatic synthesis of peptide oligonucleotide conjugates
开发用于肽寡核苷酸缀合物酶促合成的可编程纳米机器
  • 批准号:
    EP/X019624/1
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Fellowship
Postdoctoral Fellowship: STEMEdIPRF: Towards a Diverse Professoriate: Experiences that Inform Underrepresented Scholars' Perceptions of Value Alignment and Career Decisions
博士后奖学金:STEMEdIPRF:走向多元化的教授职称:为代表性不足的学者对价值调整和职业决策的看法提供信息的经验
  • 批准号:
    2327411
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant
CAREER: Adaptive Deep Learning Systems Towards Edge Intelligence
职业:迈向边缘智能的自适应深度学习系统
  • 批准号:
    2338512
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Continuing Grant
CAREER: Towards highly efficient UV emitters with lattice engineered substrates
事业:采用晶格工程基板实现高效紫外线发射器
  • 批准号:
    2338683
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Continuing Grant
ASCENT: Heterogeneously Integrated and AI-Empowered Millimeter-Wave Wide-Bandgap Transmitter Array towards Energy- and Spectrum-Efficient Next-G Communications
ASCENT:异构集成和人工智能支持的毫米波宽带隙发射机阵列,实现节能和频谱高效的下一代通信
  • 批准号:
    2328281
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant
Collaborative Research: Maritime to Inland Transitions Towards ENvironments for Convection Initiation (MITTEN CI)
合作研究:海洋到内陆向对流引发环境的转变(MITTEN CI)
  • 批准号:
    2349935
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Continuing Grant
Collaborative Research: Maritime to Inland Transitions Towards ENvironments for Convection Initiation (MITTEN CI)
合作研究:海洋到内陆向对流引发环境的转变(MITTEN CI)
  • 批准号:
    2349934
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Continuing Grant
NSF-BSF: Towards a Molecular Understanding of Dynamic Active Sites in Advanced Alkaline Water Oxidation Catalysts
NSF-BSF:高级碱性水氧化催化剂动态活性位点的分子理解
  • 批准号:
    2400195
  • 财政年份:
    2024
  • 资助金额:
    $ 42.42万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了