课题基金 / 基金详情

CAREER: Human-Behavior Driven Malware Detection

CAREER: Human-Behavior Driven Malware Detection
职业:人类行为驱动的恶意软件检测
批准号:
0953638
负责人:
Danfeng Yao
金额:
$53.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-04-01 至 2016-03-31

项目摘要

项目成果

Danfeng Yao的其他基金

相似基金

相关文献

中文摘要
翻译
据估计,全世界有数百万台计算机受到了恶意软件的感染,并且已经变成了?主人不知道?是危险机器人大军的一部分?这是一种由网络罪犯控制的在互联网上运行自动任务的软件应用程序。这些被感染的计算机被攻击者协调和利用,进行非法和破坏性的网络活动,包括身份盗窃、发送垃圾邮件(每天估计有1000亿条垃圾邮件)、发起分布式拒绝服务攻击和进行点击欺诈。他们也有能力发动信息战,摧毁一个国家的关键网络基础设施。现有的恶意软件检测方法在识别和辨别恶意机器人与合法和良性机器人的能力方面是有限的。这种扩散和复杂需要不断警惕和升级。提议的项目引入了一种新的、范式转换的恶意软件检测方法,称为人类行为驱动的恶意软件检测。通过这种方法,该项目将能够通过识别和执行主机上人类计算机使用的独特属性来准确区分合法用户和恶意软件的网络行为。与恶意软件相比,对人类用户特征的关注使计算机安全得以实现,而无需持续监控不断变化的恶意软件模式。这种方法将补充基于代码分析、数据挖掘或网络跟踪过滤的传统恶意软件检测技术。独特且防篡改的流量执行框架的设计将利用片上加密硬件支持对系统和应用级数据的来源信息进行加密验证。该项目将实现新颖且细粒度的输入流量关联分析,这些分析以前从未在主机上应用过。S网络栈、内核模块和输入设备。提议的工作将创造关于可靠操作系统和应用程序设计原则的新知识,并获得将网络安全技术无缝集成到内核中的见解。这些研究将极大地促进对基于人类行为的安全性的理解,并提高所有联网计算机的系统完整性。这项研究将为以用户为中心的安全建立一个重要的基础知识,并将为日益增长的恶意软件检测需求提供一个引人注目的、更持久的解决方案。拟议的工作将侧重于识别人类用户的特征行为(即通过键盘和鼠标的应用程序级用户输入),开发用于细粒度流量输入分析的协议,以及防止恶意软件的伪造和攻击。PI将设计并应用加密技术、相关分析和基于可信平台模块的完整性措施的组合来执行这些任务。作为该项目的一个组成部分,PI将开展外展和教育活动,旨在提高K-14社区对网络安全问题的普遍认识,并扩大本科生和代表性不足群体在计算机安全研究中的跨学科参与。此外,PI将开发一种新的交互式软件系统Sec,用于教授计算机安全,并推进课程开发、指导、多样性建设和研讨会组织方面的工作。
英文摘要
Millions of computers worldwide are estimated to be infected by malware (malicious software) and have become ? unknown to their owners ? part of an army of dangerous ?bots?, which are software applications that run automated tasks over the Internet controlled by cyber criminals. These infected computers are coordinated and used by attackers to launch illegal and destructive network activities including identity theft, sending spam (estimated 100 billion spam messages every day), launching distributed denial of service attacks, and committing click fraud. They are also capable of launching information warfare to destroy critical network infrastructure of a nation. Existing malware-detection approaches are limited in their ability to identify and discern malicious bots from legitimate and benign ones. This proliferation and sophistication requires constant vigilance and upgrading. The proposed project introduces a new and paradigm-shifting approach for malware detection, referred to as human-behavior driven malware detection. With this approach, the project will be able to accurately differentiate network behaviors of a legitimate user and malware by identifying and enforcing unique properties of human computer usage on a host.The focus on human-user characteristics, versus those of malware, allows computer security to be realized without the need for continually monitoring ever-changing malware patterns. This approach will complement conventional malware-detecting techniques based on code analysis, data mining, or network trace filtering. The design of a unique and tamper-resistant traffic-enforcement framework will cryptographically verify the provenance information of both system and application-level data utilizing on-chip cryptographic hardware support. This project will implement novel and fine-grained input-traffic correlation analysis that has not been previously applied across a host?s network stack, kernel modules, and input devices. The proposed work will create new knowledge on design principles of reliable operating systems and applications, as well as gain insights to provide seamless integration of network-security techniques into a kernel. These studies will significantly advance the understanding of human-behavior based security and improve the system integrity of all networked computers. The research will build a base of important fundamental knowledge about user-centric security and will provide a compelling and more permanent solution to the increasing need of malware detection. The proposed work will focus on identifying characteristic human-user behaviors (namely application-level user inputs via keyboard and mouse), developing protocols for fine-grained traffic-input analysis, and preventing forgeries and attacks by malware. The PI will design and apply a combination of cryptographic techniques, correlation analysis, and Trusted Platform Module based integrity measures to carry out these tasks.As an integrated component of the project, the PI will conduct outreach and educational activities that aim to increase the general awareness of cyber-security issues in the K-14 community and broaden the interdisciplinary participation of undergraduate and underrepresented groups in computer security research. In addition, the PI will develop a novel interactive software system Sec Ed for teaching computer security and advancing efforts in curriculum development, mentoring, diversity building, and workshop organization.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
iMentor Workshop at the ACM CCS Conference 2020-2022
SaTC: TTP: Medium: Collaborative: Deployment-quality and Accessible Solutions for Cryptography Code Development
SaTC: CORE: Small: Securing Web-to-Mobile Interface Through Characterization and Detection of Malicious Deep Links
EAGER: Collaborative Research: Privacy-enhancing CrowdPCR for Early Epidemic Detection
国内基金
海外基金
靶向Human ZAG蛋白的降糖小分子化合物筛选以及疗效观察
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    胡文静
  • 依托单位:
HBV S-Human ESPL1融合基因在慢性乙型肝炎发病进程中的分子机制研究
  • 批准号:
    81960115
  • 项目类别:
    地区科学基金项目
  • 资助金额:
    34.0万元
  • 批准年份:
    2019
  • 负责人:
    江建宁
  • 依托单位:
基于自适应表面肌电模型的下肢康复机器人“Human-in-Loop”控制研究
  • 批准号:
    61005070
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2010
  • 负责人:
    李庆玲
  • 依托单位: