CAREER: Coordination- and Correlation-based Botnet Defense
CAREER: Coordination- and Correlation-based Botnet Defense
批准号:
0954096
负责人:
Guofei Gu
金额:
$40.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-02-15 至 2017-01-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
This project aims to create a systematic framework with novel approaches and techniques to defend against current and next generation botnets. A botnet is a network of compromised computers (bots) that are under the control of an attacker (botmaster) through some command & control (C&C) channel. In recent years, botnets have distinguished themselves from previous generation malware as the primary platform and root-cause for most Internet attacks and illegal activities. With the magnitude and the potency of attacks afforded by their combined bandwidth and processing power, botnets are now considered as the greatest single threat to Internet security. As botnets involve both host-level and network-level activities, a systematic defensive framework should consider both host- and network-level information. We can achieve better defense by utilizing host-network coordination, community-based intelligence, and a cross-layer view, instead of relying on a single (or a set of separate) host- or network-level information source(s). This project establishes a host-network coordination- and correlation-based framework for systematic botnet defense in depth. It addresses three major questions covering detection, prevention, and attribution of botnets: How to detect the existence of botnets in an efficient, accurate, robust, fast, and automatic way? How to prevent botnets from penetrating into a protected network? Where does the command and control (C&C) actually originate from? The methodology and techniques proposed in the project can have a profound impact on future malware defense in terms of improving its effectiveness, efficiency, and robustness.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
CloudRand: Building Heterogeneous and Moving-target Network Interfaces
CloudRand:构建异构和移动目标网络接口
DOI:
--
发表时间:
2018
期刊:
2018 International Conference on Computer Communication and Networks (ICCCN'18
影响因子:
--
作者:
[Seungwon Shin, Zhaoyan Xu]
通讯作者:
Seungwon Shin, Zhaoyan Xu
NSF Convergence Accelerator Track G: PETS: Programmable Zero-Trust Security for Operating Through 5G Infrastructure
-
批准号:2226339
-
项目类别:Standard Grant
-
资助金额:$75.0万
-
财政年份:2022
-
负责人:Guofei Gu
-
依托单位:
RINGS: NextSec: Zero-Trust, Programmable and Verifiable Security Transformation for NextG
-
批准号:2148374
-
项目类别:Continuing Grant
-
资助金额:$100.0万
-
财政年份:2022
-
负责人:Guofei Gu
-
依托单位:
Community-Building Workshop on Programmable System Security in a Software-Defined World
-
批准号:1841099
-
项目类别:Standard Grant
-
资助金额:$0.15万
-
财政年份:2018
-
负责人:Guofei Gu
-
依托单位:
SaTC: CORE: Small: Adversarial Learning via Modeling Interpretation
-
批准号:1816497
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Guofei Gu
-
依托单位:
EAGER: USBRCCR: Collaborative: Securing Networks in the Programmable Data Plane Era
-
批准号:1740791
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2017
-
负责人:Guofei Gu
-
依托单位:
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
-
批准号:1700544
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2017
-
负责人:Guofei Gu
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
-
批准号:1642129
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2016
-
负责人:Guofei Gu
-
依托单位:
NeTS: Small: Detecting Races in SDN Control Plane
-
批准号:1617985
-
项目类别:Standard Grant
-
资助金额:$35.0万
-
财政年份:2016
-
负责人:Guofei Gu
-
依托单位:
TWC: Medium: Collaborative: HIMALAYAS: Hierarchical Machine Learning Stack for Fine-Grained Analysis of Malware Domain Groups
-
批准号:1314823
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2013
-
负责人:Guofei Gu
-
依托单位:
海外基金