TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software
用于检测恶意软件的基于 TC-Small-Virtual Machine Introspection 的实时取证
基本信息
- 批准号:1016807
- 负责人:
- 金额:$ 49.9万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2010
- 资助国家:美国
- 起止时间:2010-09-01 至 2015-12-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Modern malware is used extensively in computer crime and cyber-warfareand poses a serious threat to the cyber-infrastructure of the UnitedStates, at the military, civil, and corporate levels. Malware canemploy a number of techniques to gain access to needed resources andto prevent detection, including hooking or modifying system calls,adding new system calls, inserting new kernel modules, and directlypatching kernel code. Furthermore, malware is increasingly stealthy,being both difficult to detect and to analyze, and current-generationschemes for detection, analysis, and mitigation will becomeincreasingly ineffective as the trend toward additional stealthincreases, with more esoteric infection vectors, complex packingschemes, polymorphism, and metamorphism being employed.This proposal leverages emerging live digital forensics techniques, tocreate powerful techniques for malware detection and mitigation. Theselive forensics techniques deeply analyze memory dumps and buildaccurate models of kernel and application structures that reflect thestate of the machine at the time of an investigation. By integratinglive forensics techniques into a virtual machine monitor (VMM) anddeveloping hardware-supported introspection techniques to analyzesystem state, malware detection facilities can be created that preventmalware from interfering with detection and mitigation strategies.The proposal discusses a number of necessary tasks to support thisresearch agenda, including the design of and development of ahardware-assisted VMM introspection architecture and deep, portablemodeling of kernel data structures and other guest VM state, includingthe filesystem. These modeling techniques can then be used forreal-time verification of critical kernel code, cross-verification ofkernel structures, application state analysis, and protection ofcritical system files. A novel aspect of the proposed research is theuse of commodity Graphics Processing Units (GPUs), protected byhardware directed-I/O virtualization, as malware detectionaccelerators.The intellectual merit of the proposed research is to increase thedepth, flexibility, and capabilities of introspected live forensicsanalysis and to expand the scope of live forensics to the detection ofsophisticated malware. The proposed techniques expandstate-of-the-art in live forensics techniques, virtual machineintrospection, and kernel-level malware detection and will provide afoundation on which to build even more powerful techniques. Thebroader impacts of the proposed work touch all sectors of society,since individual citizens, as well as the law enforcement, military,and corporate communities all benefit from the deployment of moresophisticated malware detection mechanisms. The proposed work alsoenhances the existing curriculum in information assurance at theUniversity of New Orleans, since research results from this effortwill be incorporated into both undergraduate and graduate courses,exposing students to an important area of study in which the supply ofpractitioners falls far short of the demand.For further information see the project web site at the URLhttp://www.cs.uno.edu/~golden/live-forensics.html.
现代恶意软件被广泛用于计算机犯罪和网络战,对美国的军事、民用和企业层面的网络基础设施构成严重威胁。恶意软件可以采用许多技术来访问所需的资源并阻止检测,包括钩接或修改系统调用、添加新的系统调用、插入新的内核模块和直接修补内核代码。此外,恶意软件越来越隐蔽,难以检测和分析,当前一代的检测、分析和缓解方案将变得越来越无效,因为更多的隐蔽趋势的增加,更深奥的感染载体,复杂的包装方案,多态性和变形被采用。该提案利用新兴的实时数字取证技术,创建强大的恶意软件检测和缓解技术。这些自动取证技术深入分析内存转储,并构建内核和应用程序结构的准确模型,这些模型反映了调查时机器的状态。通过将实时取证技术集成到虚拟机监视器(VMM)中,并开发硬件支持的内省技术来分析系统状态,可以创建恶意软件检测设施,防止恶意软件干扰检测和缓解策略。该提案讨论了支持该研究议程的一些必要任务,包括硬件辅助VMM自省架构的设计和开发,以及内核数据结构和其他来宾虚拟机状态(包括文件系统)的深度可移植建模。然后,这些建模技术可以用于关键内核代码的实时验证、内核结构的交叉验证、应用程序状态分析和关键系统文件的保护。提出的研究的一个新颖方面是使用商品图形处理单元(gpu),由硬件定向i /O虚拟化保护,作为恶意软件检测加速器。提出的研究的智力价值在于增加内省现场取证分析的深度、灵活性和能力,并将现场取证的范围扩展到复杂恶意软件的检测。提出的技术扩展了实时取证技术、虚拟机内省和内核级恶意软件检测的最新技术,并将为构建更强大的技术提供基础。拟议工作的广泛影响涉及社会的各个部门,因为个人公民,以及执法部门,军队和企业社区都受益于部署更复杂的恶意软件检测机制。拟议的工作还加强了新奥尔良大学现有的信息保障课程,因为这项工作的研究成果将被纳入本科和研究生课程,让学生接触到一个重要的研究领域,在这个领域,从业人员的供应远远不足。欲了解更多信息,请参阅项目网站网址:https://www.cs.uno.edu/~golden/live-forensics.html。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Golden Richard其他文献
Golden Richard的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Golden Richard', 18)}}的其他基金
SFS: Applied Cybersecurity Training
SFS:应用网络安全培训
- 批准号:
1946626 - 财政年份:2020
- 资助金额:
$ 49.9万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Robust Memory Forensics Techniques for Userland Malware Analysis
SaTC:核心:中:用于用户态恶意软件分析的强大内存取证技术
- 批准号:
1703683 - 财政年份:2017
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
TWC:媒介:协作:迈向企业环境中以二进制为中心的网络取证框架
- 批准号:
1732143 - 财政年份:2016
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
TWC:媒介:协作:迈向企业环境中以二进制为中心的网络取证框架
- 批准号:
1409534 - 财政年份:2014
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
CT-ISG: A Comprehensive Data Carving Architecture for Digital Forensics
CT-ISG:用于数字取证的综合数据雕刻架构
- 批准号:
0627226 - 财政年份:2006
- 资助金额:
$ 49.9万 - 项目类别:
Continuing Grant
相似国自然基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
- 批准号:
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
- 批准号:n/a
- 批准年份:2022
- 资助金额:10.0 万元
- 项目类别:省市级项目
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
- 批准号:32000033
- 批准年份:2020
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
- 批准号:31972324
- 批准年份:2019
- 资助金额:58.0 万元
- 项目类别:面上项目
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
- 批准号:81900988
- 批准年份:2019
- 资助金额:21.0 万元
- 项目类别:青年科学基金项目
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
- 批准号:31802058
- 批准年份:2018
- 资助金额:26.0 万元
- 项目类别:青年科学基金项目
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
- 批准号:31870821
- 批准年份:2018
- 资助金额:56.0 万元
- 项目类别:面上项目
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
- 批准号:31772128
- 批准年份:2017
- 资助金额:60.0 万元
- 项目类别:面上项目
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
- 批准号:81704176
- 批准年份:2017
- 资助金额:20.0 万元
- 项目类别:青年科学基金项目
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
- 批准号:91640114
- 批准年份:2016
- 资助金额:85.0 万元
- 项目类别:重大研究计划
相似海外基金
HCC: Small: Making Virtual Reality Safe
HCC:小型:确保虚拟现实安全
- 批准号:
2316240 - 财政年份:2024
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
Collaborative Research: HCC: Small: Supporting Flexible and Safe Disability Representation in Social Virtual Reality
合作研究:HCC:小型:支持社交虚拟现实中灵活、安全的残疾表征
- 批准号:
2328183 - 财政年份:2023
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
Collaborative Research: HCC: Small: Supporting Flexible and Safe Disability Representation in Social Virtual Reality
合作研究:HCC:小型:支持社交虚拟现实中灵活、安全的残疾表征
- 批准号:
2328182 - 财政年份:2023
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Investigating and Mitigating Harmful Design in User-Generated Virtual World through Design Moderation
SaTC:核心:小型:通过设计审核调查和减轻用户生成的虚拟世界中的有害设计
- 批准号:
2326505 - 财政年份:2023
- 资助金额:
$ 49.9万 - 项目类别:
Continuing Grant
Collaborative Research: CNS Core: HCC: Small: Enabling Efficient Computer Systems for Augmented and Virtual Reality: A Perception-Guided Approach
合作研究:CNS 核心:HCC:小型:为增强现实和虚拟现实启用高效计算机系统:感知引导方法
- 批准号:
2225861 - 财政年份:2022
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
Collaborative Research: CNS Core: HCC: Small: Enabling Efficient Computer Systems for Augmented and Virtual Reality: A Perception-Guided Approach
合作研究:CNS 核心:HCC:小型:为增强现实和虚拟现实启用高效计算机系统:感知引导方法
- 批准号:
2225860 - 财政年份:2022
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
Collaborative Research: SHF: Small: Tangram: Scaling into the Exascale Era with Reconfigurable Aggregated "Virtual Chips"
合作研究:SHF:小型:七巧板:通过可重构聚合“虚拟芯片”扩展到百亿亿次时代
- 批准号:
2245129 - 财政年份:2022
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
HCC: Small: ProSocial: A 360-Degrees Video-based Virtual Reality Game Strengthening Social-emotional Skills with Adults with Autism Spectrum Disorder
HCC:小型:ProSocial:一款基于 360 度视频的虚拟现实游戏,可增强患有自闭症谱系障碍的成年人的社交情感技能
- 批准号:
2124549 - 财政年份:2022
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
Collaborative Research: SHF: Small: Software Hardware Architecture Co-Design for Enabling True Virtual Reality on Mobile Devices
合作研究:SHF:小型:软件硬件架构协同设计,在移动设备上实现真正的虚拟现实
- 批准号:
2215042 - 财政年份:2022
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant
Collaborative Research: SHF: Small: Software Hardware Architecture Co-Design for Enabling True Virtual Reality on Mobile Devices
合作研究:SHF:小型:软件硬件架构协同设计,在移动设备上实现真正的虚拟现实
- 批准号:
2215043 - 财政年份:2022
- 资助金额:
$ 49.9万 - 项目类别:
Standard Grant