TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software
TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software
批准号:
1016807
负责人:
Golden Richard
金额:
$49.9万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-09-01 至 2015-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Modern malware is used extensively in computer crime and cyber-warfareand poses a serious threat to the cyber-infrastructure of the UnitedStates, at the military, civil, and corporate levels. Malware canemploy a number of techniques to gain access to needed resources andto prevent detection, including hooking or modifying system calls,adding new system calls, inserting new kernel modules, and directlypatching kernel code. Furthermore, malware is increasingly stealthy,being both difficult to detect and to analyze, and current-generationschemes for detection, analysis, and mitigation will becomeincreasingly ineffective as the trend toward additional stealthincreases, with more esoteric infection vectors, complex packingschemes, polymorphism, and metamorphism being employed.This proposal leverages emerging live digital forensics techniques, tocreate powerful techniques for malware detection and mitigation. Theselive forensics techniques deeply analyze memory dumps and buildaccurate models of kernel and application structures that reflect thestate of the machine at the time of an investigation. By integratinglive forensics techniques into a virtual machine monitor (VMM) anddeveloping hardware-supported introspection techniques to analyzesystem state, malware detection facilities can be created that preventmalware from interfering with detection and mitigation strategies.The proposal discusses a number of necessary tasks to support thisresearch agenda, including the design of and development of ahardware-assisted VMM introspection architecture and deep, portablemodeling of kernel data structures and other guest VM state, includingthe filesystem. These modeling techniques can then be used forreal-time verification of critical kernel code, cross-verification ofkernel structures, application state analysis, and protection ofcritical system files. A novel aspect of the proposed research is theuse of commodity Graphics Processing Units (GPUs), protected byhardware directed-I/O virtualization, as malware detectionaccelerators.The intellectual merit of the proposed research is to increase thedepth, flexibility, and capabilities of introspected live forensicsanalysis and to expand the scope of live forensics to the detection ofsophisticated malware. The proposed techniques expandstate-of-the-art in live forensics techniques, virtual machineintrospection, and kernel-level malware detection and will provide afoundation on which to build even more powerful techniques. Thebroader impacts of the proposed work touch all sectors of society,since individual citizens, as well as the law enforcement, military,and corporate communities all benefit from the deployment of moresophisticated malware detection mechanisms. The proposed work alsoenhances the existing curriculum in information assurance at theUniversity of New Orleans, since research results from this effortwill be incorporated into both undergraduate and graduate courses,exposing students to an important area of study in which the supply ofpractitioners falls far short of the demand.For further information see the project web site at the URLhttp://www.cs.uno.edu/~golden/live-forensics.html.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SFS: Applied Cybersecurity Training
-
批准号:1946626
-
项目类别:Continuing Grant
-
资助金额:$335.82万
-
财政年份:2020
-
负责人:Golden Richard
-
依托单位:
SaTC: CORE: Medium: Robust Memory Forensics Techniques for Userland Malware Analysis
-
批准号:1703683
-
项目类别:Standard Grant
-
资助金额:$111.34万
-
财政年份:2017
-
负责人:Golden Richard
-
依托单位:
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
-
批准号:1732143
-
项目类别:Standard Grant
-
资助金额:$19.61万
-
财政年份:2016
-
负责人:Golden Richard
-
依托单位:
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
-
批准号:1409534
-
项目类别:Standard Grant
-
资助金额:$39.98万
-
财政年份:2014
-
负责人:Golden Richard
-
依托单位:
CT-ISG: A Comprehensive Data Carving Architecture for Digital Forensics
-
批准号:0627226
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:Golden Richard
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: