课题基金 / 基金详情

TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software

TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software
用于检测恶意软件的基于 TC-Small-Virtual Machine Introspection 的实时取证
批准号:
1016807
负责人:
Golden Richard
金额:
$49.9万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-09-01 至 2015-12-31

项目摘要

项目成果

Golden Richard的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Modern malware is used extensively in computer crime and cyber-warfareand poses a serious threat to the cyber-infrastructure of the UnitedStates, at the military, civil, and corporate levels. Malware canemploy a number of techniques to gain access to needed resources andto prevent detection, including hooking or modifying system calls,adding new system calls, inserting new kernel modules, and directlypatching kernel code. Furthermore, malware is increasingly stealthy,being both difficult to detect and to analyze, and current-generationschemes for detection, analysis, and mitigation will becomeincreasingly ineffective as the trend toward additional stealthincreases, with more esoteric infection vectors, complex packingschemes, polymorphism, and metamorphism being employed.This proposal leverages emerging live digital forensics techniques, tocreate powerful techniques for malware detection and mitigation. Theselive forensics techniques deeply analyze memory dumps and buildaccurate models of kernel and application structures that reflect thestate of the machine at the time of an investigation. By integratinglive forensics techniques into a virtual machine monitor (VMM) anddeveloping hardware-supported introspection techniques to analyzesystem state, malware detection facilities can be created that preventmalware from interfering with detection and mitigation strategies.The proposal discusses a number of necessary tasks to support thisresearch agenda, including the design of and development of ahardware-assisted VMM introspection architecture and deep, portablemodeling of kernel data structures and other guest VM state, includingthe filesystem. These modeling techniques can then be used forreal-time verification of critical kernel code, cross-verification ofkernel structures, application state analysis, and protection ofcritical system files. A novel aspect of the proposed research is theuse of commodity Graphics Processing Units (GPUs), protected byhardware directed-I/O virtualization, as malware detectionaccelerators.The intellectual merit of the proposed research is to increase thedepth, flexibility, and capabilities of introspected live forensicsanalysis and to expand the scope of live forensics to the detection ofsophisticated malware. The proposed techniques expandstate-of-the-art in live forensics techniques, virtual machineintrospection, and kernel-level malware detection and will provide afoundation on which to build even more powerful techniques. Thebroader impacts of the proposed work touch all sectors of society,since individual citizens, as well as the law enforcement, military,and corporate communities all benefit from the deployment of moresophisticated malware detection mechanisms. The proposed work alsoenhances the existing curriculum in information assurance at theUniversity of New Orleans, since research results from this effortwill be incorporated into both undergraduate and graduate courses,exposing students to an important area of study in which the supply ofpractitioners falls far short of the demand.For further information see the project web site at the URLhttp://www.cs.uno.edu/~golden/live-forensics.html.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SFS: Applied Cybersecurity Training
  • 批准号:
    1946626
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $335.82万
  • 财政年份:
    2020
  • 负责人:
    Golden Richard
  • 依托单位:
SaTC: CORE: Medium: Robust Memory Forensics Techniques for Userland Malware Analysis
  • 批准号:
    1703683
  • 项目类别:
    Standard Grant
  • 资助金额:
    $111.34万
  • 财政年份:
    2017
  • 负责人:
    Golden Richard
  • 依托单位:
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
  • 批准号:
    1732143
  • 项目类别:
    Standard Grant
  • 资助金额:
    $19.61万
  • 财政年份:
    2016
  • 负责人:
    Golden Richard
  • 依托单位:
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
  • 批准号:
    1409534
  • 项目类别:
    Standard Grant
  • 资助金额:
    $39.98万
  • 财政年份:
    2014
  • 负责人:
    Golden Richard
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: