TC: Small: Increasing The Cost of Malware
TC: Small: Increasing The Cost of Malware
批准号:
1017034
负责人:
Wu-chang Feng
金额:
$49.84万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-09-01 至 2014-08-31
中文摘要
从商业级恶意软件的激增可以看出,攻击网络应用程序是一项有利可图的业务。恶意软件作者目前对我们有两个优势。第一个优点是,由于用户在他们的系统上运行不同的应用程序集,反病毒和反恶意软件程序必须在系统上的所有软件中详尽地搜索特定的恶意软件实例。恶意软件很容易通过使用多态性、变形、混淆和加密包装来阻止这一点,这给反恶意软件供应商带来了经济负担,给他们的用户带来了性能负担。恶意软件作者喜欢的第二个优势是,虽然有很多应用程序可以攻击,但每个软件目标在许多客户机上都是静态的。因此,恶意软件作者只需要反向利用应用程序的单个实例就可以危害数千台机器。这个项目研究了两种新的方法来扭转恶意软件作者所拥有的优势。第一种方法探索白名单执行模型,该模型将完整性检查从操作系统扩展到在线运行的应用程序。第二种方法探索应用程序的在线运行时转换,以迫使恶意软件攻击者为其希望破坏的每个新客户端逆转和利用新应用程序。最后,该项目旨在演示这些技术对开发恶意软件成本的影响。
英文摘要
As seen by the proliferation of commercial-grade malware, attacking networked applications is a profitable enterprise. There are two advantages malware authors currently have against us. The first advantage is that because users run a diverse set of applications on their systems, anti-virus and anti-malware programs must exhaustively search for specific malware instances across all pieces of software on a system. Malware easily thwarts this through the use of polymorphism, metamorphism, obfuscation, and cryptographic packing, placing a financial burden on anti-malware vendors and a performance burden on their users. The second advantage malware authors enjoy is that while there are a lot of applications to attack, each software target is static across many client machines. As a result, malware authors only need to reverse and exploit a single instance of an application in order to compromise thousands of machines. This project examines two novel approaches for reversing the advantages held by malware authors. The first approach explores a white-listed execution model that extends integrity-checks beyond the operating system and into the running application in an on-line manner. The second approach explores the on-line, run-time transformation of applications in order to force a malware adversary to reverse and exploit a new application for each new client it wishes to compromise. Finally, the project aims to demonstrate the impact these techniques have on the cost of developing malware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Education DCL: EAGER: Re-imagining the Role of Humans in Security Education
-
批准号:2335633
-
项目类别:Standard Grant
-
资助金额:$26.29万
-
财政年份:2023
-
负责人:Wu-chang Feng
-
依托单位:
SaTC: EDU: Curricula and CTF Exercises for Teaching Smart Fuzzing and Symbolic Execution
-
批准号:1821841
-
项目类别:Standard Grant
-
资助金额:$27.94万
-
财政年份:2018
-
负责人:Wu-chang Feng
-
依托单位:
EDU: A Capture-the-Flag Service for Computer Security Courses
-
批准号:1623400
-
项目类别:Standard Grant
-
资助金额:$29.83万
-
财政年份:2016
-
负责人:Wu-chang Feng
-
依托单位:
Forensix: Large-scale Tamper-resistant Computer Forensic Systems
-
批准号:0529809
-
项目类别:Standard Grant
-
资助金额:$39.9万
-
财政年份:2004
-
负责人:Wu-chang Feng
-
依托单位:
Forensix: Large-scale Tamper-resistant Computer Forensic Systems
-
批准号:0230960
-
项目类别:Standard Grant
-
资助金额:$74.98万
-
财政年份:2002
-
负责人:Wu-chang Feng
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: