CAREER: Binary and Virtualization Centric Malware Defense
CAREER: Binary and Virtualization Centric Malware Defense
批准号:
1054605
负责人:
Heng Yin
金额:
$54.95万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-08-01 至 2016-11-30
中文摘要
恶意软件(malware)已经成为计算机安全的主要威胁,并将继续成为几十年来计算机安全研究的中心主题。该项目采用二进制和虚拟化为中心的方法,通过在线和离线分析有效和高效地击败恶意软件。离线恶意软件分析旨在为新发现的恶意软件实例或软件漏洞提取有关内部工作原理的知识,以建立适当的防御类似的攻击。网络恶意软件防御旨在建立有效的安全机制,有效地限制恶意行为,为后续的安全调查收集足够的证据。针对离线恶意软件分析,采用了一种基于虚拟化的新型恶意软件分析平台,并在此平台上应用新型类型推理技术进行恶意软件分解和漏洞诊断。针对在线恶意软件防御,采用模块级沙箱和虚拟化执行重放技术协同对抗恶意软件。这项研究的结果将通过同行评审的出版物和软件发布进行传播。基于这项研究,将开发新的课程材料、模块化实践项目和专业培训教程,以帮助未来的计算机工程师和安全研究人员获得有关恶意软件防御的深入知识。
英文摘要
Malicious software (malware) has become a major threat to computer security and will continue to be a central theme for computer security research for decades. This project takes a binary and virtualization centric approach to effectively and efficiently defeat malware using both online and offline analysis. Offline malware analysis aims to extract knowledge about the inner-workings for a newly discovered malware instance or software exploit, for the purpose of building up proper defense against similar attacks. Online malware defense aims to build efficient security mechanisms to effectively confine malicious behavior and collect enough evidence for subsequent security investigation. For offline malware analysis, a novel virtualization-based malware analysis platform is used, on top of which new type inference techniques are applied to malware decomposition and vulnerability diagnosis. For online malware defense, new techniques for module-level sandbox and execution replay using virtualization are cooperatively used to defeat malware. The results from this research will be disseminated through both peer-reviewed publications and software release. Based on this research, new course materials, modular hands-on projects, and professional training tutorials will be developed, to help future computer engineers and security researchers gain in-depth knowledge about malware defense.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Concolic-Execution-Centric Fuzzing
-
批准号:2133487
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2022
-
负责人:Heng Yin
-
依托单位:
SaTC: CORE: Small: Towards Robust and Scalable Search of Binary Code and Data
-
批准号:1719175
-
项目类别:Standard Grant
-
资助金额:$47.68万
-
财政年份:2017
-
负责人:Heng Yin
-
依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
-
批准号:1664315
-
项目类别:Continuing Grant
-
资助金额:$16.89万
-
财政年份:2016
-
负责人:Heng Yin
-
依托单位:
TC: Small: Mining Operating System Semantics: Techniques and Applications
-
批准号:1018217
-
项目类别:Standard Grant
-
资助金额:$42.7万
-
财政年份:2010
-
负责人:Heng Yin
-
依托单位:
国内基金
海外基金
Improving modelling of compact binary evolution.
-
批准号:10903001
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2009
-
负责人:史蒂芬
-
依托单位: