课题基金 / 基金详情

TC: Small: Simplification of Obfuscated Executables

TC: Small: Simplification of Obfuscated Executables
TC:小:模糊可执行文件的简化
批准号:
1115829
负责人:
Saumya Debray
金额:
$36.93万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2015-11-30

项目摘要

项目成果

Saumya Debray的其他基金

相似基金

相关文献

中文摘要
翻译
含有潜在恶意内容的程序正变得越来越常见。这类程序通常是高度模糊的,使用了各种技术,使得分析代码、找出其内部逻辑和开发对策变得困难。现有的对这类程序进行反向工程的工具很原始,需要大量乏味和耗时的人工干预,这阻碍了及时开发针对新发现的恶意软件的防御措施。该项目旨在设计自动技术来简化这些混淆,从而显著更快、更容易地理解带有潜在恶意内容的混淆代码的内部逻辑。该项目使用动态程序分析技术来识别影响程序可观察行为的指令;然后提取这些指令,并在适当的情况下使用等式技术进行简化。所调查的关键研究问题包括面对任意混淆和组合混淆时的简化,包括(可能是多层的)自我修改和模拟。该项目的主要影响将是使安全研究人员更容易、更快地找出恶意软件程序的内部逻辑。反过来,这将使其能够更快地对新的恶意软件做出反应,并更快地开发针对它们的对策,而无需更少的人工干预。其效果将是在恶意软件被中和之前减少它们造成的损害。
英文摘要
Programs with potentially malicious content are becoming increasingly common. Such programs are usually highly obfuscated, using a variety of techniques that make it difficult to analyze the code, figure out its internal logic, and develop countermeasures. Existing tools for reverse engineering such programs are primitive and require a great deal of tedious and time-consuming manual intervention, which hampers the timely development of defenses against newly discovered malware. This project aims to devise automatic techniques to simplify away these obfuscations and thereby make it significantly faster and easier to understand the internal logic of obfuscated code with potentially malicious content. The project uses dynamic program analysis techniques to identify instructions that affect the program's observable behavior; these instructions are then extracted and, where appropriate, simplified using equational techniques. Key research questions investigated include simplification in the face of arbitrary obfuscations and combinations of obfuscations, including (possibly multiple layers of) self-modification and emulation. The main impact of this project will be to make it easier and quicker for security researchers to figure out the internal logic of malware programs. This, in turn, will make it possible to respond more quickly to new malware and develop countermeasures to them faster and with less manual intervention. The effect will be to reduce the damage done by malware before they can be neutralized.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Reasoning about dependencies and information flow in dynamic code
  • 批准号:
    1908313
  • 项目类别:
    Standard Grant
  • 资助金额:
    $51.53万
  • 财政年份:
    2019
  • 负责人:
    Saumya Debray
  • 依托单位:
TWC: Small: Understanding Anti-Analysis Defenses in Malicious Code
  • 批准号:
    1525820
  • 项目类别:
    Standard Grant
  • 资助金额:
    $51.48万
  • 财政年份:
    2015
  • 负责人:
    Saumya Debray
  • 依托单位:
SHF: Small: Reverse Engineering Obfuscated Executables
  • 批准号:
    1016058
  • 项目类别:
    Standard Grant
  • 资助金额:
    $10.0万
  • 财政年份:
    2010
  • 负责人:
    Saumya Debray
  • 依托单位:
A Holistic Approach to Compiler-Assisted Optimization of Software Systems
  • 批准号:
    0410918
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2004
  • 负责人:
    Saumya Debray
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: