SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
批准号:
1127195
负责人:
Roberto Perdisci
金额:
$38.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2019-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Recently cyber-criminals have been leveraging the domain name system (DNS) to build agile malicious network infrastructures in support of their criminal activities. For example, botnets and other types of malware typically use DNS to locate their command-and-control (C&C) servers. Another example of such malicious use of DNS is represented by flux networks, which make use of fast-flux domains, i.e., domains whose set of resolved IPs changes abnormally frequently, to support spam campaigns, phishing websites, browser exploits, etc.In this project, the PIs will develop a suite of open-source tools that use passive and active DNS traffic monitoring to detect and track the evolution in time of malicious domains. In particular, the PIs will develop and publicly release FluxBuster, a system that is able to detect flux networks "in the wild" by passively monitoring DNS traffic collected from many different networks through the ISC Security Information Exchange (ISC/SIE) framework. Along with FluxBuster, the PIs will develop and release DNS monitoring tools that leverage passive and active approaches to detect and track the evolution in time of malware-related (e.g., C&C) domain names.The PIs plan to deploy the proposed tools and make their results available to the security community. This project can therefore broadly benefit society, in that it produces results that are readily usable by security researchers, network operators, and law enforcement agencies to identify and block malicious domains and combat cyber-criminal activities, thus contributing to making the Internet more secure.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
-
批准号:2126641
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2021
-
负责人:Roberto Perdisci
-
依托单位:
EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
-
批准号:1741608
-
项目类别:Standard Grant
-
资助金额:$17.98万
-
财政年份:2017
-
负责人:Roberto Perdisci
-
依托单位:
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
-
批准号:1514052
-
项目类别:Standard Grant
-
资助金额:$29.99万
-
财政年份:2015
-
负责人:Roberto Perdisci
-
依托单位:
CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
-
批准号:1149051
-
项目类别:Continuing Grant
-
资助金额:$40.26万
-
财政年份:2012
-
负责人:Roberto Perdisci
-
依托单位:
国内基金
海外基金
登录
查看更多内容
工业大麻内生菌SEC-024A高效抑菌VOCs的合成调控、诱变选育及其增效分子机制研究
-
批准号:2026JJ81271
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2026
-
负责人:王吐虹
-
依托单位:
蟾毒灵通过SEC13/HMGB1/TLR4/NF-κB轴调控转移生态位抑制乳腺癌骨转移的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:殷佩浩
-
依托单位:
SEC61A2调控EMT影响肺腺癌细胞侵袭和转移的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:徐磊
-
依托单位:
膀胱癌细胞中TEAD4激活SEC61G通过糖酵解促进M2巨噬细胞极化的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:李朋
-
依托单位:
金葡菌肠毒素SEC 激活内皮细胞 PDK/AKT/mTOR 信号轴介导血管新生的分子
机制研究
-
批准号:24ZR1448300
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:易磊
-
依托单位:
SEC14L3 通过 CCN1调控心肌细胞凋亡在脓毒症诱导的
心功能障碍中的作用及机制研究
-
批准号:2024JJ3038
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:张伟志
-
依托单位:
毕赤酵母中Sec16p蛋白介导的膜泡出芽机制解析及运输系统重塑
研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:吕雪芹
-
依托单位:
Circ-SEC23B通过ceRNA机制调控CD24/Siglec10表达介导巨噬细胞M1极化参与Graves病免疫炎症的机制研究
-
批准号:2024Y9411
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:白雪凤
-
依托单位:
全基因组CRISPR筛选鉴定SEC23A驱动胃黏膜肠化生的作用和机制研究
-
批准号:2024Y9191
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:魏旭劲
-
依托单位:
基于胶质瘤类器官模型探讨SEC16B/TRIM56/HMGA1信号轴通过调控DNA损伤修复介导胶质母细胞瘤对替莫唑胺治疗耐药的分子机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:黄广龙
-
依托单位: