SDCI Sec: New Software Platforms for Supporting Network-wide Detection of Code Injection Attacks
SDCI Sec: New Software Platforms for Supporting Network-wide Detection of Code Injection Attacks
批准号:
1127361
负责人:
Fabian Monrose
金额:
$80.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-08-01 至 2017-01-31
中文摘要
近年来,代码注入攻击已成为对现代计算机系统最常见的攻击形式之一。在较高级别上,对网络服务(例如文件共享和Web服务器)和基于客户端的程序(例如浏览器和文档查看器)的代码注入攻击允许将易受攻击的程序中的执行流重定向到称为外壳代码的任意代码,该代码作为攻击的一部分提供。注入的代码通常允许对系统资源、应用程序和数据进行未经授权的控制。检测这些攻击的关键在于准确地发现被注入到易受攻击的程序中的外壳代码的存在。本研究的目的是设计、实现和部署一个名为ShellOS的新框架,该框架不断分析网络流或程序缓冲区,以检测是否存在可能有害的可执行代码。该方法解决了当前动态分析技术使用基于软件的CPU仿真来检测外壳代码的缺点。与以前的方法不同,这种方法利用硬件虚拟化的优势,通过直接在CPU上执行指令序列来允许更高效、更准确地检查缓冲区。通过这样做,该项目实现了更多可伸缩的技术,以保护网络基础设施免受代码注入攻击。在可能的情况下,该项目还计划发布匿名形式的检测到的攻击。此类数据的可获得性可以在促进合作和确保美国在网络安全研究方面的技术领先地位方面发挥重要作用。作为该项目的一部分创建的工具将在开放源码许可下提供给更广泛的研究社区。
英文摘要
In recent years, code-injection attacks have become one of the mostcommon forms of attack on modern computer systems. At a high level,code-injection attacks on network services (e.g. file sharing andwebservers) and client-based programs (e.g., browsers and documentviewers) enable redirection of the flow of execution in the vulnerableprogram to arbitrary code, called shellcode, which is provided as partof the attack. The injected code often enables unauthorized control ofsystem resources, applications, and data. The key to detecting theseattacks lies in accurately discovering the presence of the shellcodebeing injected into the vulnerable program.The intent of this research is to design, implement, and deploy a newframework, called ShellOS, that continuously analyzes network streamsor program buffers to detect the presence of executable code that maybe harmful. The proposed approach addresses the shortcomings ofcurrent dynamic analysis techniques that use software-based CPUemulation for detecting shellcode. Unlike previous approaches, this approach takesadvantage of hardware virtualization to allow for more efficient andaccurate inspection of buffers by directly executing instructionsequences on the CPU. In doing so, this project enables more scalabletechniques for protecting cyberinfrastructure against code injectionattacks. Where possible, the project also plans to release anonymized forms ofdetected attacks. The availability of such data can play a significantrole in fostering collaboration and ensuring U.S. technical leadershipin network security research. The tools created as part of thisproject will be made available to the broader research community underan open source license.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Student Travel to the 2016 USENIX Security Symposium
-
批准号:1521575
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2015
-
负责人:Fabian Monrose
-
依托单位:
NSF Support for the 2015 USENIX Security Symposium, Financial Aid; August 2015; Washington, D.C.
-
批准号:1421152
-
项目类别:Standard Grant
-
资助金额:$2.5万
-
财政年份:2014
-
负责人:Fabian Monrose
-
依托单位:
TWC: TTP Option: Small: Collaborative: Scalable Techniques for Better Situational Awareness: Algorithmic Frameworks and Large-Scale Empirical Analyses
-
批准号:1421703
-
项目类别:Standard Grant
-
资助金额:$49.2万
-
财政年份:2014
-
负责人:Fabian Monrose
-
依托单位:
NSF Support for the 2013 USENIX Security Symposium, Financial Aid; August 2013; Washington DC
-
批准号:1338288
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2013
-
负责人:Fabian Monrose
-
依托单位:
NSF Support for the 2014 USENIX Security Symposium, Financial Aid; August 2014; San Diego, CA
-
批准号:1342609
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2013
-
负责人:Fabian Monrose
-
依托单位:
TWC: Small: Toward Pronounceable Authentication Strings
-
批准号:1318520
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2013
-
负责人:Fabian Monrose
-
依托单位:
NSF Support for the 2011 USENIX Security Symposium, Financial Aid; August 2011; San Francisco CA
-
批准号:1115657
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2011
-
负责人:Fabian Monrose
-
依托单位:
NSF Support for the 2010 USENIX Security Symposium, Financial Aid; August 2010; Washington D.C.
-
批准号:1049707
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2010
-
负责人:Fabian Monrose
-
依托单位:
TC: Small: Exploring Privacy Breaches in Encrypted VoIP Communications
-
批准号:1017318
-
项目类别:Standard Grant
-
资助金额:$49.65万
-
财政年份:2010
-
负责人:Fabian Monrose
-
依托单位:
TC: Small: Collaborative Research: Scalable Malware Analysis Using Lightweight Virtualization
-
批准号:0915364
-
项目类别:Continuing Grant
-
资助金额:$25.93万
-
财政年份:2009
-
负责人:Fabian Monrose
-
依托单位:
CAREER:Towards Effective Identification of Application Behaviors in Encrypted Traffic
-
批准号:0852649
-
项目类别:Continuing Grant
-
资助金额:$24.12万
-
财政年份:2008
-
负责人:Fabian Monrose
-
依托单位:
CAREER:Towards Effective Identification of Application Behaviors in Encrypted Traffic
-
批准号:0546350
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2006
-
负责人:Fabian Monrose
-
依托单位:
Collaborative Research: Using Generative Models to Evaluate and Strengthen Biometrically Enhanced Systems
-
批准号:0430338
-
项目类别:Standard Grant
-
资助金额:$31.15万
-
财政年份:2004
-
负责人:Fabian Monrose
-
依托单位:
国内基金
海外基金
登录
查看更多内容
工业大麻内生菌SEC-024A高效抑菌VOCs的合成调控、诱变选育及其增效分子机制研究
-
批准号:2026JJ81271
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2026
-
负责人:王吐虹
-
依托单位:
蟾毒灵通过SEC13/HMGB1/TLR4/NF-κB轴调控转移生态位抑制乳腺癌骨转移的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:殷佩浩
-
依托单位:
SEC61A2调控EMT影响肺腺癌细胞侵袭和转移的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:徐磊
-
依托单位:
膀胱癌细胞中TEAD4激活SEC61G通过糖酵解促进M2巨噬细胞极化的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2025
-
负责人:李朋
-
依托单位:
金葡菌肠毒素SEC 激活内皮细胞 PDK/AKT/mTOR 信号轴介导血管新生的分子
机制研究
-
批准号:24ZR1448300
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:易磊
-
依托单位:
SEC14L3 通过 CCN1调控心肌细胞凋亡在脓毒症诱导的
心功能障碍中的作用及机制研究
-
批准号:2024JJ3038
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:张伟志
-
依托单位:
Circ-SEC23B通过ceRNA机制调控CD24/Siglec10表达介导巨噬细胞M1极化参与Graves病免疫炎症的机制研究
-
批准号:2024Y9411
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:白雪凤
-
依托单位:
毕赤酵母中Sec16p蛋白介导的膜泡出芽机制解析及运输系统重塑
研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:吕雪芹
-
依托单位:
全基因组CRISPR筛选鉴定SEC23A驱动胃黏膜肠化生的作用和机制研究
-
批准号:2024Y9191
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:魏旭劲
-
依托单位:
基于胶质瘤类器官模型探讨SEC16B/TRIM56/HMGA1信号轴通过调控DNA损伤修复介导胶质母细胞瘤对替莫唑胺治疗耐药的分子机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:15.0万元
-
批准年份:2024
-
负责人:黄广龙
-
依托单位: