课题基金 / 基金详情

SDCI Sec: New Software Platforms for Supporting Network-wide Detection of Code Injection Attacks

SDCI Sec: New Software Platforms for Supporting Network-wide Detection of Code Injection Attacks
SDCI Sec:支持全网代码注入攻击检测的新软件平台
批准号:
1127361
负责人:
Fabian Monrose
金额:
$80.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-08-01 至 2017-01-31

项目摘要

项目成果

Fabian Monrose的其他基金

相似基金

相关文献

中文摘要
翻译
近年来,代码注入攻击已成为对现代计算机系统最常见的攻击形式之一。在较高级别上,对网络服务(例如文件共享和Web服务器)和基于客户端的程序(例如浏览器和文档查看器)的代码注入攻击允许将易受攻击的程序中的执行流重定向到称为外壳代码的任意代码,该代码作为攻击的一部分提供。注入的代码通常允许对系统资源、应用程序和数据进行未经授权的控制。检测这些攻击的关键在于准确地发现被注入到易受攻击的程序中的外壳代码的存在。本研究的目的是设计、实现和部署一个名为ShellOS的新框架,该框架不断分析网络流或程序缓冲区,以检测是否存在可能有害的可执行代码。该方法解决了当前动态分析技术使用基于软件的CPU仿真来检测外壳代码的缺点。与以前的方法不同,这种方法利用硬件虚拟化的优势,通过直接在CPU上执行指令序列来允许更高效、更准确地检查缓冲区。通过这样做,该项目实现了更多可伸缩的技术,以保护网络基础设施免受代码注入攻击。在可能的情况下,该项目还计划发布匿名形式的检测到的攻击。此类数据的可获得性可以在促进合作和确保美国在网络安全研究方面的技术领先地位方面发挥重要作用。作为该项目的一部分创建的工具将在开放源码许可下提供给更广泛的研究社区。
英文摘要
In recent years, code-injection attacks have become one of the mostcommon forms of attack on modern computer systems. At a high level,code-injection attacks on network services (e.g. file sharing andwebservers) and client-based programs (e.g., browsers and documentviewers) enable redirection of the flow of execution in the vulnerableprogram to arbitrary code, called shellcode, which is provided as partof the attack. The injected code often enables unauthorized control ofsystem resources, applications, and data. The key to detecting theseattacks lies in accurately discovering the presence of the shellcodebeing injected into the vulnerable program.The intent of this research is to design, implement, and deploy a newframework, called ShellOS, that continuously analyzes network streamsor program buffers to detect the presence of executable code that maybe harmful. The proposed approach addresses the shortcomings ofcurrent dynamic analysis techniques that use software-based CPUemulation for detecting shellcode. Unlike previous approaches, this approach takesadvantage of hardware virtualization to allow for more efficient andaccurate inspection of buffers by directly executing instructionsequences on the CPU. In doing so, this project enables more scalabletechniques for protecting cyberinfrastructure against code injectionattacks. Where possible, the project also plans to release anonymized forms ofdetected attacks. The availability of such data can play a significantrole in fostering collaboration and ensuring U.S. technical leadershipin network security research. The tools created as part of thisproject will be made available to the broader research community underan open source license.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Student Travel to the 2016 USENIX Security Symposium
NSF Support for the 2015 USENIX Security Symposium, Financial Aid; August 2015; Washington, D.C.
TWC: TTP Option: Small: Collaborative: Scalable Techniques for Better Situational Awareness: Algorithmic Frameworks and Large-Scale Empirical Analyses
NSF Support for the 2013 USENIX Security Symposium, Financial Aid; August 2013; Washington DC
国内基金
海外基金
工业大麻内生菌SEC-024A高效抑菌VOCs的合成调控、诱变选育及其增效分子机制研究
蟾毒灵通过SEC13/HMGB1/TLR4/NF-κB轴调控转移生态位抑制乳腺癌骨转移的机制研究
SEC61A2调控EMT影响肺腺癌细胞侵袭和转移的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    徐磊
  • 依托单位:
膀胱癌细胞中TEAD4激活SEC61G通过糖酵解促进M2巨噬细胞极化的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2025
  • 负责人:
    李朋
  • 依托单位: