课题基金 / 基金详情

CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models

CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
职业:自适应网络中心恶意软件检测模型的自动学习
批准号:
1149051
负责人:
Roberto Perdisci
金额:
$40.26万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2012
资助国家:
美国
项目状态:
已结题
起止时间:
2012-06-01 至 2018-05-31

项目摘要

项目成果

Roberto Perdisci的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Malicious software (a.k.a. malware) is at the basis of most cyber-criminal operations, causing significant financial loss and posing great risks to national security.This research creates novel network-centric behavior-based malware detection systems that automatically learn how to identify malware-compromised machines within a network, and that can self-tune to achieve the best possible trade-off between malware detection rate and false alarms for a given network. This self-tuning property is achieved by combining models of malware-generated network traffic with models of legitimate user-generated network activities to build hybrid detection models that can adapt to a specific network environment and accurately detect malware-generated network traffic crossing the network perimeter.This new approach to malware detection takes into account events that occur within an entire network, rather than focusing on events that occur at each single host, and focuses on adaptive detection of all types of malware, rather than being limited to a specific malware type (e.g., botnets). Therefore, the detection systems resulting from this research will provide new effective detection capabilities that can complement current anti-malware technologies and significantly contribute to a better defense-in-depth strategy against malware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
海外基金