TWC: Medium: Collaborative: HIMALAYAS: Hierarchical Machine Learning Stack for Fine-Grained Analysis of Malware Domain Groups

TWC:媒介:协作:HIMALAYAS:用于恶意软件域组细粒度分析的分层机器学习堆栈

基本信息

  • 批准号:
    1314823
  • 负责人:
  • 金额:
    $ 25万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2013
  • 资助国家:
    美国
  • 起止时间:
    2013-10-01 至 2018-09-30
  • 项目状态:
    已结题

项目摘要

The domain name system (DNS) protocol plays a significant role in operation of the Internet by enabling the bi-directional association of domain names with IP addresses. It is also increasingly abused by malware, particularly botnets, by use of: (1) automated domain generation algorithms for rendezvous with a command-and-control (C&C) server, (2) DNS fast flux as a way to hide the location of malicious servers, and (3) DNS as a carrier channel for C&C communications.This project explores the development of a scalable, hierarchical machine-learning stack, called HIMALAYAS, which specializes in algorithms for automatically mining DNS data for malware activity. In particular, we are interested in isolating both ordered and unordered sets of malware domain groups whose access patterns are temporally and logically correlated. HIMALAYAS performs a task of increasing complexity at each level ? starting from scalable clustering and feature selection at lower levels, to more advanced malware domain subsequence identification algorithms at higher levels. It has multiple benefits, including speed, accuracy, interpretability, and ability to use domain knowledge, which makes it very well suited for malware analysis and related tasks. The analysis by HIMALAYAS should accelerate the identification and takedown of malware domains on the Internet and improve services such as Google SafeSearch. The machine-learning stack developed as part of the HIMALAYAS project has broader application to many important data mining problems, e.g., in financial data analysis, and mining user patterns from web access logs. The project provides opportunities for students to participate in the development and transition of the technology.
域名系统(DNS)协议通过实现域名与IP地址的双向关联而在互联网的操作中起着重要作用。 它也越来越多地被恶意软件滥用,特别是僵尸网络,通过使用:(1)自动域生成算法与命令和控制(C C)服务器会合,(2)DNS快速流量作为隐藏恶意服务器位置的一种方式,以及(3)DNS作为C C通信的载体通道。特别是,我们有兴趣在隔离有序和无序集的恶意软件域组的访问模式是时间和逻辑相关。 HIMALAYAS在每个级别上执行增加复杂性的任务?从较低级别的可扩展聚类和特征选择开始,到较高级别的更高级的恶意软件域子序列识别算法。它具有多种优势,包括速度,准确性,可解释性和使用领域知识的能力,这使得它非常适合恶意软件分析和相关任务。HIMALAYAS的分析应该会加速互联网上恶意软件域名的识别和删除,并改善谷歌安全搜索等服务。作为HIMALAYAS项目的一部分开发的机器学习堆栈对许多重要的数据挖掘问题有更广泛的应用,例如,金融数据分析,以及从Web访问日志中挖掘用户模式。 该项目为学生提供了参与技术开发和过渡的机会。

项目成果

期刊论文数量(5)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Mobile Application Web API Reconnaissance: Web-to-Mobile Inconsistencies & Vulnerabilities
Bring your own controller: Enabling tenant-defined SDN apps in IaaS clouds
自带控制器:在 IaaS 云中启用租户定义的 SDN 应用程序
Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile Applications
Error-Sensor: Mining Information from HTTP Error Traffic for Malware Intelligence
  • DOI:
    10.1007/978-3-030-00470-5_22
  • 发表时间:
    2018-09
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Jialong Zhang;Jiyong Jang;G. Gu;M. Stoecklin;Xin Hu
  • 通讯作者:
    Jialong Zhang;Jiyong Jang;G. Gu;M. Stoecklin;Xin Hu
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Guofei Gu其他文献

Disrupting the SDN Control Channel via Shared Links: Attacks and Countermeasures
通过共享链路破坏SDN控制通道:攻击与对策
  • DOI:
    10.1109/tnet.2022.3169136
  • 发表时间:
    2022-10
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Renjie Xie;Jiahao Cao;Qi Li;Kun Sun;Guofei Gu;Mingwei Xu;Yuan Yang
  • 通讯作者:
    Yuan Yang
Identify User-Input Privacy in Mobile Applications at Large Scale
大规模识别移动应用程序中的用户输入隐私
Rethinking Permission Enforcement Mechanism on Mobile Systems
重新思考移动系统的权限执行机制
NetHCF: Filtering Spoofed IP Traffic With Programmable Switches
NetHCF:使用可编程交换机过滤欺骗性 IP 流量

Guofei Gu的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Guofei Gu', 18)}}的其他基金

NSF Convergence Accelerator Track G: PETS: Programmable Zero-Trust Security for Operating Through 5G Infrastructure
NSF 融合加速器轨道 G:PETS:通过 5G 基础设施运行的可编程零信任安全
  • 批准号:
    2226339
  • 财政年份:
    2022
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
RINGS: NextSec: Zero-Trust, Programmable and Verifiable Security Transformation for NextG
RINGS:NextSec:NextG 的零信任、可编程和可验证安全转型
  • 批准号:
    2148374
  • 财政年份:
    2022
  • 资助金额:
    $ 25万
  • 项目类别:
    Continuing Grant
Community-Building Workshop on Programmable System Security in a Software-Defined World
软件定义世界中的可编程系统安全社区建设研讨会
  • 批准号:
    1841099
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Adversarial Learning via Modeling Interpretation
SaTC:核心:小:通过建模解释进行对抗性学习
  • 批准号:
    1816497
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
EAGER: USBRCCR: Collaborative: Securing Networks in the Programmable Data Plane Era
EAGER:USBRCCR:协作:确保可编程数据平面时代的网络安全
  • 批准号:
    1740791
  • 财政年份:
    2017
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
SDI-CSCS: Collaborative Research: S2OS: Enabling Infrastructure-Wide Programmable Security with SDI
SDI-CSCS:协作研究:S2OS:通过 SDI 实现基础设施范围内的可编程安全性
  • 批准号:
    1700544
  • 财政年份:
    2017
  • 资助金额:
    $ 25万
  • 项目类别:
    Continuing Grant
Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
合作研究:CICI:安全和弹性架构:S3D:用于科学 DMZ 的新的基于 SDN 的安全框架
  • 批准号:
    1642129
  • 财政年份:
    2016
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
NeTS: Small: Detecting Races in SDN Control Plane
NeTS:小型:检测 SDN 控制平面中的竞争
  • 批准号:
    1617985
  • 财政年份:
    2016
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
CAREER: Coordination- and Correlation-based Botnet Defense
职业:基于协调和关联的僵尸网络防御
  • 批准号:
    0954096
  • 财政年份:
    2010
  • 资助金额:
    $ 25万
  • 项目类别:
    Continuing Grant

相似海外基金

TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
  • 批准号:
    1840790
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
  • 批准号:
    1937622
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
  • 批准号:
    1855391
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
  • 批准号:
    1834213
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
  • 批准号:
    1854000
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
  • 批准号:
    1929901
  • 财政年份:
    2018
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
  • 批准号:
    1748127
  • 财政年份:
    2017
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
  • 批准号:
    1801986
  • 财政年份:
    2017
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
  • 批准号:
    1562888
  • 财政年份:
    2016
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
  • 批准号:
    1563848
  • 财政年份:
    2016
  • 资助金额:
    $ 25万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了