课题基金 / 基金详情

TWC: Medium: Collaborative: HIMALAYAS: Hierarchical Machine Learning Stack for Fine-Grained Analysis of Malware Domain Groups

TWC: Medium: Collaborative: HIMALAYAS: Hierarchical Machine Learning Stack for Fine-Grained Analysis of Malware Domain Groups
TWC:媒介:协作:HIMALAYAS:用于恶意软件域组细粒度分析的分层机器学习堆栈
批准号:
1314823
负责人:
Guofei Gu
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2013
资助国家:
美国
项目状态:
已结题
起止时间:
2013-10-01 至 2018-09-30

项目摘要

项目成果

Guofei Gu的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
The domain name system (DNS) protocol plays a significant role in operation of the Internet by enabling the bi-directional association of domain names with IP addresses. It is also increasingly abused by malware, particularly botnets, by use of: (1) automated domain generation algorithms for rendezvous with a command-and-control (C&C) server, (2) DNS fast flux as a way to hide the location of malicious servers, and (3) DNS as a carrier channel for C&C communications.This project explores the development of a scalable, hierarchical machine-learning stack, called HIMALAYAS, which specializes in algorithms for automatically mining DNS data for malware activity. In particular, we are interested in isolating both ordered and unordered sets of malware domain groups whose access patterns are temporally and logically correlated. HIMALAYAS performs a task of increasing complexity at each level ? starting from scalable clustering and feature selection at lower levels, to more advanced malware domain subsequence identification algorithms at higher levels. It has multiple benefits, including speed, accuracy, interpretability, and ability to use domain knowledge, which makes it very well suited for malware analysis and related tasks. The analysis by HIMALAYAS should accelerate the identification and takedown of malware domains on the Internet and improve services such as Google SafeSearch. The machine-learning stack developed as part of the HIMALAYAS project has broader application to many important data mining problems, e.g., in financial data analysis, and mining user patterns from web access logs. The project provides opportunities for students to participate in the development and transition of the technology.
期刊论文(5)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/sp.2018.00039
发表时间: 2018-04
期刊: 2018 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者: [Abner Mendoza;G. Gu]
通讯作者: Abner Mendoza;G. Gu
Bring your own controller: Enabling tenant-defined SDN apps in IaaS clouds
自带控制器:在 IaaS 云中启用租户定义的 SDN 应用程序
DOI: 10.1109/infocom.2017.8057137
发表时间: 2017
期刊: Proc. of 2017 IEEE International Conference on Computer Communications (INFOCOM'17
影响因子: --
作者: [Wang, Haopei, Srivastava, Abhinav, Xu, Lei, Hong, Sungmin, Gu, Guofei]
通讯作者: Gu, Guofei
DOI: 10.1109/sp.2018.00043
发表时间: 2018-05
期刊: 2018 IEEE Symposium on Security and Privacy (SP)
影响因子: --
作者: [Guangliang Yang;Jeff Huang;G. Gu;Abner Mendoza]
通讯作者: Guangliang Yang;Jeff Huang;G. Gu;Abner Mendoza
DOI: 10.1007/978-3-030-00470-5_22
发表时间: 2018-09
期刊:
影响因子: --
作者: [Jialong Zhang;Jiyong Jang;G. Gu;M. Stoecklin;Xin Hu]
通讯作者: Jialong Zhang;Jiyong Jang;G. Gu;M. Stoecklin;Xin Hu
NSF Convergence Accelerator Track G: PETS: Programmable Zero-Trust Security for Operating Through 5G Infrastructure
RINGS: NextSec: Zero-Trust, Programmable and Verifiable Security Transformation for NextG
Community-Building Workshop on Programmable System Security in a Software-Defined World
SaTC: CORE: Small: Adversarial Learning via Modeling Interpretation
海外基金