TWC: Medium: Collaborative: Know Thy Enemy: Data Mining Meets Networks for Understanding Web-Based Malware Dissemination

TWC:媒介:协作:了解你的敌人:数据挖掘与网络结合以了解基于 Web 的恶意软件传播

基本信息

  • 批准号:
    1314935
  • 负责人:
  • 金额:
    $ 33.3万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2013
  • 资助国家:
    美国
  • 起止时间:
    2013-09-01 至 2016-07-31
  • 项目状态:
    已结题

项目摘要

How does web-based malware spread? We use the term web-based malware to describe malware that is distributed through websites, and malicious posts in social networks. We are in an arms race against web-based malware distributors; and as in any war, knowledge is power. The more we know about them, the better we can defend ourselves. Our goal is to understand the dissemination of web-based malware by creating "MalScope", a suite of methods and tools that uses cutting-edge approaches to build spatiotemporal models, generators and sampling techniques for malware dissemination. From a scientific point of view, this project brings together two disciplines: Data Mining and Network Security. The outcome is a suite of novel, sophisticated, and scalable techniques and models that will enhance our understanding of malware dissemination at a large scale. We use two types of web-based malware dissemination data: (1) user machines accessing dangerous sites and downloading web-based malware; and (2) Facebook users being exposed to malicious posts. We already have and will continue to obtain more data from our industry partners (e.g. Symantec's WINE project), open-access projects, or collect on our own (e.g MyPageKeeper).The broader impact of our work is that it will enable the development of security solutions for end-users and industry. A 15-minute network outage costs a 200-employee company about $40K, while identity theft costs about $1,500 per person on average. By knowing the enemy better, security researchers and industry can more effectively stop the interconnected manifestations of Internet threats: identity theft, the creation of botnets, and DoS attacks. The PIs have a track record of technology transfer, with collaborators at industrial labs (Yahoo, MSR, Symantec, AT&T, IBM), national labs (LLNL, Sandia), open-source software (``Pegasus''), and spin-off startups (StopTheHacker). Educational impacts include developing a new course, providing publicly available educational material, and open-source software.
基于Web的恶意软件如何传播?我们使用基于Web的恶意软件来描述通过网站分发的恶意软件以及社交网络中的恶意帖子。我们正在与基于网络的恶意软件分销商进行军备竞赛;就像在任何战争中一样,知识就是力量。 我们对他们了解得越多,我们就能越好地保护自己。我们的目标是通过创建“MalScope”来了解基于网络的恶意软件的传播,“MalScope”是一套方法和工具,使用尖端方法来构建用于恶意软件传播的时空模型、生成器和采样技术。从科学的角度来看,该项目汇集了两个学科:数据挖掘和网络安全。其结果是一套新颖,复杂,可扩展的技术和模型,将提高我们对恶意软件传播的大规模理解。我们使用两种基于Web的恶意软件传播数据:(1)用户机器访问危险站点并下载基于Web的恶意软件;(2)Facebook用户暴露于恶意帖子。我们已经并将继续从我们的行业合作伙伴(例如赛门铁克的WINE项目)、开放访问项目或我们自己收集(例如MyPageKeeper)获得更多数据。我们工作的更广泛影响是,它将使最终用户和行业的安全解决方案的开发成为可能。 一家拥有200名员工的公司因15分钟的网络中断而损失约4万美元,而身份盗窃平均每人损失约1,500美元。通过更好地了解敌人,安全研究人员和行业可以更有效地阻止互联网威胁的相互关联的表现形式:身份盗窃,僵尸网络的创建和DoS攻击。PI拥有技术转让的跟踪记录,与工业实验室(Yahoo,MSR,Symantec,AT T,IBM),国家实验室(LLNL,Sandia),开源软件(“Pegasus”)和分拆创业公司(StopTheHacker)的合作者。教育影响包括开发新课程,提供公开的教育材料和开源软件。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Michalis Faloutsos其他文献

iDispatcher: A unified platform for secure planet-scale information dissemination
  • DOI:
    10.1007/s12083-012-0128-8
  • 发表时间:
    2012-04-19
  • 期刊:
  • 影响因子:
    2.600
  • 作者:
    Md Sazzadur Rahman;Guanhua Yan;Harsha V. Madhyastha;Michalis Faloutsos;Stephan Eidenbenz;Mike Fisk
  • 通讯作者:
    Mike Fisk
Performance Evaluation of a New MAC Protocol for the CDMA Interconnection Network
  • DOI:
    10.1007/s11235-005-6628-6
  • 发表时间:
    2005-05-01
  • 期刊:
  • 影响因子:
    2.300
  • 作者:
    Jang Hyun Baek;Michalis Faloutsos;Ho Yeon Chung
  • 通讯作者:
    Ho Yeon Chung
Analyzing Communication Interaction Networks (CINs) in enterprises and inferring hierarchies
分析企业中的通信交互网络 (CIN) 并推断层次结构
  • DOI:
    10.1016/j.comnet.2012.11.028
  • 发表时间:
    2013-07
  • 期刊:
  • 影响因子:
    5.6
  • 作者:
    Yi Wang;Marios Iliofotou;Michalis Faloutsos;Bin Wu
  • 通讯作者:
    Bin Wu
A linear-time optimal-message distributed algorithm for minimum spanning trees
  • DOI:
    10.1007/s00446-004-0107-2
  • 发表时间:
    2004-08-01
  • 期刊:
  • 影响因子:
    2.100
  • 作者:
    Michalis Faloutsos;Mart Molle
  • 通讯作者:
    Mart Molle

Michalis Faloutsos的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Michalis Faloutsos', 18)}}的其他基金

SaTC: CORE: Small: SOFIA: Finding and profiling malware source-code in public archives at scale
SaTC:核心:小型:SOFIA:大规模在公共档案中查找和分析恶意软件源代码
  • 批准号:
    2132642
  • 财政年份:
    2021
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Know Thy Enemy: Data Mining Meets Networks for Understanding Web-Based Malware Dissemination
TWC:媒介:协作:了解你的敌人:数据挖掘与网络结合以了解基于 Web 的恶意软件传播
  • 批准号:
    1638219
  • 财政年份:
    2016
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
NECO: A Graph-Based Approach to Traffic Monitoring and Application Classification
NECO:基于图的流量监控和应用分类方法
  • 批准号:
    1316446
  • 财政年份:
    2012
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
NECO: A Graph-Based Approach to Traffic Monitoring and Application Classification
NECO:基于图的流量监控和应用分类方法
  • 批准号:
    0832069
  • 财政年份:
    2008
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
Collaborative Research: NETS-NBD: RIDR: Towards Robust Inter-Domain Routing: Measurements, Models, and Deployable Tools
协作研究:NETS-NBD:RIDR:迈向稳健的域间路由:测量、模型和可部署工具
  • 批准号:
    0721889
  • 财政年份:
    2007
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Continuing Grant
Collaborative Research: NetMine: Finding Patterns in Network Data
合作研究:NetMine:寻找网络数据中的模式
  • 批准号:
    0208950
  • 财政年份:
    2002
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Continuing Grant
CAREER: Multicast Protocols and Topology Models for the Internet
职业:互联网的组播协议和拓扑模型
  • 批准号:
    9985195
  • 财政年份:
    2000
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant

相似海外基金

TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
  • 批准号:
    1840790
  • 财政年份:
    2018
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Continuing Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
  • 批准号:
    1855391
  • 财政年份:
    2018
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
  • 批准号:
    1834213
  • 财政年份:
    2018
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
  • 批准号:
    1937622
  • 财政年份:
    2018
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
  • 批准号:
    1854000
  • 财政年份:
    2018
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
  • 批准号:
    1929901
  • 财政年份:
    2018
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
  • 批准号:
    1748127
  • 财政年份:
    2017
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
  • 批准号:
    1801986
  • 财政年份:
    2017
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
  • 批准号:
    1562888
  • 财政年份:
    2016
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
  • 批准号:
    1563848
  • 财政年份:
    2016
  • 资助金额:
    $ 33.3万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了