TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
TWC:媒介:协作:迈向企业环境中以二进制为中心的网络取证框架
基本信息
- 批准号:1409534
- 负责人:
- 金额:$ 39.98万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2014
- 资助国家:美国
- 起止时间:2014-09-01 至 2017-04-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Emerging attacks such as Advanced Persistent Threats pose significant threat to cyberspace. These attacks are often stealthy, low-and-slow, and disguised via deceptive campaigns. This research focuses on the forensics of cyber attacks targeting enterprise environments, with the goals of (1) understanding an attack's intent, strategy, steps, and targets, (2) collecting digital evidence for legal proceedings, (3) revealing hidden attack behaviors to prevent or minimize damage.To achieve these goals, an integrated framework is being developed which covers three key aspects - temporal, spatial, and malware-behavioral forensics. All three aspects face the common challenge of analyzing binary executables. More specifically, temporal forensics requires finer-grain program logging for identifying attack provenance and ramifications. The solution is to partition a binary program's execution and data for high-accuracy causal analysis. Malware forensics involves revealing malware behaviors that are multi-stage, condition-guarded, and environment-specific. The solution is a new binary analysis approach that force-executes an unknown binary without input or environment setup and exposes the malware's behavior along the execution paths forced into. Temporal forensics requires understanding unknown file formats and in-memory data structure contents. The solution is to identify and reuse the file parsing/generation and data structure rendering logic in the corresponding binary programs.This research will advance the state-of-the-art in cyber forensics, a critical need as our nation and society become increasingly dependent on cyberinfrastructures. It will help train next-generation cybersecurity experts by exposing students to real case investigations. Under-represented students are being involved in research activities and cyber forensics exercises.
高级持续性威胁等新兴攻击对网络空间构成重大威胁。这些攻击通常是隐蔽的,低而缓慢的,并通过欺骗性的运动来伪装。本研究的重点是针对企业环境的网络攻击取证,其目标是:(1)了解攻击的意图、策略、步骤和目标,(2)为法律诉讼收集数字证据,(3)揭示隐藏的攻击行为,以防止或尽量减少损害。为了实现这些目标,正在开发一个集成框架,它涵盖三个关键方面——时间、空间和恶意软件行为取证。这三个方面都面临分析二进制可执行文件的共同挑战。更具体地说,时间取证需要更细粒度的程序日志记录,以识别攻击的来源和后果。解决方案是对二进制程序的执行和数据进行分区,以便进行高精度的因果分析。恶意软件取证涉及揭示多阶段、条件保护和特定于环境的恶意软件行为。解决方案是一种新的二进制分析方法,在没有输入或环境设置的情况下强制执行未知二进制文件,并在强制执行路径上暴露恶意软件的行为。时间取证需要理解未知的文件格式和内存中的数据结构内容。解决方案是识别和重用相应二进制程序中的文件解析/生成和数据结构呈现逻辑。这项研究将推动最先进的网络取证技术,随着我们的国家和社会越来越依赖网络基础设施,这是一项关键需求。它将通过让学生接触真实的案例调查,帮助培养下一代网络安全专家。代表性不足的学生正在参与研究活动和网络取证练习。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Golden Richard其他文献
Golden Richard的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Golden Richard', 18)}}的其他基金
SFS: Applied Cybersecurity Training
SFS:应用网络安全培训
- 批准号:
1946626 - 财政年份:2020
- 资助金额:
$ 39.98万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Robust Memory Forensics Techniques for Userland Malware Analysis
SaTC:核心:中:用于用户态恶意软件分析的强大内存取证技术
- 批准号:
1703683 - 财政年份:2017
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
TWC:媒介:协作:迈向企业环境中以二进制为中心的网络取证框架
- 批准号:
1732143 - 财政年份:2016
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TC-Small-Virtual Machine Introspection-based Live Forensics for Detection of Malicious Software
用于检测恶意软件的基于 TC-Small-Virtual Machine Introspection 的实时取证
- 批准号:
1016807 - 财政年份:2010
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
CT-ISG: A Comprehensive Data Carving Architecture for Digital Forensics
CT-ISG:用于数字取证的综合数据雕刻架构
- 批准号:
0627226 - 财政年份:2006
- 资助金额:
$ 39.98万 - 项目类别:
Continuing Grant
相似海外基金
TWC SBE: Medium: Collaborative: Brain Hacking: Assessing Psychological and Computational Vulnerabilities in Brain-based Biometrics
TWC SBE:媒介:协作:大脑黑客:评估基于大脑的生物识别技术中的心理和计算漏洞
- 批准号:
1840790 - 财政年份:2018
- 资助金额:
$ 39.98万 - 项目类别:
Continuing Grant
TWC: Medium: Collaborative: Black-Box Evaluation of Cryptographic Entropy at Scale
TWC:媒介:协作:大规模密码熵的黑盒评估
- 批准号:
1937622 - 财政年份:2018
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Building a Privacy-Preserving Social Networking Platform from a Technological and Sociological Perspective
TWC SBE:媒介:协作:从技术和社会学角度构建保护隐私的社交网络平台
- 批准号:
1855391 - 财政年份:2018
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1834213 - 财政年份:2018
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC:媒介:协作:通过机器取消学习有效修复学习系统
- 批准号:
1854000 - 财政年份:2018
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Seal: Secure Engine for AnaLytics - From Secure Similarity Search to Secure Data Analytics
TWC:媒介:协作:Seal:AnaLytics 的安全引擎 - 从安全相似性搜索到安全数据分析
- 批准号:
1929901 - 财政年份:2018
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC: TTP Option: Medium: Collaborative: MALDIVES: Developing a Comprehensive Understanding of Malware Delivery Mechanisms
TWC:TTP 选项:中:协作:马尔代夫:全面了解恶意软件传播机制
- 批准号:
1748127 - 财政年份:2017
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC SBE: Medium: Collaborative: Dollars for Hertz: Making Trustworthy Spectrum Sharing Technically and Economically Viable
TWC SBE:媒介:协作:赫兹美元:使值得信赖的频谱共享在技术上和经济上可行
- 批准号:
1801986 - 财政年份:2017
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: New Protocols and Systems for RAM-Based Secure Computation
TWC:媒介:协作:基于 RAM 的安全计算的新协议和系统
- 批准号:
1562888 - 财政年份:2016
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant
TWC: Medium: Collaborative: Systems, Tools, and Techniques for Executing, Managing, and Securing SGX Programs
TWC:媒介:协作:用于执行、管理和保护 SGX 程序的系统、工具和技术
- 批准号:
1563848 - 财政年份:2016
- 资助金额:
$ 39.98万 - 项目类别:
Standard Grant