TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
TWC: Medium: Collaborative: Towards a Binary-Centric Framework for Cyber Forensics in Enterprise Environments
批准号:
1409668
负责人:
Dongyan Xu
金额:
$80.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2014
资助国家:
美国
项目状态:
已结题
起止时间:
2014-09-01 至 2019-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Emerging attacks such as Advanced Persistent Threats pose significant threat to cyberspace. These attacks are often stealthy, low-and-slow, and disguised via deceptive campaigns. This research focuses on the forensics of cyber attacks targeting enterprise environments, with the goals of (1) understanding an attack's intent, strategy, steps, and targets, (2) collecting digital evidence for legal proceedings, (3) revealing hidden attack behaviors to prevent or minimize damage.To achieve these goals, an integrated framework is being developed which covers three key aspects - temporal, spatial, and malware-behavioral forensics. All three aspects face the common challenge of analyzing binary executables. More specifically, temporal forensics requires finer-grain program logging for identifying attack provenance and ramifications. The solution is to partition a binary program's execution and data for high-accuracy causal analysis. Malware forensics involves revealing malware behaviors that are multi-stage, condition-guarded, and environment-specific. The solution is a new binary analysis approach that force-executes an unknown binary without input or environment setup and exposes the malware's behavior along the execution paths forced into. Temporal forensics requires understanding unknown file formats and in-memory data structure contents. The solution is to identify and reuse the file parsing/generation and data structure rendering logic in the corresponding binary programs.This research will advance the state-of-the-art in cyber forensics, a critical need as our nation and society become increasingly dependent on cyberinfrastructures. It will help train next-generation cybersecurity experts by exposing students to real case investigations. Under-represented students are being involved in research activities and cyber forensics exercises.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Medium: Collaborative: Threat-Aware Defense: Evaluating Threats for Continuous Improvement
-
批准号:1801601
-
项目类别:Standard Grant
-
资助金额:$39.98万
-
财政年份:2018
-
负责人:Dongyan Xu
-
依托单位:
NeTS: Small: Towards Exposing and Mitigating End-to-End TCP Performance and Fairness Issues in Data Center Networks
-
批准号:1219004
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2012
-
负责人:Dongyan Xu
-
依托单位:
TC: EAGER: Binary-based Data Structure Revelation for Memory Forensics
-
批准号:1049303
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2010
-
负责人:Dongyan Xu
-
依托单位:
Collaborative Research: II-New: OpenVMI: A Software Instrument for Virtual Machine Introspection
-
批准号:0855141
-
项目类别:Standard Grant
-
资助金额:$25.5万
-
财政年份:2009
-
负责人:Dongyan Xu
-
依托单位:
CSR-EHS: Collaborative Research: H-Media: The Holistic-Multistream Environment for Distributed Immersive Applicatons
-
批准号:0720665
-
项目类别:Continuing Grant
-
资助金额:$14.5万
-
财政年份:2007
-
负责人:Dongyan Xu
-
依托单位:
CT-ISG: Collaborative Proposal : Enabling Detection of Elusive Malware by Going Out of the Box with Semantically Reconstructed View (OBSERV)
-
批准号:0716444
-
项目类别:Standard Grant
-
资助金额:$13.0万
-
财政年份:2007
-
负责人:Dongyan Xu
-
依托单位:
CAREER: Towards Virtual Distributed Environments in a Shared Distributed Infrastructure
-
批准号:0546173
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2006
-
负责人:Dongyan Xu
-
依托单位:
SGER: Collaborative Research: NMI Development (CISE): Self-Managing Distributed Virtual Environments
-
批准号:0504261
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Dongyan Xu
-
依托单位:
SCI: NMI DEPLOYMENT(ENG) nanoHUB
-
批准号:0438246
-
项目类别:Cooperative Agreement
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Dongyan Xu
-
依托单位:
海外基金