TWC: Small: Understanding Anti-Analysis Defenses in Malicious Code
TWC: Small: Understanding Anti-Analysis Defenses in Malicious Code
批准号:
1525820
负责人:
Saumya Debray
金额:
$51.48万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2019-08-31
中文摘要
网络安全问题涵盖各种规模的计算机系统,几乎影响到我们日常生活的方方面面。这使得在网络威胁发展时准确检测并迅速做出反应从根本上说是重要的。该项目旨在开发技术和工具,以加快了解和应对新的网络威胁的进程。恶意软件(Malware)的作者通常会试图使恶意软件隐身,以避免被检测到。在许多情况下,这涉及旨在阻碍安全分析人员进行分析工作的各种技术;我们将这些技术称为反分析防御。当遇到这种防御时,安全分析师必须识别并禁用它们,以便观察和理解其真实行为,从而制定对策。目前做到这一点的方法既缓慢又繁琐。该项目旨在开发高度通用、高效和强大的自动化技术,以加快识别和理解恶意软件中的反分析防御措施的过程,目标是为安全分析人员提供工具,帮助他们在新的网络威胁发展时快速做出反应。恶意软件(恶意软件)通常使用各种反分析和反篡改防御措施来阻碍分析和逆向工程。目前,消除这种防御需要大量的人工干预,因此既繁琐又耗时。该项目开发基于语义的技术来自动化大部分或全部工作,从而加速识别和中和此类防御的过程。该项目专注于分析采用各种反分析和反篡改防御措施的程序。该项目将特别侧重于以下研究问题:*检测。环境观测的特征如何转化为反分析防御的检测算法?如何使检测算法通用?*精确度。影响此类检测算法精度的因素有哪些?如何提高精度?*性能。对低级代码进行复杂的分析可能代价高昂。与此同时,遇到的大量新恶意软件使分析变得高效变得重要。如何才能使这样的检测算法变得足够有效,从而变得实用?*隐形防御。如何使环境检查具有静态和动态隐蔽性?对反分析检测算法的影响是什么?为了使这种反分析技术长盛不衰,重要的是它们必须是通用的,即对可能应用的防御的性质或形式做出尽可能少的假设。为此,该项目将明确阐述其开发的技术背后的假设。通过指出哪些方面的假设可能被削弱或取消,可以预期这将为研究提供新的方向。这项研究的潜在贡献既有技术上的,也有社会上的。更轻松地中和恶意软件部署的反分析防御的能力将使安全研究人员能够快速响应新的和正在出现的恶意软件威胁。这将起到限制此类恶意软件造成的破坏范围的效果,并提高我们网络基础设施的安全性和可靠性。此外,该项目将让研究生和本科生参与研究的各个方面,从而有助于发展一支高技能的劳动力队伍。最后,作为项目一部分开发的软件将提供给更广泛的研究界,从而协助和支持这一领域的其他研究项目。
英文摘要
The problem of cyber-security encompasses computer systems of all sizes and affects almost all aspects of our day-to-day lives. This makes it fundamentally important to detect accurately and respond quickly to cyber-threats as they develop. This project aims to develop techniques and tools that can accelerate the process of understanding and responding to new cyber-threats as they develop. The authors of malicious software (malware) usually try to make the malware stealthy in order to avoid detection. In many cases, this involves a variety of techniques aimed at hindering analysis efforts by security analysts; we refer to such techniques as anti-analysis defenses. When confronted by such defenses, security analysts have to identify and disable them in order to observe and understand its real behaviors and thereby develop countermeasures. Current approaches for doing this are slow and cumbersome. This project aims to develop highly general, efficient, and robust automated techniques for speeding up the process of identifying and understanding anti-analysis defenses in malware, with the goal of providing security analysts with tools that can help them respond quickly to new cyber-threats as they develop.Malicious software (malware) usually employs a variety of anti-analysis and anti-tampering defenses to hinder analysis and reverse engineering. Currently, neutralizing such defenses requires a lot of manual intervention and is therefore tedious and time-consuming. This project develops semantics-based techniques to automate most or all of this effort and so accelerate the process of identifying and neutralizing such defenses. The project focusses on analyzing programs that employ a variety of anti-analysis and anti-tampering defenses. In particular, the project will focus on the following research questions:* Detection. How do characterizations of environmental observations translate to detection algorithms for anti-analysis defenses? How can the detection algorithms be made general?* Precision. What factors affect the precision of such detection algorithms? How can the precision be improved?* Performance. Sophisticated analysis of low-level code can be expensive. At the same time, the high volumes of new malware that are encountered make it important for analyses to be efficient. How can such detection algorithms be made efficient enough to be practical?*Stealthy Defenses. How can environment checks be made statically and dynamically stealthy? What are the implications for anti-analysis detection algorithms?In order for such anti-anti-analysis techniques to have longevity, it is important that they be general, i.e., make as few assumptions as possible about the nature or form of the defenses that may have been applied. To this end, the project will articulate explicitly the assumptions underlying the techniques it develops. This can be expected to suggest new directions for research by indicating where assumptions may be weakened or removed. The potential contributions of this research are both technical and societal. The ability to more easily neutralize anti-analysis defenses deployed by malware will allow security researchers to respond to new and emerging malware threats quickly. This will have the effect of limiting the scope of the damage caused by such malware, and improve the security and reliability of our cyber-infrastructure. Additionally, the project will involve graduate and undergraduate students in all aspects of the research and thereby contribute to the development of a highly skilled workforce. Finally, software developed as part of the project will be made available to the broader research community, thereby assisting and supporting other research projects in this area.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Reasoning about dependencies and information flow in dynamic code
-
批准号:1908313
-
项目类别:Standard Grant
-
资助金额:$51.53万
-
财政年份:2019
-
负责人:Saumya Debray
-
依托单位:
TC: Small: Simplification of Obfuscated Executables
-
批准号:1115829
-
项目类别:Standard Grant
-
资助金额:$36.93万
-
财政年份:2011
-
负责人:Saumya Debray
-
依托单位:
SHF: Small: Reverse Engineering Obfuscated Executables
-
批准号:1016058
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2010
-
负责人:Saumya Debray
-
依托单位:
A Holistic Approach to Compiler-Assisted Optimization of Software Systems
-
批准号:0410918
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:Saumya Debray
-
依托单位:
ITR/SY (CISE): Software Improvement Through Binary Rewriting
-
批准号:0113633
-
项目类别:Continuing Grant
-
资助金额:$37.29万
-
财政年份:2001
-
负责人:Saumya Debray
-
依托单位:
Compiler Techniques for Code Compression
-
批准号:0073394
-
项目类别:Continuing Grant
-
资助金额:$26.42万
-
财政年份:2000
-
负责人:Saumya Debray
-
依托单位:
Optimizing Program Performance at Link and Run-Time
-
批准号:9720738
-
项目类别:Standard Grant
-
资助金额:$35.79万
-
财政年份:1998
-
负责人:Saumya Debray
-
依托单位:
Low Level Aspects of Partial Evaluation and Program Specialization
-
批准号:9711166
-
项目类别:Standard Grant
-
资助金额:$12.55万
-
财政年份:1997
-
负责人:Saumya Debray
-
依托单位:
U.S.-E.C. Cooperative Research: Collaborative Research on Analysis and Implementation of Concurrent Constraint Programming
-
批准号:9414105
-
项目类别:Standard Grant
-
资助金额:$4.5万
-
财政年份:1995
-
负责人:Saumya Debray
-
依托单位:
Scalable Parallel Implementations of Declarative Programming Languages
-
批准号:9502826
-
项目类别:Continuing Grant
-
资助金额:$18.07万
-
财政年份:1995
-
负责人:Saumya Debray
-
依托单位:
Implementation of Concurrent Constraint Programming Languages
-
批准号:9123520
-
项目类别:Continuing Grant
-
资助金额:$16.44万
-
财政年份:1992
-
负责人:Saumya Debray
-
依托单位:
Development of Effective Flow Analysis Systems for Logic Programs
-
批准号:8901283
-
项目类别:Standard Grant
-
资助金额:$17.17万
-
财政年份:1990
-
负责人:Saumya Debray
-
依托单位:
Analysis and Optimization of Logic Programs
-
批准号:8702939
-
项目类别:Continuing Grant
-
资助金额:$15.29万
-
财政年份:1988
-
负责人:Saumya Debray
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: