课题基金 / 基金详情

TWC: Small: Collaborative: Practical Hardware-Assisted Always-On Malware Detection

TWC: Small: Collaborative: Practical Hardware-Assisted Always-On Malware Detection
TWC:小型:协作:实用的硬件辅助始终在线恶意软件检测
批准号:
1617915
负责人:
Dmitry Ponomarev
金额:
$27.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2020-08-31

项目摘要

项目成果

Dmitry Ponomarev的其他基金

相似基金

相关文献

中文摘要
翻译
该项目探索在硬件中构建对恶意软件检测的支持。随着恶意软件的数量和复杂性的增加,恶意软件检测具有挑战性和资源密集性。恶意软件检测的资源要求限制了其在实践中的使用,使得许多系统上的恶意软件没有得到检查。我们使用低级硬件检测器来识别恶意软件,利用低级特征如硬件事件、指令混合和内存地址模式来识别计算异常。一旦怀疑是恶意软件,我们就通知更高级别的软件检测或保护机制,该机制可以将其资源仅集中在可疑的恶意软件上。该检测器使用低复杂度的机器学习方法,使用在硬件上可行的实现将恶意软件与正常程序分类。该项目探索基于对抗性机器学习的对策,以限制攻击者试图逃避检测,开发硬件和软件检测之间的安全集成,并评估实施权衡。该项目提供了一种新的方法来提高恶意软件检测的有效性,并允许系统在不需要软件监视器所需的大量资源投资的情况下得到持续保护。该项目有望对一个国家迫切需要的领域产生重大影响,以帮助保护系统免受不断扩大的恶意软件威胁。提案中遵循的原则可以推广到不同的计算环境,包括移动电话、云和网络物理系统。
英文摘要
The project explores building support for malware detection in hardware. Malware detection is challenging and resource intensive, as the number and sophistication of malware increases. The resource requirements for malware detection limit its use in practice, leaving malware unchecked on many systems. We use a low level hardware detector to identify malware as a computational anomaly using low level features such as hardware events, instruction mixes and memory address patterns. Once malware is suspected, we inform a higher level software detection or protection mechanism that can focus its resources only on suspected malware. The detector uses low complexity machine learning approaches to classify malware from normal programs using implementations that are feasible in hardware. The project explores countermeasures based on adversarial machine learning to limit attackers trying to evade detection, develops secure integration between the hardware and software detection, and evaluates implementation tradeoffs. The project contributes a new approach to improve the effectiveness of malware detection and to allow systems to be protected continuously without requiring the large resource investment needed by software monitors. The project holds the promise of significantly impacting an area of critical national need to help secure systems against the expanding threats of malware. The principles pursued in the proposal can generalize to different computational environments including mobile phones, clouds, and cyberphysical systems.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Leakage-free Isolated Execution: Architectures and Security Models
  • 批准号:
    2053391
  • 项目类别:
    Standard Grant
  • 资助金额:
    $69.46万
  • 财政年份:
    2021
  • 负责人:
    Dmitry Ponomarev
  • 依托单位:
SaTC: CORE: Small: Microarchitectural side channel attacks and defenses in integrated CPU-GPU systems
  • 批准号:
    2130978
  • 项目类别:
    Standard Grant
  • 资助金额:
    $53.46万
  • 财政年份:
    2021
  • 负责人:
    Dmitry Ponomarev
  • 依托单位:
TWC: Small: Side Channels through Lower-Level Caches: Attacks, Defenses and Security Metrics
  • 批准号:
    1422401
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.19万
  • 财政年份:
    2014
  • 负责人:
    Dmitry Ponomarev
  • 依托单位:
SHF: Small: Architectural Support for Security in the Many-core Age: Threats and Opportunities
  • 批准号:
    1018496
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2010
  • 负责人:
    Dmitry Ponomarev
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: