TWC: Medium: Collaborative: Know Thy Enemy: Data Mining Meets Networks for Understanding Web-Based Malware Dissemination
TWC: Medium: Collaborative: Know Thy Enemy: Data Mining Meets Networks for Understanding Web-Based Malware Dissemination
批准号:
1638219
负责人:
Michalis Faloutsos
金额:
$5.23万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-01-28 至 2017-08-31
中文摘要
基于网络的恶意软件是如何传播的?我们使用术语基于网络的恶意软件来描述通过网站分发的恶意软件,以及社交网络中的恶意帖子。我们正在与基于网络的恶意软件经销商进行军备竞赛;就像在任何战争中一样,知识就是力量。我们对他们了解得越多,我们就越能为自己辩护。我们的目标是通过创建“MalScope”来了解基于Web的恶意软件的传播,MalScope是一套使用尖端方法来构建恶意软件传播的时空模型、生成器和采样技术的方法和工具。从科学的角度来看,这个项目汇集了两个学科:数据挖掘和网络安全。其结果是一套新颖、复杂且可扩展的技术和模型,这些技术和模型将增强我们对恶意软件大规模传播的理解。我们使用两种类型的基于Web的恶意软件传播数据:(1)访问危险站点并下载基于Web的恶意软件的用户机器;(2)暴露在恶意帖子中的Facebook用户。我们已经拥有并将继续从我们的行业合作伙伴(如赛门铁克的葡萄酒项目)、开放获取项目或我们自己收集的数据(如MyPageKeeper)中获得更多数据。我们工作的更广泛影响是,它将使最终用户和行业能够开发安全解决方案。一次15分钟的网络中断给一家拥有200名员工的公司造成的损失约为4万美元,而身份被盗的平均成本约为每人1500美元。通过更好地了解敌人,安全研究人员和行业可以更有效地阻止互联网威胁的相互关联的表现形式:身份盗窃、僵尸网络的创建和DoS攻击。私人投资机构在技术转让方面有着良好的记录,其合作伙伴包括工业实验室(Yahoo、MSR、Symantec、AT&;T、IBM)、国家实验室(LLNL、Sandia)、开源软件(Pegasus)和剥离出来的初创企业(StopTheHacker)。教育影响包括开发一门新课程,提供公开可用的教育材料,以及开放源码软件。
英文摘要
How does web-based malware spread? We use the term web-based malware to describe malware that is distributed through websites, and malicious posts in social networks. We are in an arms race against web-based malware distributors; and as in any war, knowledge is power. The more we know about them, the better we can defend ourselves. Our goal is to understand the dissemination of web-based malware by creating "MalScope", a suite of methods and tools that uses cutting-edge approaches to build spatiotemporal models, generators and sampling techniques for malware dissemination. From a scientific point of view, this project brings together two disciplines: Data Mining and Network Security. The outcome is a suite of novel, sophisticated, and scalable techniques and models that will enhance our understanding of malware dissemination at a large scale. We use two types of web-based malware dissemination data: (1) user machines accessing dangerous sites and downloading web-based malware; and (2) Facebook users being exposed to malicious posts. We already have and will continue to obtain more data from our industry partners (e.g. Symantec's WINE project), open-access projects, or collect on our own (e.g MyPageKeeper).The broader impact of our work is that it will enable the development of security solutions for end-users and industry. A 15-minute network outage costs a 200-employee company about $40K, while identity theft costs about $1,500 per person on average. By knowing the enemy better, security researchers and industry can more effectively stop the interconnected manifestations of Internet threats: identity theft, the creation of botnets, and DoS attacks. The PIs have a track record of technology transfer, with collaborators at industrial labs (Yahoo, MSR, Symantec, AT&T, IBM), national labs (LLNL, Sandia), open-source software ("Pegasus"), and spin-off startups (StopTheHacker). Educational impacts include developing a new course, providing publicly available educational material, and open-source software.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: SOFIA: Finding and profiling malware source-code in public archives at scale
-
批准号:2132642
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2021
-
负责人:Michalis Faloutsos
-
依托单位:
TWC: Medium: Collaborative: Know Thy Enemy: Data Mining Meets Networks for Understanding Web-Based Malware Dissemination
-
批准号:1314935
-
项目类别:Standard Grant
-
资助金额:$33.3万
-
财政年份:2013
-
负责人:Michalis Faloutsos
-
依托单位:
NECO: A Graph-Based Approach to Traffic Monitoring and Application Classification
-
批准号:1316446
-
项目类别:Standard Grant
-
资助金额:$1.88万
-
财政年份:2012
-
负责人:Michalis Faloutsos
-
依托单位:
NECO: A Graph-Based Approach to Traffic Monitoring and Application Classification
-
批准号:0832069
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2008
-
负责人:Michalis Faloutsos
-
依托单位:
Collaborative Research: NETS-NBD: RIDR: Towards Robust Inter-Domain Routing: Measurements, Models, and Deployable Tools
-
批准号:0721889
-
项目类别:Continuing Grant
-
资助金额:$24.5万
-
财政年份:2007
-
负责人:Michalis Faloutsos
-
依托单位:
Collaborative Research: NetMine: Finding Patterns in Network Data
-
批准号:0208950
-
项目类别:Continuing Grant
-
资助金额:$12.0万
-
财政年份:2002
-
负责人:Michalis Faloutsos
-
依托单位:
CAREER: Multicast Protocols and Topology Models for the Internet
-
批准号:9985195
-
项目类别:Standard Grant
-
资助金额:$37.69万
-
财政年份:2000
-
负责人:Michalis Faloutsos
-
依托单位:
海外基金