课题基金 / 基金详情

CAREER: Binary and Virtualization Centric Malware Defense

CAREER: Binary and Virtualization Centric Malware Defense
职业:以二进制和虚拟化为中心的恶意软件防御
批准号:
1664315
负责人:
Heng Yin
金额:
$16.89万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-09-01 至 2018-07-31

项目摘要

项目成果

Heng Yin的其他基金

相似基金

相关文献

中文摘要
翻译
恶意软件(malware)已经成为计算机安全的主要威胁,并将在未来几十年内继续成为计算机安全研究的中心主题。该项目采用以二进制和虚拟化为中心的方法,使用在线和离线分析来有效地击败恶意软件。离线恶意软件分析旨在提取有关新发现的恶意软件实例或软件漏洞的内部工作原理的知识,以建立针对类似攻击的适当防御。在线恶意软件防御旨在建立高效的安全机制,有效地限制恶意行为,并为后续的安全调查收集足够的证据。对于离线恶意软件分析,使用了一种新的基于虚拟化的恶意软件分析平台,在此基础上,将新型推理技术应用于恶意软件分解和漏洞诊断。对于在线恶意软件防御,使用虚拟化的模块级沙箱和执行重放的新技术被协作地用于击败恶意软件。这项研究的结果将通过同行评审的出版物和软件发布来传播。基于这项研究,将开发新的课程材料,模块化实践项目和专业培训教程,以帮助未来的计算机工程师和安全研究人员深入了解恶意软件防御。
英文摘要
Malicious software (malware) has become a major threat to computer security and will continue to be a central theme for computer security research for decades. This project takes a binary and virtualization centric approach to effectively and efficiently defeat malware using both online and offline analysis. Offline malware analysis aims to extract knowledge about the inner-workings for a newly discovered malware instance or software exploit, for the purpose of building up proper defense against similar attacks. Online malware defense aims to build efficient security mechanisms to effectively confine malicious behavior and collect enough evidence for subsequent security investigation. For offline malware analysis, a novel virtualization-based malware analysis platform is used, on top of which new type inference techniques are applied to malware decomposition and vulnerability diagnosis. For online malware defense, new techniques for module-level sandbox and execution replay using virtualization are cooperatively used to defeat malware. The results from this research will be disseminated through both peer-reviewed publications and software release. Based on this research, new course materials, modular hands-on projects, and professional training tutorials will be developed, to help future computer engineers and security researchers gain in-depth knowledge about malware defense.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SaTC: CORE: Small: Concolic-Execution-Centric Fuzzing
  • 批准号:
    2133487
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Heng Yin
  • 依托单位:
SaTC: CORE: Small: Towards Robust and Scalable Search of Binary Code and Data
  • 批准号:
    1719175
  • 项目类别:
    Standard Grant
  • 资助金额:
    $47.68万
  • 财政年份:
    2017
  • 负责人:
    Heng Yin
  • 依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
  • 批准号:
    1054605
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $54.95万
  • 财政年份:
    2011
  • 负责人:
    Heng Yin
  • 依托单位:
TC: Small: Mining Operating System Semantics: Techniques and Applications
  • 批准号:
    1018217
  • 项目类别:
    Standard Grant
  • 资助金额:
    $42.7万
  • 财政年份:
    2010
  • 负责人:
    Heng Yin
  • 依托单位:
国内基金
海外基金
Improving modelling of compact binary evolution.
  • 批准号:
    10903001
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    20.0万元
  • 批准年份:
    2009
  • 负责人:
    史蒂芬
  • 依托单位: