课题基金 / 基金详情

SaTC: CORE: Small: Towards Robust and Scalable Search of Binary Code and Data

SaTC: CORE: Small: Towards Robust and Scalable Search of Binary Code and Data
SaTC:核心:小型:实现二进制代码和数据的稳健且可扩展的搜索
批准号:
1719175
负责人:
Heng Yin
金额:
$47.68万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-09-15 至 2022-08-31

项目摘要

项目成果

Heng Yin的其他基金

相似基金

相关文献

中文摘要
翻译
二进制编码和数据搜索的问题涉及如何以准确、可扩展和健壮的方式从二进制编码和二进制数据中收集有价值的信息。这是许多安全问题的核心,包括漏洞扫描、代码抄袭检测、软件谱系、恶意软件分类、内存取证、虚拟机自省、恶意文档检测等。虽然这个问题并不新鲜,已经提出了大量的解决方案,但没有一个解决方案能够同时达到准确性、可扩展性和健壮性的要求。由于搜索方案的不同,二进制代码和数据搜索存在瓶颈:二进制代码搜索的配对比较不具有伸缩性,基于规则的二进制数据搜索过于僵化,因此对不同平台版本和恶意操作造成的更改不具有健壮性。主要有两个研究方向:1)可扩展的跨平台二进制代码搜索,旨在通过聚类和深度学习从二进制代码中自动学习高级特征,从不同体系结构的大型二进制代码库中快速识别语义等价或相似的代码;2)自适应、高效和健壮的二进制数据分析,旨在通过构建深度神经网络模型,从内存转储和文档等二进制数据中准确识别对象。由于二进制代码和数据搜索是许多安全应用程序的基础,因此对这些基础的改进可以推动构建在其上的所有安全应用程序的边界。此外,深度学习在二进制代码和数据搜索中的成功应用将彻底改变我们如何从总体上解决许多安全问题,并通过深度学习刺激更多关于安全方向的研究。
英文摘要
The problem of binary code and data search concerns how to glean valuable information from binary code and binary data in an accurate, scalable and robust fashion. This concern is central to many security problems, including vulnerability scanning, code plagiarism detection, software lineage, malware classification, memory forensics, virtual machine introspection, malicious document detection, etc. Although this problem is not new and a great deal of solutions have been proposed, no solutions can achieve the requirements of accuracy, scalability and robustness simultaneously. There are bottlenecks for binary code and data search due to the search schemes: pair-wise comparison for binary code search does not scale, and rule-based binary data search is too rigid and thus not robust against changes caused by different platform versions and malicious manipulations.The proposed work takes a novel approach to the problem of binary code and data search, one that mimics how the human brain recognizes interesting objects from an enormous amount of visual information. There are two research thrusts: 1) scalable cross-platform binary code search, which aims to quickly identify semantically equivalent or similar code from a large binary code base in different architectures, by automatically learning high-level features from binary code via clustering and deep learning; and 2) adaptive, efficient and robust binary data analysis, which aims to accurately identify objects from binary data such as memory dumps and documents, by constructing deep neural network models. Because binary code and data search are foundational for many security applications, advances to these foundations can push the boundary for all the security applications built on top. Moreover, successful application of deep learning onto binary code and data search will revolutionize how we solve many security problems in general and stimulate more research in the direction of security by deep learning.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3243734.3243813
发表时间: 2018-10
期刊: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Wei Song;Heng Yin;Chang Liu;D. Song]
通讯作者: Wei Song;Heng Yin;Chang Liu;D. Song
DOI: 10.1145/3488932.3497768
发表时间: 2022-05
期刊: Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security
影响因子: --
作者: [Wei Song;Xuezixiang Li;Sadia Afroz;Deepali Garg;Dmitry Kuznetsov;Heng Yin]
通讯作者: Wei Song;Xuezixiang Li;Sadia Afroz;Deepali Garg;Dmitry Kuznetsov;Heng Yin
DeepDi: Learning a Relational Graph Convolutional Network Model on Instructions for Fast and Accurate Disassembly
DeepDi:根据指令学习关系图卷积网络模型,实现快速准确的反汇编
DOI: --
发表时间: 2022
期刊: Proceedings of the 31st USENIX Security Symposium
影响因子: --
作者: [Yu, Sheng, Qu, Yu, Hu, Xunchao, Yin, Heng]
通讯作者: Yin, Heng
DOI: 10.1145/3460120.3484587
发表时间: 2021-01
期刊: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者: [Xuezixiang Li;Qu Yu;Heng Yin]
通讯作者: Xuezixiang Li;Qu Yu;Heng Yin
SaTC: CORE: Small: Concolic-Execution-Centric Fuzzing
  • 批准号:
    2133487
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2022
  • 负责人:
    Heng Yin
  • 依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
  • 批准号:
    1664315
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $16.89万
  • 财政年份:
    2016
  • 负责人:
    Heng Yin
  • 依托单位:
CAREER: Binary and Virtualization Centric Malware Defense
  • 批准号:
    1054605
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $54.95万
  • 财政年份:
    2011
  • 负责人:
    Heng Yin
  • 依托单位:
TC: Small: Mining Operating System Semantics: Techniques and Applications
  • 批准号:
    1018217
  • 项目类别:
    Standard Grant
  • 资助金额:
    $42.7万
  • 财政年份:
    2010
  • 负责人:
    Heng Yin
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: