CRII: SaTC: GEMINI: Guided Execution Based Mobile Advanced Persistent Threat Investigation
CRII: SaTC: GEMINI: Guided Execution Based Mobile Advanced Persistent Threat Investigation
批准号:
1755721
负责人:
Brendan Saltaformaggio
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-02-01 至 2020-01-31
中文摘要
高级持续威胁(APT)活动越来越多地针对跨企业、政府和金融机构部署的移动设备。不幸的是,即使是对备受瞩目的APT攻击的反应也慢得令人望而却步,这表明当局缺乏快速调查正在进行的攻击的能力(在几小时或几天内,而不是几个月)。为了应对这一挑战,这项研究从记忆图像取证技术(特别是最近引入的一种称为引导执行的技术)的最新发展中获得了灵感,该技术提供了目前APT调查中无与伦比的快速证据收集和犯罪调查能力。这项研究正在开发一个名为Gemini的综合框架,它将现代记忆取证的目标从调查物理世界的犯罪转移到APT运动。基于对单个内存图像的分析-在怀疑发生攻击后从Android设备收集-双子座提供了以下APT调查能力:(1)基于探索性引导执行技术,双子座可以搜索并重新创建以前实施的APT攻击阶段。(2)除了调查以前的攻击执行情况外,双子座还通过使用预先准备的内存图像数据对隐藏/潜在的未来攻击行为的执行进行“木偶表演”,从而揭示隐藏的/潜在的未来攻击行为。(3)在探索未来的有效载荷后,双子座可以进一步利用其引导执行能力来补救观察到的攻击策略。这项工作通过推进针对移动设备的APT战役的研究和开发技术,直接为国家安全做出贡献。此外,这项研究的结果正在公之于众,目的是加强发现和增强这一领域未来的研究能力,并有助于开发侧重于恶意软件分析和反向工程的新课程材料。
英文摘要
Advanced persistent threat (APT) campaigns are increasingly targeting mobile devices deployed across corporations, governments, and financial institutions. Unfortunately, prohibitively slow responses to even high-profile APT attacks have shown that authorities lack the capability to quickly investigate ongoing attacks (in a matter of hours or days rather than months). To address this challenge, this research draws inspiration from recent developments in memory image forensics (in particular a recently introduced technique called guided execution), which has provided rapid evidence collection and crime investigation capabilities currently unparalleled in APT investigation. This research is developing an integrated framework, called GEMINI, which shifts the goal of modern memory forensics from the investigation of physical-world crimes to APT campaigns. Based on the analysis of only a single memory image --- collected from an Android device after an attack is suspected --- GEMINI provides the following set of APT investigation capabilities: (1) Based on exploratory guided execution techniques, GEMINI can search for and re-create previously enacted APT attack stages. (2) Beyond investigating prior attack execution, GEMINI enables the revelation of hidden/potential future attack behaviors by 'puppeteering' their executing with pre-staged memory image data. (3) After exploring future payloads, GEMINI can further leverage its guided execution capabilities for the remediation of the observed attack strategies.This work directly contributes to national security by advancing research in and developing techniques for the investigation of APT campaigns targeting mobile devices. In addition, the results of this research are being made publicly available with the goal of enhancing discovery and empowering future research in this area as well as contributing to the development of new curriculum materials focused on malware analysis and reverse engineering.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
[Omar Alrawi;Chaoshun Zuo;Ruian Duan;R. Kasturi;Zhiqiang Lin;Brendan Saltaformaggio]
通讯作者:
Omar Alrawi;Chaoshun Zuo;Ruian Duan;R. Kasturi;Zhiqiang Lin;Brendan Saltaformaggio
CAREER: GLEAN: Gearing Rapid Malware Forensics Toward Holistic Mobile Botnet Takedown
-
批准号:2143689
-
项目类别:Continuing Grant
-
资助金额:$51.98万
-
财政年份:2022
-
负责人:Brendan Saltaformaggio
-
依托单位:
SaTC: CORE: Medium: Collaborative: Doctor WHO: Investigation and Prevention of Online Content Management System Abuse
-
批准号:1916550
-
项目类别:Standard Grant
-
资助金额:$45.07万
-
财政年份:2019
-
负责人:Brendan Saltaformaggio
-
依托单位:
海外基金