CRII: SaTC: Leveraging Userland In-Memory Objects for Cybercrime Investigations and Malware Classification

CRII:SaTC:利用用户态内存对象进行网络犯罪调查和恶意软件分类

基本信息

  • 批准号:
    1850054
  • 负责人:
  • 金额:
    $ 17.5万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2019
  • 资助国家:
    美国
  • 起止时间:
    2019-06-01 至 2022-05-31
  • 项目状态:
    已结题

项目摘要

On mobile devices, the advancement and sophistication in application development and the great reliance on their functionality daily by many users makes them a critical piece of evidence for digital investigations. This project focuses on the reconstruction of app execution to recover user and fingerprint malware activities on mobile devices. The research will provide a methodology for investigators to easily outline user actions and strategies, and possible malware attack blueprint without the need for prior knowledge of the target application logic. This project will further advance digital forensics capabilities, by engaging both undergraduate and graduate students in memory forensics research.By leveraging in-memory artifacts for execution reconstruction and malware classification, this project develops app-agnostic memory forensics utilities for investigating Android applications. The solution will recreate program execution slices from residual in-memory userland data objects and their metadata and then map them to the loaded images recovered from the code section of the process memory to determine the exact components and program flows that generated the user's activity. The advantage of this technique is it gives the investigator a clear picture of the program flow path, showing a sequence of user events and the data involved. The newly reconstructed in-memory program slices and loaded image files will then further serve as input feature vectors to two distinct modalities in a multimodal learning malware classification scheme. These unique features which together represent app functionality and code structure when applied in the multimodal algorithm will result in a more robust and resilient malware fingerprint that can detect similar and obfuscated variants with a high degree of accuracy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
在移动设备上,应用程序开发的先进性和复杂性以及许多用户每天对其功能的极大依赖使它们成为数字调查的关键证据。本项目侧重于重建应用程序执行,以恢复移动设备上的用户和指纹恶意软件活动。该研究将为调查人员提供一种方法,可以轻松概述用户操作和策略,以及可能的恶意软件攻击蓝图,而无需事先了解目标应用程序逻辑。该项目将通过吸引本科生和研究生参与记忆取证研究,进一步提高数字取证能力。通过利用内存构件进行执行重建和恶意软件分类,该项目开发了与应用程序无关的内存取证工具,用于调查Android应用程序。该解决方案将从内存中剩余的用户区数据对象及其元数据中重新创建程序执行片,然后将它们映射到从进程内存的代码部分恢复的加载映像,以确定生成用户活动的确切组件和程序流。这种技术的优点是,它为研究者提供了程序流程路径的清晰图像,显示了用户事件的序列和所涉及的数据。在多模态学习恶意软件分类方案中,新重构的内存程序切片和加载的图像文件将进一步作为两种不同模态的输入特征向量。当应用于多模态算法时,这些独特的功能共同代表了应用程序的功能和代码结构,将产生更强大和有弹性的恶意软件指纹,可以以高度准确的方式检测相似和混淆的变体。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
App-Agnostic Post-Execution Semantic Analysis of Android In-Memory Forensics Artifacts
Object Allocation Pattern as an Indicator for Maliciousness - An Exploratory Analysis
对象分配模式作为恶意指标 - 探索性分析
  • DOI:
    10.1145/3422337.3450322
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Hussaini, Adamu;Zahran, Bassam;Ali-Gombe, Aisha
  • 通讯作者:
    Ali-Gombe, Aisha
IIoT-ARAS: IIoT/ICS Automated Risk Assessment System for Prediction and Prevention
IIoT-ARAS:用于预测和预防的 IIoT/ICS 自动风险评估系统
  • DOI:
    10.1145/3422337.3450320
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Zahran, Bassam;Hussaini, Adamu;Ali-Gombe, Aisha
  • 通讯作者:
    Ali-Gombe, Aisha
Evaluating the Reliability of Android Userland Memory Forensics
评估 Android 用户态内存取证的可靠性
I Don't Know Why You Need My Data: A Case Study of Popular Social Media Privacy Policies
我不知道你为什么需要我的数据:流行社交媒体隐私政策的案例研究
  • DOI:
    10.1145/3508398.3519359
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Miller, E.;Rahman Md, R.;Hossain, M.;Ali-Gombe, A.
  • 通讯作者:
    Ali-Gombe, A.
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Aisha Ali-Gombe其他文献

Enhancing privacy policy comprehension through <em>Privacify</em>: A user-centric approach using advanced language models
  • DOI:
    10.1016/j.cose.2024.103997
  • 发表时间:
    2024-10-01
  • 期刊:
  • 影响因子:
  • 作者:
    Justin Woodring;Katherine Perez;Aisha Ali-Gombe
  • 通讯作者:
    Aisha Ali-Gombe
<em>MARS</em>: The first line of defense for IoT incident response
  • DOI:
    10.1016/j.fsidi.2024.301754
  • 发表时间:
    2024-07-01
  • 期刊:
  • 影响因子:
  • 作者:
    Karley M. Waguespack;Kaitlyn J. Smith;Olame A. Muliri;Ramyapandian Vijayakanthan;Aisha Ali-Gombe
  • 通讯作者:
    Aisha Ali-Gombe

Aisha Ali-Gombe的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

相似海外基金

Collaborative Research: SaTC: CORE: Small: Understanding the Limitations of Wireless Network Security Designs Leveraging Wireless Properties: New Threats and Defenses in Practice
协作研究:SaTC:核心:小型:了解利用无线特性的无线网络安全设计的局限性:实践中的新威胁和防御
  • 批准号:
    2316720
  • 财政年份:
    2023
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Understanding the Limitations of Wireless Network Security Designs Leveraging Wireless Properties: New Threats and Defenses in Practice
协作研究:SaTC:核心:小型:了解利用无线特性的无线网络安全设计的局限性:实践中的新威胁和防御
  • 批准号:
    2316719
  • 财政年份:
    2023
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Regulating and Leveraging Types for Security
SaTC:核心:小型:监管和利用安全类型
  • 批准号:
    2247434
  • 财政年份:
    2023
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Continuing Grant
SaTC: CORE: Small: Collaborative: Leveraging community oversight to enhance collective efficacy for privacy and security
SaTC:核心:小型:协作:利用社区监督来提高隐私和安全的集体效力
  • 批准号:
    2326901
  • 财政年份:
    2022
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CISE-MSI: RCBP-RF: SaTC: Privacy Preserving Models Leveraging Mobility Data for Public Health
CISE-MSI:RCBP-RF:SaTC:利用移动数据促进公共卫生的隐私保护模型
  • 批准号:
    2131164
  • 财政年份:
    2022
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Leveraging Physical Side-Channel Information to Build Detection-Based Rowhammer Defenses
SaTC:核心:小型:利用物理侧信道信息构建基于检测的 Rowhammer 防御
  • 批准号:
    2147217
  • 财政年份:
    2021
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Leveraging Physical Side-Channel Information to Build Detection-Based Rowhammer Defenses
SaTC:核心:小型:利用物理侧信道信息构建基于检测的 Rowhammer 防御
  • 批准号:
    2038076
  • 财政年份:
    2021
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
EAGER: SaTC: SAVED: Secure Audio and Video Data from Deepfake Attacks Leveraging Environmental Fingerprints
EAGER:SaTC:SAVED:利用环境指纹保护音频和视频数据免遭 Deepfake 攻击
  • 批准号:
    2039342
  • 财政年份:
    2020
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Collaborative: Leveraging community oversight to enhance collective efficacy for privacy and security
SaTC:核心:小型:协作:利用社区监督来提高隐私和安全的集体效力
  • 批准号:
    1814068
  • 财政年份:
    2018
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: Collaborative: Leveraging community oversight to enhance collective efficacy for privacy and security
SaTC:核心:小型:协作:利用社区监督来提高隐私和安全的集体效力
  • 批准号:
    1814110
  • 财政年份:
    2018
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了