课题基金 / 基金详情

CRII: SaTC: Leveraging Userland In-Memory Objects for Cybercrime Investigations and Malware Classification

CRII: SaTC: Leveraging Userland In-Memory Objects for Cybercrime Investigations and Malware Classification
CRII:SaTC:利用用户态内存对象进行网络犯罪调查和恶意软件分类
批准号:
1850054
负责人:
Aisha Ali-Gombe
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-06-01 至 2022-05-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
On mobile devices, the advancement and sophistication in application development and the great reliance on their functionality daily by many users makes them a critical piece of evidence for digital investigations. This project focuses on the reconstruction of app execution to recover user and fingerprint malware activities on mobile devices. The research will provide a methodology for investigators to easily outline user actions and strategies, and possible malware attack blueprint without the need for prior knowledge of the target application logic. This project will further advance digital forensics capabilities, by engaging both undergraduate and graduate students in memory forensics research.By leveraging in-memory artifacts for execution reconstruction and malware classification, this project develops app-agnostic memory forensics utilities for investigating Android applications. The solution will recreate program execution slices from residual in-memory userland data objects and their metadata and then map them to the loaded images recovered from the code section of the process memory to determine the exact components and program flows that generated the user's activity. The advantage of this technique is it gives the investigator a clear picture of the program flow path, showing a sequence of user events and the data involved. The newly reconstructed in-memory program slices and loaded image files will then further serve as input feature vectors to two distinct modalities in a multimodal learning malware classification scheme. These unique features which together represent app functionality and code structure when applied in the multimodal algorithm will result in a more robust and resilient malware fingerprint that can detect similar and obfuscated variants with a high degree of accuracy.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3427228.3427244
发表时间: 2020-12
期刊: Proceedings of the 36th Annual Computer Security Applications Conference
影响因子: --
作者: [Aisha I. Ali-Gombe;Alexandra Tambaoan;Angela Gurfolino;G. Richard]
通讯作者: Aisha I. Ali-Gombe;Alexandra Tambaoan;Angela Gurfolino;G. Richard
Object Allocation Pattern as an Indicator for Maliciousness - An Exploratory Analysis
对象分配模式作为恶意指标 - 探索性分析
DOI: 10.1145/3422337.3450322
发表时间: 2021
期刊: ACM CODASPY 2021
影响因子: --
作者: [Hussaini, Adamu, Zahran, Bassam, Ali-Gombe, Aisha]
通讯作者: Ali-Gombe, Aisha
IIoT-ARAS: IIoT/ICS Automated Risk Assessment System for Prediction and Prevention
IIoT-ARAS:用于预测和预防的 IIoT/ICS 自动风险评估系统
DOI: 10.1145/3422337.3450320
发表时间: 2021
期刊: ACM CODASPY 2021
影响因子: --
作者: [Zahran, Bassam, Hussaini, Adamu, Ali-Gombe, Aisha]
通讯作者: Ali-Gombe, Aisha
Evaluating the Reliability of Android Userland Memory Forensics
评估 Android 用户态内存取证的可靠性
DOI: 10.34190/iccws.17.1.54
发表时间: 2022
期刊: 17th International Conference on Information Warfare and Security
影响因子: --
作者: [Sudhakaran, S., Ali-Gombe, A., Case, A., Richard III, G. G.]
通讯作者: Richard III, G. G.
6
    海外基金