CRII: SaTC: Towards Paving the Way for Large-Scale Malware Analysis: New Directions in Generic Binary Unpacking

CRII:SaTC:为大规模恶意软件分析铺平道路:通用二进制解包的新方向

基本信息

  • 批准号:
    1850434
  • 负责人:
  • 金额:
    $ 17.5万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2019
  • 资助国家:
    美国
  • 起止时间:
    2019-05-01 至 2022-04-30
  • 项目状态:
    已结题

项目摘要

Malware, with harmful intent to compromise computer systems, has been one of the significant challenges to the Internet. Driven by the rich profit, relentless malware developers apply various obfuscation schemes to circumvent malware detection. Binary packing is the most common obfuscation adopted by malware authors to camouflage malicious code and defeat popular signature-based malware detection. Binary packing first encrypts or compresses malware code as data, making it immune to static analysis. At run time, the attached unpacking routine writes the decoded code to memory and then resumes malicious payload execution. Over the past two decades, packed malware has been a challenge in the anti-malware landscape. This project addresses this problem from new angles and advances the state of the art in terms of better performance and stronger anti-analysis resistance. The project's novelties are new methods and efficient tools to extract packed malware payload without the prior knowledge of packers. The project's impacts are paving the way for large-scale malware analysis and helping people respond to emerging malware attacks promptly.Existing generic binary unpacking work suffers from high runtime overhead and lack of anti-analysis resistance. This project conducts an in-depth study on an enormous variety of malware packers and reveals promising research directions to address the long-standing binary unpacking problem. Based on the investigator's encouraging preliminary results, this project goes one step further to address the unsolved challenges and pave the last mile to a complete generic unpacking solution. This project develops a novel machine learning model to extract the semantics of the original entry point. The proposed technique notably outperforms existing search heuristics. This project's hybrid de-obfuscation approaches enable unpacking tools to recover a fully functional version of the original binary, which is the ultimate goal of unpacking technique. To achieve stronger resilience to various anti-analysis attacks, the investigator advances the use of hardware supported lower-level features to detecting the end of unpacking. The proposed methods can handle a broader range of malware packers, even brand new packers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
恶意软件具有危害计算机系统的恶意,一直是互联网面临的重大挑战之一。在丰厚利润的推动下,无情的恶意软件开发人员应用各种混淆方案来规避恶意软件检测。二进制打包是恶意软件作者用来伪装恶意代码和挫败流行的基于签名的恶意软件检测的最常见的混淆方法。二进制打包首先将恶意软件代码加密或压缩为数据,使其不受静态分析的影响。在运行时,附加的解包例程将解码的代码写入内存,然后恢复恶意有效负载执行。在过去的二十年里,打包恶意软件一直是反恶意软件领域的一个挑战。该项目从新的角度解决了这一问题,并在更好的性能和更强的抗分析能力方面提高了技术水平。该项目的新颖性是在打包者事先不知道的情况下提取打包的恶意软件有效载荷的新方法和有效工具。该项目的影响正在为大规模恶意软件分析铺平道路,并帮助人们快速应对新出现的恶意软件攻击。现有的通用二进制解包工作存在运行时开销高且缺乏反分析能力的问题。这个项目对大量的恶意软件打包程序进行了深入的研究,并揭示了解决长期存在的二进制解包问题的有前途的研究方向。基于研究人员令人鼓舞的初步结果,该项目进一步解决了未解决的挑战,并为完整的通用拆包解决方案铺平了最后一英里。该项目开发了一种新的机器学习模型来提取原始入口点的语义。该方法的性能明显优于现有的搜索启发式算法。该项目的混合反模糊方法使解包工具能够恢复原始二进制文件的全功能版本,这是解包技术的最终目标。为了实现对各种反分析攻击的更强的弹性,调查者提出了使用硬件支持的底层特征来检测解包结束。建议的方法可以处理更广泛的恶意软件打包程序,甚至是全新的打包程序。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(14)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based Virtualization
Obfuscation-Resilient Executable Payload Extraction From Packed Malware
  • DOI:
  • 发表时间:
    2021
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
  • 通讯作者:
    Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
Chosen-Instruction Attack Against Commercial Code Virtualization Obfuscators
VAHunt: Warding Off New Repackaged Android Malware in App-Virtualization's Clothing
PatchScope: Memory Object Centric Patch Diffing
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Jiang Ming其他文献

Carbon, Nitrogen and Phosphorus Contents of Wetland Soils in Relation to Environment Factors in Northeast China
东北地区湿地土壤碳、氮、磷含量与环境因子的关系
  • DOI:
    10.1007/s13157-016-0856-2
  • 发表时间:
    2017-01
  • 期刊:
  • 影响因子:
    2
  • 作者:
    Liu Ying;Jiang Ming;Lu Xianguo;Lou Yanjing;Liu Bo
  • 通讯作者:
    Liu Bo
Enhanced Adaptive Polar-Linear Interpolation Aided Channel Estimation
增强型自适应极线性插值辅助信道估计
EFFECTS OF NITROGEN ADDITIONS ON SOIL SEED BANK OF A FRESHWATER MARSH IN SANJIANG PLAIN, NORTHEASTERN CHINA: A SHORT-TERM STUDY
氮添加对东北三江平原淡水沼泽土壤种子库的影响:一项短期研究
A Straightforward Updating Criterion for 2-D/3-D Hybrid Discontinuous Galerkin Time-Domain Method Controlling Comparative Error
控制比较误差的2-D/3-D混合间断伽辽金时域方法的直接更新准则
Fuzzy synthetic evaluation of water quality of Naoli River using parameter correlation analysis
参数相关分析模糊挠力河水质综合评价
  • DOI:
    10.1007/s11769-008-0361-5
  • 发表时间:
    2008-11
  • 期刊:
  • 影响因子:
    3.4
  • 作者:
    Wang Jianhua;Lu Xianguo;Tian Jinghan;Jiang Ming
  • 通讯作者:
    Jiang Ming

Jiang Ming的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Jiang Ming', 18)}}的其他基金

SaTC: CORE: Small: A Transparent and Customizable Android Container-Based Virtualization Architecture for Dynamic Malware Analysis
SaTC:CORE:Small:用于动态恶意软件分析的透明且可定制的基于 Android 容器的虚拟化架构
  • 批准号:
    2312185
  • 财政年份:
    2022
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
SaTC: CORE: Small: A Transparent and Customizable Android Container-Based Virtualization Architecture for Dynamic Malware Analysis
SaTC:CORE:Small:用于动态恶意软件分析的透明且可定制的基于 Android 容器的虚拟化架构
  • 批准号:
    2128703
  • 财政年份:
    2021
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
TWC: Small: Collaborative: Advancing Anonymity Against an AS-level Adversary
TWC:小型:协作:针对 AS 级对手推进匿名性
  • 批准号:
    1423163
  • 财政年份:
    2014
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant

相似海外基金

CRII: SaTC: Towards a Secure and Efficient Ethereum P2P Network with Client Diversity
CRII:SaTC:迈向具有客户端多样性的安全高效的以太坊 P2P 网络
  • 批准号:
    2347486
  • 财政年份:
    2024
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
CRII:SaTC:了解图神经网络对抗图扰动的鲁棒性
  • 批准号:
    2241713
  • 财政年份:
    2023
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Understanding and Defending Against New Waves of Online Hate
CRII:SaTC:理解和防御新一波的网络仇恨
  • 批准号:
    2245983
  • 财政年份:
    2023
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Data-effective and Cost-efficient Security Attack Detections
CRII:SaTC:迈向数据有效且经济高效的安全攻击检测
  • 批准号:
    2245968
  • 财政年份:
    2023
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Detecting and Mitigating Vulnerabilities
CRII:SaTC:致力于检测和缓解漏洞
  • 批准号:
    2153474
  • 财政年份:
    2022
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: RUI: Towards Trustworthy and Accountable IoT Data Marketplaces
CRII:SaTC:RUI:迈向值得信赖和负责任的物联网数据市场
  • 批准号:
    2153464
  • 财政年份:
    2022
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Trustworthy and Accountable IoT Data Marketplaces
CRII:SaTC:迈向值得信赖和负责任的物联网数据市场
  • 批准号:
    2231085
  • 财政年份:
    2022
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Secure and Privacy-preserving Input on Augmented Reality Systems
CRII:SaTC:增强现实系统的安全和隐私保护输入
  • 批准号:
    2153397
  • 财政年份:
    2022
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Understanding Typing Privacy: Vulnerabilities and Protection
CRII:SaTC:了解打字隐私:漏洞和保护
  • 批准号:
    1948547
  • 财政年份:
    2020
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
CRII: SaTC: Towards Efficient and Scalable Crowdsourced Vulnerability-Discovery using Bug-Bounty Programs
CRII:SaTC:使用错误赏金计划实现高效且可扩展的众包漏洞发现
  • 批准号:
    1850510
  • 财政年份:
    2019
  • 资助金额:
    $ 17.5万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了