CRII: SaTC: Towards Paving the Way for Large-Scale Malware Analysis: New Directions in Generic Binary Unpacking
CRII:SaTC:为大规模恶意软件分析铺平道路:通用二进制解包的新方向
基本信息
- 批准号:1850434
- 负责人:
- 金额:$ 17.5万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2019
- 资助国家:美国
- 起止时间:2019-05-01 至 2022-04-30
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Malware, with harmful intent to compromise computer systems, has been one of the significant challenges to the Internet. Driven by the rich profit, relentless malware developers apply various obfuscation schemes to circumvent malware detection. Binary packing is the most common obfuscation adopted by malware authors to camouflage malicious code and defeat popular signature-based malware detection. Binary packing first encrypts or compresses malware code as data, making it immune to static analysis. At run time, the attached unpacking routine writes the decoded code to memory and then resumes malicious payload execution. Over the past two decades, packed malware has been a challenge in the anti-malware landscape. This project addresses this problem from new angles and advances the state of the art in terms of better performance and stronger anti-analysis resistance. The project's novelties are new methods and efficient tools to extract packed malware payload without the prior knowledge of packers. The project's impacts are paving the way for large-scale malware analysis and helping people respond to emerging malware attacks promptly.Existing generic binary unpacking work suffers from high runtime overhead and lack of anti-analysis resistance. This project conducts an in-depth study on an enormous variety of malware packers and reveals promising research directions to address the long-standing binary unpacking problem. Based on the investigator's encouraging preliminary results, this project goes one step further to address the unsolved challenges and pave the last mile to a complete generic unpacking solution. This project develops a novel machine learning model to extract the semantics of the original entry point. The proposed technique notably outperforms existing search heuristics. This project's hybrid de-obfuscation approaches enable unpacking tools to recover a fully functional version of the original binary, which is the ultimate goal of unpacking technique. To achieve stronger resilience to various anti-analysis attacks, the investigator advances the use of hardware supported lower-level features to detecting the end of unpacking. The proposed methods can handle a broader range of malware packers, even brand new packers.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
具有损害计算机系统的有害意图的恶意软件一直是互联网面临的重大挑战之一。在富裕利润的驱动下,无情的恶意软件开发人员应用了各种混淆计划来规避恶意软件检测。二进制包装是恶意软件作者采用的最常见的混淆,以伪装恶意代码并击败流行的基于签名的恶意软件检测。二进制包装首先加密或压缩恶意软件代码作为数据,使其不受静态分析的影响。在运行时,随附的解压缩例程将解码的代码写入内存,然后恢复恶意有效载荷执行。在过去的二十年中,包装的恶意软件一直是反恶意软件景观的挑战。该项目从新的角度解决了这个问题,并以更好的性能和更强的抗分析抗性来提高最新技术的状态。该项目的新颖性是新方法和有效的工具,可以在没有包装工的事先了解的情况下提取包装的恶意软件有效载荷。该项目的影响为大规模恶意软件分析铺平了道路,并帮助人们迅速对新兴的恶意软件攻击做出反应。将通用的二进制解拆箱工作遭受高运行时开销和缺乏抗分析阻力的影响。该项目对各种恶意软件包装工进行了深入的研究,并揭示了有前途的研究方向,以解决长期存在的二进制解开问题。基于研究者的令人鼓舞的初步结果,该项目进一步迈出了一步,以应对未解决的挑战,并在最后一英里为完整的通用解开解决方案铺路。该项目开发了一种新颖的机器学习模型,以提取原始入口点的语义。提出的技术尤其优于现有的搜索启发式方法。该项目的混合脱束方法实现了拆卸工具,以恢复原始二进制功能的功能齐全的版本,这是解开包装技术的最终目标。为了对各种抗分析攻击实现更强的韧性,研究人员推进了使用硬件支持的低级功能来检测解开包装的结束。 所提出的方法可以处理更广泛的恶意软件包装工,甚至全新的包装工。该奖项反映了NSF的法定任务,并且使用基金会的知识分子优点和更广泛的影响评估标准,被认为值得通过评估来获得支持。
项目成果
期刊论文数量(14)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared libraries
- DOI:10.1145/3503222.3507768
- 发表时间:2022-02
- 期刊:
- 影响因子:0
- 作者:Haotian Zhang;Mengfei Ren;Yu Lei;Jiang Ming
- 通讯作者:Haotian Zhang;Mengfei Ren;Yu Lei;Jiang Ming
PolyCruise: A Cross-Language Dynamic Information Flow Analysis
PolyCruise:跨语言动态信息流分析
- DOI:
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Wen Li, Jiang Ming
- 通讯作者:Wen Li, Jiang Ming
Towards Transparent and Stealthy Android OS Sandboxing via Customizable Container-Based Virtualization
- DOI:10.1145/3460120.3484544
- 发表时间:2021-11
- 期刊:
- 影响因子:0
- 作者:Wenna Song;Jiang Ming;Lin Jiang;Yi Xiang;Xuanchen Pan;Jianming Fu;Guojun Peng
- 通讯作者:Wenna Song;Jiang Ming;Lin Jiang;Yi Xiang;Xuanchen Pan;Jianming Fu;Guojun Peng
Obfuscation-Resilient Executable Payload Extraction From Packed Malware
- DOI:
- 发表时间:2021
- 期刊:
- 影响因子:0
- 作者:Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
- 通讯作者:Binlin Cheng;Jiang Ming;Erika A. Leal;Haotian Zhang;Jianming Fu;Guojun Peng;Jean-Yves Marion
Chosen-Instruction Attack Against Commercial Code Virtualization Obfuscators
- DOI:10.14722/ndss.2022.24015
- 发表时间:2022
- 期刊:
- 影响因子:0
- 作者:Shijia Li;Chunfu Jia;Pengda Qiu;Qiyuan Chen;Jiang Ming;Debin Gao
- 通讯作者:Shijia Li;Chunfu Jia;Pengda Qiu;Qiyuan Chen;Jiang Ming;Debin Gao
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Jiang Ming其他文献
On the Ecological Ethics in the Ancient Mongolian Prairie Culture
- DOI:
- 发表时间:
2004 - 期刊:
- 影响因子:0
- 作者:
Jiang Ming - 通讯作者:
Jiang Ming
EFFECTS OF NITROGEN ADDITIONS ON SOIL SEED BANK OF A FRESHWATER MARSH IN SANJIANG PLAIN, NORTHEASTERN CHINA: A SHORT-TERM STUDY
氮添加对东北三江平原淡水沼泽土壤种子库的影响:一项短期研究
- DOI:
- 发表时间:
2016 - 期刊:
- 影响因子:0
- 作者:
Wang Guodong;Jiang Ming;Wang Ming;Wang GD - 通讯作者:
Wang GD
Quantifying the cooling-effects of urban and peri-urban wetlands using remote sensing data: Case study of cities of Northeast China
利用遥感数据量化城市和城郊湿地的降温效应:中国东北城市的案例研究
- DOI:
10.1016/j.landurbplan.2018.10.015 - 发表时间:
2019-02 - 期刊:
- 影响因子:9.1
- 作者:
Xue Zhenshan;Hou Guanglei;Zhang Zhongsheng;Lyu Xianguo;Jiang Ming;Zou Yuanchun;Shen Xiangjin;Wang Jie;Liu Xiaohui - 通讯作者:
Liu Xiaohui
Characterization of Water Quality in Xiao Xingkai Lake: Implications for Trophic Status and Management
小兴凯湖水质特征:对营养状况和管理的影响
- DOI:
10.1007/s11769-021-1199-3 - 发表时间:
2021-05 - 期刊:
- 影响因子:3.4
- 作者:
Yu Shuling;Li Xiaoyu;Wen Bolong;Chen Guoshuang;Hartleyc Anne;Jiang Ming;Li Xiujun - 通讯作者:
Li Xiujun
Wetland recreational agriculture: Balancing wetland conservation and agro-development
湿地休闲农业:平衡湿地保护和农业发展
- DOI:
10.1016/j.envsci.2018.05.015 - 发表时间:
2018-09 - 期刊:
- 影响因子:6
- 作者:
Yu Xiaofei;Mingju E;Sun Mingyang;Xue Zhenshan;Lu Xianguo;Jiang Ming;Zou Yuanchun - 通讯作者:
Zou Yuanchun
Jiang Ming的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Jiang Ming', 18)}}的其他基金
SaTC: CORE: Small: A Transparent and Customizable Android Container-Based Virtualization Architecture for Dynamic Malware Analysis
SaTC:CORE:Small:用于动态恶意软件分析的透明且可定制的基于 Android 容器的虚拟化架构
- 批准号:
2312185 - 财政年份:2022
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
SaTC: CORE: Small: A Transparent and Customizable Android Container-Based Virtualization Architecture for Dynamic Malware Analysis
SaTC:CORE:Small:用于动态恶意软件分析的透明且可定制的基于 Android 容器的虚拟化架构
- 批准号:
2128703 - 财政年份:2021
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
TWC: Small: Collaborative: Advancing Anonymity Against an AS-level Adversary
TWC:小型:协作:针对 AS 级对手推进匿名性
- 批准号:
1423163 - 财政年份:2014
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
相似海外基金
CRII: SaTC: Towards a Secure and Efficient Ethereum P2P Network with Client Diversity
CRII:SaTC:迈向具有客户端多样性的安全高效的以太坊 P2P 网络
- 批准号:
2347486 - 财政年份:2024
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
CRII:SaTC:了解图神经网络对抗图扰动的鲁棒性
- 批准号:
2241713 - 财政年份:2023
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Understanding and Defending Against New Waves of Online Hate
CRII:SaTC:理解和防御新一波的网络仇恨
- 批准号:
2245983 - 财政年份:2023
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Data-effective and Cost-efficient Security Attack Detections
CRII:SaTC:迈向数据有效且经济高效的安全攻击检测
- 批准号:
2245968 - 财政年份:2023
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant
CRII: SaTC: Towards Detecting and Mitigating Vulnerabilities
CRII:SaTC:致力于检测和缓解漏洞
- 批准号:
2153474 - 财政年份:2022
- 资助金额:
$ 17.5万 - 项目类别:
Standard Grant