CRII: SaTC: An Integrated Treatment of Ransomware Through Microarchitecture and Software Solutions
CRII: SaTC: An Integrated Treatment of Ransomware Through Microarchitecture and Software Solutions
批准号:
1947580
负责人:
Anys Bacha
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-07-01 至 2024-06-30
中文摘要
网络犯罪分子一直在寻找使他们的攻击有利可图的方法。因此,各种移动的用户、企业和政府机构都成为一种新的破坏性恶意软件(称为勒索软件)的受害者。勒索软件允许攻击者恶意加密用户数据,然后勒索赎金,以换取恢复他们的加密数据。本项目旨在开发新的检测和恢复解决方案,以防御跨移动的和计算机系统的勒索软件,同时引入最小的性能开销。本研究将研究针对勒索软件攻击的新防御措施。该项目的第一部分将专注于利用卷积神经网络进行跨移动的和计算机系统的异构架构的勒索软件检测。这项工作设计了一个框架,将应用程序指令映射到不同的空间表示。然后,它将评估这种表示在使用卷积神经网络检测勒索软件方面的有效性。第二部分将专注于开发一种新的端到端解决方案,该解决方案跨越微架构、固件和操作系统层,以恢复恶意加密的数据。这项研究有可能大幅提高系统的整体安全性和数据可用性,以抵御计算范围内的勒索软件威胁,并增强推动我们社会发展的个人和商业数据的可用性。鉴于该项目对数据的重视,这是我们社会的动力,这项工作预计将对计算行业,社会,执法和美国国家安全产生重大影响。此外,该项目将研究活动与教育和外联活动结合起来,以扩大妇女和少数群体对计算机科学学科的参与,通过该项目产生的数据将存入密歇根大学的机构数据储存库深蓝数据。深蓝数据中的内容存储在网络存储上,并在园区数据中心进行适当的备份。发布的结果和收集的数据将在项目期间和奖项结束后至少三年内通过该系统提供。关于项目存储库的更多信息将在www.example.com上提供https://anysbacha.github.io.This奖项反映了NSF的法定使命,并被认为值得通过使用基金会的知识价值和更广泛的影响审查标准进行评估来支持。
英文摘要
Cyber-criminals are constantly seeking ways to make their attacks profitable. As a result, various mobile users, businesses, and government agencies are falling victim to a new disruptive class of malware known as ransomware. Ransomware allows attackers to maliciously encrypt user data then extort them for ransom in return for restoring their encrypted data. This project aims to develop novel detection and recovery solutions to defend against ransomware across mobile and computer systems while introducing minimal performance overhead.This research will investigate novel defenses against ransomware attacks. The first part of this project will focus on harnessing convolutional neural networks for ransomware detection across heterogeneous architectures that span mobile and computer systems. This work devises a framework that maps application instructions into different spatial representations. It will then evaluate the effectiveness of such representations in detecting ransomware with convolutional neural networks. The second part will focus on the development of a new end-to-end solution that spans the microarchitecture, firmware, and operating system layers to recover maliciously encrypted data.This research has the potential to substantially improve the overall security of systems and data availability against ransomware threats across the computing spectrum and enhance the availability of personal and business data that drives our society. Given the emphasis of this project on data, which serves as the impetus of our society, the work is expected to have a significant impact on the computing industry, society, law enforcement, and United States national security. In addition, this project integrates the research activities with education and outreach to broaden the participation of women and minorities in computer science disciplines.The data generated through this project will be deposited into Deep Blue Data, the University of Michigan’s institutional data repository. Content in Deep Blue Data is stored on network storage with proper backup in campus data centers. Published results and collected data will be available via this system over the duration of the project and for a minimum of three years after the conclusion of the award. Further information on the project repository will be made accessible at https://anysbacha.github.io.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1145/3579822
发表时间:
2023-01
期刊:
ACM Transactions on Privacy and Security
影响因子:
2.3
作者:
[Nada Lachtar;Duha Ibdah;Hamza Khan;Anys Bacha]
通讯作者:
Nada Lachtar;Duha Ibdah;Hamza Khan;Anys Bacha
DOI:
10.1109/access.2021.3130495
发表时间:
2021-01-01
期刊:
IEEE ACCESS
影响因子:
3.9
作者:
[Abu Elkhail, Abdulrahman, Refat, Rafi Ud Daula, Malik, Hafiz]
通讯作者:
Malik, Hafiz
DOI:
10.1109/tdsc.2022.3214781
发表时间:
2023-01
期刊:
IEEE Transactions on Dependable and Secure Computing
影响因子:
7.3
作者:
[Abdulrahman Abu Elkhail;Nada Lachtar;Duha Ibdah;Rustam Aslam;Hamza Khan;Anys Bacha;Hafiz Malik]
通讯作者:
Abdulrahman Abu Elkhail;Nada Lachtar;Duha Ibdah;Rustam Aslam;Hamza Khan;Anys Bacha;Hafiz Malik
An Application Agnostic Defense Against the Dark Arts of Cryptojacking
针对加密劫持黑暗艺术的与应用程序无关的防御
DOI:
10.1109/dsn48987.2021.00044
发表时间:
2021
期刊:
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN
影响因子:
--
作者:
[Lachtar, Nada, Elkhail, Abdulrahman Abu, Bacha, Anys, Malik, Hafiz]
通讯作者:
Malik, Hafiz
DOI:
10.1109/lca.2020.3017457
发表时间:
2020-07
期刊:
IEEE Computer Architecture Letters
影响因子:
2.3
作者:
[Nada Lachtar;Abdulrahman Abu Elkhail;Anys Bacha;Hafiz Malik]
通讯作者:
Nada Lachtar;Abdulrahman Abu Elkhail;Anys Bacha;Hafiz Malik
NSF Student Travel Support for the 52nd IEEE/ACM Symposium on Microarchitecture (MICRO)
-
批准号:1933772
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2019
-
负责人:Anys Bacha
-
依托单位:
海外基金