课题基金 / 基金详情

SaTC: CORE: Small: Beat Modern Virtualization Obfuscation at Their Own Game: A Bottom-Up Deobfuscation Approach

SaTC: CORE: Small: Beat Modern Virtualization Obfuscation at Their Own Game: A Bottom-Up Deobfuscation Approach
SaTC:核心:小型:在自己的游戏中击败现代虚拟化混淆:自下而上的反混淆方法
批准号:
2211905
负责人:
Dongpeng Xu
金额:
$60.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-01-01 至 2025-12-31

项目摘要

项目成果

Dongpeng Xu的其他基金

相似基金

相关文献

中文摘要
翻译
混淆技术已被恶意代码(恶意软件)的编写者广泛采用,以绕过防御解决方案。混淆的目标是将恶意软件转换为等同的,但高度复杂的形式,隐藏恶意软件的结构,并阻碍自动检测解决方案,甚至安全分析师的人工检查。快速分析被混淆的恶意软件对于快速响应新出现的威胁(如勒索软件)至关重要。这个研究项目提高了人类在击败混淆恶意软件方面的知识。该项目的新颖之处在于从最先进的混淆中揭示的新知识,为提取知识而设计的新技术,以及用于理解此类隐形恶意软件的新解混淆方法。该项目更广泛的意义和重要性是为K-12/本科生/研究生提供新的网络安全学习经验,以及针对各种新兴恶意软件威胁的国家网络安全新技术,具有很高的实践转型潜力。这个项目的目的是利用虚拟化技术本身来击败现代虚拟化混淆器。两个主要特性在虚拟化混淆的成功中起着至关重要的作用:复杂性(混淆后的形式非常复杂,与原始程序不同)和多样化(同一程序的多个混淆形式差异很大)。这些特性严重阻碍了现有的去混淆技术,这些技术依赖于识别特殊的虚拟机模式或将整个虚拟化视为黑盒。本项目发明并实现了一系列新颖的方法:(1)全面探索虚拟机内部复杂的结构,如解释架构、虚拟指令、处理程序加密等;(2)揭示多种虚拟机组合、变异和随机化的核心技术;(3)构建一个新的、可解释的、专门用于解混淆的虚拟机,并将其拼接成一个简单的、可执行的程序作为解混淆的结果。从这个项目中开发的新技术有效地将安全专业人员从恶意软件分析中产生的痛苦、繁琐的解混淆步骤中解放出来。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Obfuscation technology has been widely adopted by writers of malicious code (malware) to circumvent defense solutions. The goal of obfuscation is to transform malware into an equivalent, but highly complex form that hides the malware's structure and hinders automatic detection solutions and even manual inspection by security analysts. Rapid analysis of obfuscated malware is vital for a swift response to emerging threats, such as ransomware. This research project advances human knowledge on defeating obfuscated malware. The project's novelties are the new knowledge revealed from the state-of-the-art obfuscation, the new techniques designed for extracting the knowledge, and the new deobfuscation methods for understanding such type of stealthy malware. The project's broader significance and importance are new cybersecurity learning experiences for K-12/undergraduate/graduate students, and new technologies for national cybersecurity against a wide range of emerging malware threats, with high potential for transition to practice. The insight of this project is to leverage the virtualization technique itself to beat modern virtualization obfuscators. Two major features play a crucial role in the success of virtualization obfuscation: sophistication (the obfuscated form is very complex and different from the original program) and diversification (multiple obfuscated forms of the same program strikingly vary). These features heavily impede existing deobfuscation techniques that rely on recognizing special virtual machine patterns or treating the whole virtualization as a black box. This project invents and implements a series of novel methods to: (1) comprehensively probe the sophisticated structures inside virtual machines, such as interpretation architecture, virtual instructions, and handler encryption, (2) reveal the core techniques to combine, mutate, and randomize diverse virtual machines, and (3) build a new, interpretable virtual machine specifically for deobfuscation, which can be stitched into a simple, executable program as the deobfuscation result. The new techniques developed from this project effectively free security professionals from the painful, tedious deobfuscation steps incurred in malware analysis.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/dsn58367.2023.00039
发表时间: 2023-06
期刊: 2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子: --
作者: [Naiqian Zhang;Daroc Alden;Dongpeng Xu;Shuai Wang;T. Jaeger;Wheeler Ruml]
通讯作者: Naiqian Zhang;Daroc Alden;Dongpeng Xu;Shuai Wang;T. Jaeger;Wheeler Ruml
CRII: SaTC: Simplification of Mixed Boolean-Arithmetic Obfuscated Expression
  • 批准号:
    1948489
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.5万
  • 财政年份:
    2020
  • 负责人:
    Dongpeng Xu
  • 依托单位:
SaTC: CORE: Small: Towards Securing the Hardware and Software for Approximate Computing Systems
  • 批准号:
    2022279
  • 项目类别:
    Standard Grant
  • 资助金额:
    $50.0万
  • 财政年份:
    2020
  • 负责人:
    Dongpeng Xu
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: