SBIR Phase II: Advanced Ransomware Countermeasure
SBIR Phase II: Advanced Ransomware Countermeasure
批准号:
2304216
负责人:
Sudesh Kumar
金额:
$99.44万
依托单位:
依托单位国家:
美国
项目类别:
Cooperative Agreement
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-02-01 至 2026-01-31
中文摘要
这个小企业创新研究(SBIR)第二阶段项目将开发第一个普遍感知的勒索软件保护软件,采用主动的方法来阻止入侵的基于文件和无文件的攻击。近年来,全球范围内发起的勒索软件攻击数量大幅增长。为了利用以前未被发现的弱点并进行更有效的攻击,网络犯罪分子利用越来越多的员工在远程工作时通过虚拟专用网络(VPN)从家中访问业务网络。目前的勒索软件应对方案并不全面,通常无法应对持续和持久的攻击。此外,当前的解决方案仅在操作系统级别跟踪威胁,并且可以禁用。该解决方案基于与用户、勒索软件、非特定环境指标和非勒索软件度量相关的特征组合,具有普遍意识。全面的勒索软件检测、修复、根除和数据恢复解决方案提供了无与伦比的网络攻击保护,并允许及时检测和关闭网络攻击,从而大大减少了受损数据的数量。这种增强的保护将为广泛的关键基础设施带来安全效益,从能源和财务到医疗数据的保护。该小企业创新研究(SBIR)第二阶段项目旨在开发先进的勒索软件对策(ARC)平台,该平台将代表最先进和最有效的勒索软件攻击保护。该技术将执行四项协同行动:(1)前提条件观察和表征,(2)传入交互验证,(3)内部内容观察和表征,以及(4)传出交互验证。在这个项目中,研发工作将致力于(1)开发接种者和监管机构之间的通信框架,并部署有效的对策;(2)设计和开发用户友好的界面,提供简单的用户体验;(3)将ARC平台与现有的安全信息和事件管理(SIEM)工具无缝集成。(4)在ARC平台中实施人工智能/机器学习模型,有效防御零日勒索软件的攻击;(5)对ARC平台进行已知勒索软件的验证,以确保所有模块的正常功能。SBIR第二阶段活动的成功完成将提供一个功能齐全,商业上可行的产品,具有一般可用性,可以与现有的SIEM工具无缝运行/工作,并成功防御已知的勒索软件攻击和零日漏洞。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This Small Business Innovation Research (SBIR) Phase II project will develop the first universally aware software for ransomware protection with a proactive approach to stop incoming file-based and file-less attacks. The number of ransomware attacks launched globally has grown substantially over the years. To exploit previously undiscovered weaknesses and conduct more effective attacks, cybercriminals take advantage of the rising number of workers accessing business networks from home through a virtual private network (VPN) while working remotely. Current ransomware countermeasure solutions are not comprehensive and generally fail in tackling sustained and persistent attacks. Moreover, the current solutions track threats only at the operating system level and can be disabled. This solution features universal awareness based on a combination of characteristics related to user, ransomware, non-specific environment indicators, and non-ransomware metrics. The comprehensive ransomware detection, remediation, eradication, and data recovery solution enable unmatched protection from cyberattacks and allow timely detection and shutdown of cyberattacks thus, significantly reducing the amount of compromised data. This enhanced protection will have security benefits for a wide range of critical infrastructures, ranging from energy and finances to the protection of medical data.This Small Business Innovation Research (SBIR) Phase II project seeks to develop an advanced ransomware countermeasure (ARC) platform which will represent the most advanced and effective protection against ransomware attacks. The technology will enforce four synergistic actions: (1) precondition observation and characterization, (2) incoming interactions validation, (3) internal contents observation and characterization, and (4) outgoing interactions validation. In this project, the research and development efforts will be dedicated towards the (1) the development of the framework of communication between the inoculator and watch-dog and its deployment for effective countermeasure, (2) design and development of user-friendly interface providing simple user experience, (3) seamless integration of the ARC platform with existing Security Information and Event Management (SIEM) tools, (4) implementation of artificial intelligence/machine learning models in the ARC platform for the effective defense against zero-day ransomware exploits, and 5) validation of the ARC platform against known ransomware to ensure the proper function of all the modules. The successful completion of the SBIR Phase II activities will deliver a fully functional, commercially viable product with general availability that can seamlessly run/work along with existing SIEM tools and successfully defend against known ransomware attacks and zero-day exploits.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
SBIR Phase I: Advanced Ransomware Countermeasure
-
批准号:2040467
-
项目类别:Standard Grant
-
资助金额:$25.5万
-
财政年份:2021
-
负责人:Sudesh Kumar
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark
Supercooled Phase Transition
-
批准号:24ZR1429700
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:YUICHIRO NAKAI
-
依托单位:
ATLAS实验探测器Phase 2升级
-
批准号:11961141014
-
项目类别:国际(地区)合作与交流项目
-
资助金额:3350万元
-
批准年份:2019
-
负责人:刘衍文
-
依托单位:
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
-
批准号:41802035
-
项目类别:青年科学基金项目
-
资助金额:12.0万元
-
批准年份:2018
-
负责人:张里
-
依托单位:
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究
-
批准号:61675216
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2016
-
负责人:叶青
-
依托单位:
基于Phase-type分布的多状态系统可靠性模型研究
-
批准号:71501183
-
项目类别:青年科学基金项目
-
资助金额:17.4万元
-
批准年份:2015
-
负责人:陈童
-
依托单位:
纳米(I-Phase+α-Mg)准共晶的临界半固态形成条件及生长机制
-
批准号:51201142
-
项目类别:青年科学基金项目
-
资助金额:25.0万元
-
批准年份:2012
-
负责人:张英波
-
依托单位:
连续Phase-Type分布数据拟合方法及其应用研究
-
批准号:11101428
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2011
-
负责人:黄卓
-
依托单位:
D-Phase准晶体的电子行为各向异性的研究
-
批准号:19374069
-
项目类别:面上项目
-
资助金额:6.4万元
-
批准年份:1993
-
负责人:张殿琳
-
依托单位: