课题基金 / 基金详情

OAC Core: Enhancing Network Security by Implementing an ML Malware Detection and Classification Scheme in P4 Programmable Data Planes and SmartNICs

OAC Core: Enhancing Network Security by Implementing an ML Malware Detection and Classification Scheme in P4 Programmable Data Planes and SmartNICs
OAC 核心:通过在 P4 可编程数据平面和智能网卡中实施 ML 恶意软件检测和分类方案来增强网络安全
批准号:
2403360
负责人:
Jorge Crichigno
金额:
$60.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-07-01 至 2027-06-30

项目摘要

项目成果

Jorge Crichigno的其他基金

相似基金

相关文献

中文摘要
翻译
恶意软件攻击对组织构成了重大威胁,组织使用各种方法来防范它们。例子包括在通用计算机上运行的入侵检测系统、入侵防御系统和其他安全系统。这些方案执行“深度数据包检测”(DPI),通过该过程,保护组织的安全设备彻底检查传入的流量并向管理员发出可疑活动警报。虽然DPI在某些情况下可能是有效的,但它需要大量的处理。此外,如果组织收到来自Internet的大量流量,DPI可能跟不上流量,可能只检查其中的一小部分。此外,检测可能不是实时进行的,可能只是在攻击发生后才检测到恶意软件。本项目建议利用P4可编程数据平面(PDP)交换机和智能网卡的能力来执行DPI。该项目有四个目标。1)开发一个运行在pdp上的恶意软件检测和分类应用程序,以线速率运行。应用程序将执行域名系统(DNS)数据包的DPI,防止恶意软件与相应的C2服务器通信。流量将被实时监控,通常在通用cpu上执行的功能将被卸载到pdp上。该计划包括分析DNS数据,描述流量模式,并将这些信息提供给机器学习(ML)算法。机器学习算法将检测和分类恶意软件根据他们的家族(例如,特洛伊木马,后门,勒索软件)。2)开发一个运行在SmartNIC上的恶意软件检测与分类应用,用于加密DNS报文。研究将对生成此类数据包的恶意软件进行特征提取。机器学习算法将使用这些特征来检测和分类恶意软件。3)开发一个控制应用程序,共享威胁情报,避免恶意软件传播。由于PDP交换机和智能网卡检测恶意软件,它们与中央控制器共享威胁情报。4)扩展eX-IoT平台,为新检测和分类的恶意软件提供指纹、存储和索引。eX-IoT平台是一个实时平台,用于在互联网上识别受损设备的指纹。在pdp和智能网卡上运行的原型将使用社区可用的开源组件构建,并且开发的知识将通过将其合成为课程和自定进度学习的虚拟实验室图书馆来传播。这些图书馆将分配给各大院校。最后,将与Internet2和FABRIC等组织一起组织恶意软件检测和pdp教程。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Malware attacks represent significant threats to organizations, which use a variety of approaches to protect against them. Examples include intrusion detection systems, intrusion prevention systems, and other security systems that run on general-purpose computers. Such schemes perform "deep packet inspection" (DPI), a process by which a security device protecting an organization thoroughly examines incoming traffic and alerts administrators about suspicious activities. While DPI may be effective in some scenarios, it requires significant processing. Furthermore, if the organization receives a high volume of traffic from the Internet, DPI may not keep up with the traffic and may only inspect a fraction of it. Additionally, the inspection may not be conducted in real-time and may only detect the malware after the attack.This project proposes to leverage the capability of P4 programmable data plane (PDP) switches and smartNICs to perform DPI. The project has four objectives. 1) Develop a malware detection and classification application running on PDPs, operating at line rate. The application will perform DPI of Domain Name System (DNS) packets, preventing malware from communicating with the corresponding C2 server. Traffic will be monitored in real-time, and functions commonly executed on general-purpose CPUs will be offloaded to PDPs. The plan includes analyzing DNS data, characterizing traffic patterns, and feeding such information to a machine learning (ML) algorithm. The ML algorithm will detect and classify malware according to their family (e.g., trojan, backdoor, ransomware). 2) Develop a malware detection and classification application running on a SmartNIC, for encrypted DNS packets. Research will be conducted to perform feature extraction for malware generating such packets. An ML algorithm will use the features to detect and classify the malware. 3) Develop a control application that shares threat intelligence and avoids malware propagation. As PDP switches and smartNIC detect malware, they share the threat intelligence with a centralized controller. 4) Expand the eX-IoT platform to fingerprint, store, and index newly detected and classified malware. The eX-IoT platform is a real-time platform for fingerprinting compromised devices on the Internet. The prototype running on PDPs and smart NICs will be built with open-source components available to the community, and the developed knowledge will be disseminated by synthesizing it as virtual lab libraries for courses and self-paced learning. The libraries will be distributed to colleges and universities. Finally, tutorials on malware detection and PDPs will be organized with organizations such as Internet2 and FABRIC.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CC* Integration-Small: Enhancing Data Transfers by Enabling Programmability and Closed-loop Control in a Non-programmable Science DMZ
CyberTraining: Implementation: Small: Cybertraining on P4 Programmable Devices using an Online Scalable Platform with Physical and Virtual Switches and Real Protocol Stacks
Collaborative: Multi-state Community College, University and Industry Collaboration to Prepare Learners for 21st Century Information Technology Jobs
CC* Networking Infrastructure: Building a Science DMZ for Data-intensive Research and Computation at the University of South Carolina
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: