Addressing Evasive Malware
解决规避恶意软件问题
基本信息
- 批准号:2107021
- 负责人:
- 金额:--
- 依托单位:
- 依托单位国家:英国
- 项目类别:Studentship
- 财政年份:2018
- 资助国家:英国
- 起止时间:2018 至 无数据
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
The main areas of interest of this research is addressing malware that can detect virtual sandbox environments so that they can avoid analysis environments. An example of a simple sandbox evasion mechanism is the WannaCry malware which uses a DNS query. This malware was shut down by registering the correct domain and responding in the correct manner. This method worked because sandboxes often respond to DNS queries giving the appearance of a target device being online. The malware author had knowledge of this and programmed WannaCry to shut down when a response to an unregistered domain was received. Malware analysis through sandboxes focus on trying to mirror physical systems so that they appear transparent to the sample program being tested. In practice, this has proved difficult to achieve with malware authors programming their software to look for indicators that an environment is virtual. Historically it has been shown that there is a pattern of malware authors quickly finding solutions to engineering attempts to hide a sandbox environment from the malware. This leads to an endless game of "cat and mouse|, with security engineers having to respond to malware authors new ways of detecting a sandbox environment. A common approach is to reconfigure the sandbox environment to make it seem more like a physical environment, but this is not without its issues because some of the changes can lead to incompatibility between the test environment and the subject programmes.The research undertaken in this PhD will seek to detect the malware's sandbox detection mechanisms and turn the malware authors' techniques of environmental analysis against them. These methods include looking at the sum of the activities that a sample performs whilst it is trying to learn about its environment when it is first executed. Some examples are: capturing the network traffic generated by the sample on execution, using hooks to look at system calls made by the malware, looking at the number of NOPs that a malware may generate and looking at differential behaviour analysis i.e. if a detection mechanism is removed, does the sample become more active. The reason for focussing on when a sample is first executed is that there is typically some active interrogation before the malware activates its payload or is programmed to stay dormant and evade analysis. This can be considered a form of 'noise' that the malware makes when it is analysing the environment in the first instance and this is what the project will be targeting.Machine learning or possibly bame theory will be explored to see if it is possible to model these malware interactions in order to classify the software sample on a scale which can indicate to security analysts that further investigation in a physical environment is required. The reason an adaptive approach is required rather than an absolute approach is because sometimes interrogation of an environment by a program is considered normal behaviour. It is possible that a combination of these interactions will point to a sample looking to evade analysis in a sandbox
这项研究的主要兴趣领域是解决可以检测虚拟沙箱环境的恶意软件,以便它们可以避开分析环境。一个简单的沙箱规避机制的例子是使用DNS查询的WannaCry恶意软件。该恶意软件通过注册正确的域并以正确的方式响应而关闭。这种方法之所以有效,是因为沙箱经常响应DNS查询,使目标设备看起来在线。恶意软件作者知道这一点,并编程WannaCry在收到未注册域名的响应时关闭。通过沙箱进行的恶意软件分析侧重于尝试镜像物理系统,以便它们对正在测试的示例程序透明。在实践中,这已被证明是难以实现的恶意软件作者编程他们的软件来寻找环境是虚拟的指标。从历史上看,恶意软件作者有一种模式,可以快速找到解决方案,以工程化的方式试图隐藏恶意软件的沙箱环境。这导致了一场无休止的“猫捉老鼠”游戏|,安全工程师必须响应恶意软件作者检测沙箱环境的新方法。一种常见的方法是重新配置沙箱环境,使其看起来更像一个物理环境,但这并不是没有问题,因为一些变化可能会导致测试环境和主题程序之间的不兼容性。在这个博士学位进行的研究将寻求检测恶意软件的沙箱检测机制,并将恶意软件作者的环境分析技术针对他们。这些方法包括查看样本在第一次执行时尝试了解其环境时执行的活动的总和。以下是一些示例:捕获由执行时的样本生成的网络流量,使用钩子来查看由恶意软件进行的系统调用,查看恶意软件可能生成的NOP的数量,以及查看差异行为分析,即,如果检测机制被移除,则样本是否变得更活跃。关注样本首次执行时间的原因是,在恶意软件激活其有效载荷或被编程为保持休眠并逃避分析之前,通常会有一些主动询问。这可以被认为是恶意软件在第一时间分析环境时发出的一种“噪音”,这就是该项目的目标。机器学习或可能的bame理论将被探索,看看是否有可能对这些恶意软件交互进行建模,以便在一定程度上对软件样本进行分类,这可以向安全分析师表明,在物理环境中进行进一步调查是可行的。必需的.之所以需要自适应方法而不是绝对方法,是因为有时程序对环境的询问被认为是正常行为。这些交互作用的组合可能会指向一个试图逃避沙箱分析的样本
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
其他文献
吉治仁志 他: "トランスジェニックマウスによるTIMP-1の線維化促進機序"最新医学. 55. 1781-1787 (2000)
Hitoshi Yoshiji 等:“转基因小鼠中 TIMP-1 的促纤维化机制”现代医学 55. 1781-1787 (2000)。
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
- 通讯作者:
LiDAR Implementations for Autonomous Vehicle Applications
- DOI:
- 发表时间:
2021 - 期刊:
- 影响因子:0
- 作者:
- 通讯作者:
吉治仁志 他: "イラスト医学&サイエンスシリーズ血管の分子医学"羊土社(渋谷正史編). 125 (2000)
Hitoshi Yoshiji 等人:“血管医学与科学系列分子医学图解”Yodosha(涉谷正志编辑)125(2000)。
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
- 通讯作者:
Effect of manidipine hydrochloride,a calcium antagonist,on isoproterenol-induced left ventricular hypertrophy: "Yoshiyama,M.,Takeuchi,K.,Kim,S.,Hanatani,A.,Omura,T.,Toda,I.,Akioka,K.,Teragaki,M.,Iwao,H.and Yoshikawa,J." Jpn Circ J. 62(1). 47-52 (1998)
钙拮抗剂盐酸马尼地平对异丙肾上腺素引起的左心室肥厚的影响:“Yoshiyama,M.,Takeuchi,K.,Kim,S.,Hanatani,A.,Omura,T.,Toda,I.,Akioka,
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
- 通讯作者:
的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('', 18)}}的其他基金
An implantable biosensor microsystem for real-time measurement of circulating biomarkers
用于实时测量循环生物标志物的植入式生物传感器微系统
- 批准号:
2901954 - 财政年份:2028
- 资助金额:
-- - 项目类别:
Studentship
Exploiting the polysaccharide breakdown capacity of the human gut microbiome to develop environmentally sustainable dishwashing solutions
利用人类肠道微生物群的多糖分解能力来开发环境可持续的洗碗解决方案
- 批准号:
2896097 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
A Robot that Swims Through Granular Materials
可以在颗粒材料中游动的机器人
- 批准号:
2780268 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
Likelihood and impact of severe space weather events on the resilience of nuclear power and safeguards monitoring.
严重空间天气事件对核电和保障监督的恢复力的可能性和影响。
- 批准号:
2908918 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
Proton, alpha and gamma irradiation assisted stress corrosion cracking: understanding the fuel-stainless steel interface
质子、α 和 γ 辐照辅助应力腐蚀开裂:了解燃料-不锈钢界面
- 批准号:
2908693 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
Field Assisted Sintering of Nuclear Fuel Simulants
核燃料模拟物的现场辅助烧结
- 批准号:
2908917 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
Assessment of new fatigue capable titanium alloys for aerospace applications
评估用于航空航天应用的新型抗疲劳钛合金
- 批准号:
2879438 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
Developing a 3D printed skin model using a Dextran - Collagen hydrogel to analyse the cellular and epigenetic effects of interleukin-17 inhibitors in
使用右旋糖酐-胶原蛋白水凝胶开发 3D 打印皮肤模型,以分析白细胞介素 17 抑制剂的细胞和表观遗传效应
- 批准号:
2890513 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
Understanding the interplay between the gut microbiome, behavior and urbanisation in wild birds
了解野生鸟类肠道微生物组、行为和城市化之间的相互作用
- 批准号:
2876993 - 财政年份:2027
- 资助金额:
-- - 项目类别:
Studentship
相似海外基金
ModRNA-based Direct Programming of Universal Donor hiPSCs into Immune Evasive Beta Cells
基于 ModRNA 的通用供体 hiPSC 直接编程至免疫逃避型 β 细胞
- 批准号:
10774361 - 财政年份:2023
- 资助金额:
-- - 项目类别:
Brain states and their roles in evasive behaviour
大脑状态及其在逃避行为中的作用
- 批准号:
DP230102614 - 财政年份:2023
- 资助金额:
-- - 项目类别:
Discovery Projects
Implantable Electrospun Cell Chamber Device with Immune-Evasive Properties for Beta Cell Replacement Therapy
用于β细胞替代疗法的具有免疫规避特性的植入式静电纺丝细胞室装置
- 批准号:
10756256 - 财政年份:2023
- 资助金额:
-- - 项目类别:
Polled In Vivo CRISPR-Cas9 Screening in iPSCs to generate immune-evasive iPSCs
在 iPSC 中进行体内轮询 CRISPR-Cas9 筛选以生成免疫逃避 iPSC
- 批准号:
22K15490 - 财政年份:2022
- 资助金额:
-- - 项目类别:
Grant-in-Aid for Early-Career Scientists
Enhancing cell-based DNA-Encoded Libraries for targeting immune evasive cancers.
增强基于细胞的 DNA 编码文库,以针对免疫逃避癌症。
- 批准号:
546440-2019 - 财政年份:2019
- 资助金额:
-- - 项目类别:
Canadian Graduate Scholarships Foreign Study Supplements
Cognitive-Pragmatics Approach to Evasive Communication
回避沟通的认知语用方法
- 批准号:
17K02701 - 财政年份:2017
- 资助金额:
-- - 项目类别:
Grant-in-Aid for Scientific Research (C)
Elucidation of a novel evasive adaptation mechanism against antiangiogenic treatment in colorectal cancer cells
阐明结直肠癌细胞抗血管生成治疗的新型逃避适应机制
- 批准号:
15H04931 - 财政年份:2015
- 资助金额:
-- - 项目类别:
Grant-in-Aid for Scientific Research (B)
Understanding the evasive contributions to net carbon dioxide and methane exchanges
了解二氧化碳和甲烷净交换的回避贡献
- 批准号:
467805-2014 - 财政年份:2014
- 资助金额:
-- - 项目类别:
University Undergraduate Student Research Awards
Proposal of an integrated model of attractive pheromone and evasive pheromone and its application to large-scale swarm robots
吸引信息素与回避信息素集成模型的提出及其在大型群体机器人中的应用
- 批准号:
26870806 - 财政年份:2014
- 资助金额:
-- - 项目类别:
Grant-in-Aid for Young Scientists (B)
Evasive Flow Capturing Problem: Optimal Allocation of Weigh-in-Motion Stations, Tollbooths, and Security Checkpoints
规避流量捕获问题:动态称重站、收费站和安全检查站的优化分配
- 批准号:
1335416 - 财政年份:2013
- 资助金额:
-- - 项目类别:
Standard Grant














{{item.name}}会员




