课题基金 / 基金详情

Computational tools for analyzing and detecting software supply chain attacks

Computational tools for analyzing and detecting software supply chain attacks
用于分析和检测软件供应链攻击的计算工具
批准号:
474601-2014
负责人:
Lie, David
金额:
$2.6万
依托单位:
依托单位国家:
加拿大
项目类别:
Collaborative Research and Development Grants
财政年份:
2015
资助国家:
加拿大
项目状态:
已结题
起止时间:
2015-01-01 至 2016-12-31

项目摘要

项目成果

Lie, David的其他基金

相似基金

相关文献

中文摘要
翻译
软件供应链攻击--在客户从开发到最终使用的过程中,恶意软件被秘密插入到信誉良好的、否则是良性的软件中的攻击已经成为一个日益令人担忧的问题。供应链攻击有可能影响企业、公共组织和个人用户,对各种用户都是一种威胁。诸如防病毒扫描仪之类的传统防御在很大程度上是无效的,因为这些攻击存放的恶意软件通常是定制的,并且可以秘密地嵌入到通常由最终用户高度信任的代码中。 在这个合作项目中,我们将通过调查和设计新的代码分析技术来应对这一威胁,这些技术可以检测和识别软件供应链攻击。传统的恶意软件检测技术需要足够便宜,才能在每台机器上运行,这将它们限制在相当便宜的句法、基于签名的检测机制上,这些机制几乎不会试图了解它正在扫描的代码的行为。然而,在云计算服务中发现的大量易于获得的并行计算能力,再加上快速网络连接的广泛可用性,激发了一种方法,即可以集中应用代码分析技术,然后将结果传播到所有终端主机。这为非常计算密集但功能强大的静态和动态分析技术打开了大门,这种技术不是仅仅寻求检测代码是否与一些先前已知的签名匹配,而是寻求了解和分析不受信任的软件的潜在行为,以确定它是否包含任何恶意意图。
英文摘要
Software supply chain attacks -- attacks where malware is covertly inserted into reputable and otherwise benign software somewhere in the chain between development and final use by the customer have become a growing concern. With the potential to affect enterprises, public organizations and individual users, supply chain attacks are a threat to users of every kind. Traditional defenses, such as anti-virus scanners are largely ineffective as the malware deposited by these attacks are often custom crafted and can be stealthily embedded in code that is normally highly trusted by the end user. In this collaborative project, we will address this threat by investigating and designing new code analysis techniques that can detect and identify software supply chain attacks. Traditional malware detection techniques needed to be cheap enough to run on each machine, limiting them to fairly cheap syntactic, signature-based detection mechanisms that did little to try to understand the behavior of the code it was scanning. However, the large amounts of easily available parallel computing power found in cloud computing services, combined with the broad availability of fast network connectivity, motivates an approach where code analysis techniques can be applied centrally and then the results are disseminated to all end hosts. This opens the door to very computationally intensive, but powerful static and dynamic analysis techniques which, instead of merely seeking to detect if the code matches some a previously known signature, seeks instead to understand and analyze the potential behavior of an untrusted piece of software to see if it harbors any malicious intent.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
  • 批准号:
    RGPIN-2018-05931
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2022
  • 负责人:
    Lie, David
  • 依托单位:
Secure and Reliable Systems
  • 批准号:
    CRC-2019-00242
  • 项目类别:
    Canada Research Chairs
  • 资助金额:
    $14.57万
  • 财政年份:
    2022
  • 负责人:
    Lie, David
  • 依托单位:
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
  • 批准号:
    RGPIN-2018-05931
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $2.04万
  • 财政年份:
    2021
  • 负责人:
    Lie, David
  • 依托单位:
Tools and methods for detecting vulnerabilities in embedded devices
  • 批准号:
    535902-2018
  • 项目类别:
    Collaborative Research and Development Grants
  • 资助金额:
    $5.19万
  • 财政年份:
    2021
  • 负责人:
    Lie, David
  • 依托单位:
海外基金