Intelligence-driven malware detection system
Intelligence-driven malware detection system
批准号:
RGPIN-2020-04701
负责人:
HabibiLAshkari, Arash
金额:
$2.11万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Over the next five years, I will focus on advancing research in intelligence-driven malware detection by identifying and developing: Malware anatomy analysis: Malware writers obfuscate malware samples to conceal malicious code inside a legitimate executable to evade antimalware solutions and tamper without changing its genuine structure to exploit target machines and remain fully undetected. Since one of the main contributions of this research is to design automated static and dynamic malware analysis and detection, my research activities in this part will focus on several areas: malware analysis, malware attribution, malware authorship attribution, malware behavior pattern creation and malware characterization. Security big data analytics: The amount of malware produced and published by modern infrastructures has been exploding daily, making the resulting data sets too large, too complex and too rapidly changing for traditional analysis and detection tools. In the malware detection domain, this data provides a rich source of information that allows for analysis of the anatomy of malware, often pinpointing weak spots and potential solutions. In this area, I will be concentrating on the dynamic recognition/structuring and predictive analysis of malware on large-scale systems with the aim of using data mining methods to incorporate predictive analytic methods to design a comprehensive behavioral pattern of malware on different infrastructure. A pattern visualization technique: Common visualization techniques are generally not designed for malware pattern recognition, so we require novel techniques fine-tuned for thorough malware analysis. Malware visualizations should have an elegant and visually appealing design, while being informative, interactive, and providing exploratory capabilities. These features assist an analyst to first grasp an overall view of the malware behavior, allowing them to perceive areas of activity, and second to permit further explorations of irregular behavioral patterns, assisting in the detection of malware or identification of possible threats. Therefore, I will provide a new visualization technique that will cover the where, why and how features for malware analyzer. A bank of malware datasets: Modern malware is designed with mutation characteristics, such as polymorphism and metamorphism, causing an enormous growth in the number of malware families, and malware variants inside the families. Having a malware dataset that can systematically characterize malware from various aspects, including their installation methods, activation mechanisms, and the nature of malicious payloads is vital to the machine learning process and pattern definition. I will focus to collect huge available malware and develop similar malware to generate a massive bank of malware to dissect, understand the malicious code, and trigger it, allowing for analysis of the anatomy of malware and prediction of behavior patterns for malware families.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Behaviour-Centric Cybersecurity
-
批准号:CRC-2021-00340
-
项目类别:Canada Research Chairs
-
资助金额:$6.92万
-
财政年份:2022
-
负责人:HabibiLAshkari, Arash
-
依托单位:
Intelligence-driven malware detection system
-
批准号:RGPIN-2020-04701
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2021
-
负责人:HabibiLAshkari, Arash
-
依托单位:
国内基金
海外基金
Data-driven Recommendation System Construction of an Online Medical Platform Based on the Fusion of Information
-
批准号:--
-
项目类别:外国青年学者研究基金项目
-
资助金额:--
-
批准年份:2024
-
负责人:江洋子
-
依托单位:
基于Cache的远程计时攻击研究
-
批准号:60772082
-
项目类别:面上项目
-
资助金额:28.0万元
-
批准年份:2007
-
负责人:王韬
-
依托单位: