课题基金 / 基金详情

基于免疫的Rootkit隐遁攻击动态内存取证方法研究

批准号:
61462025
项目类别:
地区科学基金项目
资助金额:
44.0 万元
负责人:
张瑜
依托单位:
学科分类:
网络与系统安全
结题年份:
2018
批准年份:
2014
项目状态:
已结题
项目参与者:
Qingzhong Liu、陈凯、梁新秋、刘雁翎、李亚楠、庞富强

项目摘要

结项摘要

项目成果

张瑜的其他基金

相似基金

相关文献

中文摘要
完整获取、分析内存镜像数据,并从中提取Rootkit隐遁攻击证据,能有效预防恶意隐遁网络攻击、遏制网络犯罪。本项目在前期研究Rootkit攻击进程分析与免疫检测的基础上,进一步研究Rootkit内存数据获取与分析方法和Rootkit内存免疫取证方法。主要包括:①通过逆向分析Windows内存页面交换机制,获取完整的内存镜像数据,为内存数据分析提供数据支持;②利用内核驱动技术,动态分析内存镜像中的进程数据,并重建与进程相对应的可执行文件映像,为进一步的Rootkit内存取证提供技术与证据支持;③借鉴人体免疫系统机理,通过Rootkit检测器(免疫细胞)的动态演化及证据提取,研究Rootkit隐遁攻击动态内存取证方法。本项目可促进Rootkit隐遁攻击内存数据获取与分析技术的深入发展,拓展Rootkit内存免疫取证研究新思路;同时,对构建自主产权的Rootkit安全取证产品具有重要参考价值。
英文摘要
A Rootkit for Windows systems is a program that penetrates into the system and intercepts the system functions. Rootkit evasion attack is a kind of network attacks,which can effectively hide their presence by intercepting low-level API functions or modifying the system kernel. Moreover, it can hide the presence of particular processes, folders, files and registry keys. Recently, some Rootkits install their own drivers and services only in the system memory. That particular trend makes them invisible and difficult to detect. Therefore, it is very important for preventing network stealth attacks and curbing cyber crimes to completely obtain memory data, analyse the data, and extract the Rootkit evasion attacks evidence. The proposed project will focus primarily on Rootkit evasion attacks about memory data obtainment, memory data analysis,and immunity-inspired memory forensics. It mainly includes the follows: ① The memory data full obtainment of Rootkit evasion attacks. The completely memory data obtained by reversely analyzing the Windows page-swapping files will provide data support for the analysis of it. ② The memory process accurately analysis and its portable executable image file reconstruction. Those information obtained with kernel mode driver will provide evidence support for Rootkit evasion attacks memory forensics. ③The immunity-inspired Rootkit evasion attacks memory forensics. Drawing inspiration from the human immune system and using the mechanisms such as vaccination, self-tolerance, affinity maturation, and antigen presentation are to build a dynamic approach for Rootkit evasion memory forensics. The proposed project can promote the memory data obtainment of Rootkit evasion attacks, improve the technology of analyzing memory data, and thereby develop a novel idea of immunity-inspired Rootkit evasion attacks memory forensics. Furthermore, the proposed project plays an important role in building Rootkit forensics defense products with independent property rights.
Rootkit 隐遁攻击原本已经所向披靡,加之采用内存反取证对抗措施后,致使传统的磁盘文件系统取证方法难以取证,这对于网络信息安全的威胁无疑雪上加霜。因此,从Rootkit 隐遁攻击的发展趋势来看,对Rootkit隐遁攻击进行内存取证分析,已是大势所趋、势在必行。.完整获取、分析内存镜像数据,并从中提取Rootkit 隐遁攻击证据,能有效预防恶意隐遁网络攻击、遏制网络犯罪。本项目在前期研究Rootkit 攻击进程分析与免疫检测的基础上,进一步研究Rootkit 内存数据获取与分析方法和Rootkit 内存免疫取证方法。主要包括:①通过逆向分析Windows 内存页面交换机制,获取完整的内存镜像数据,为内存数据分析提供数据支持;②利用内核驱动技术,动态分析内存镜像中的进程数据,并重建与进程相对应的可执行文件映像,为进一步的Rootkit 内存取证提供技术与证据支持;③借鉴人体免疫系统机理,通过Rootkit 检测器(免疫细胞)的动态演化及证据提取,研究Rootkit隐遁攻击动态内存取证方法。.项目成果解决了内存镜像数据完整获取、内存镜像数据的进程分析与可执行文件映像重建、以及Rootkit隐遁攻击内存取证免疫模型的动态刻画问题。本项目促进了Rootkit 隐遁攻击内存数据获取与分析技术的深入发展,拓展了Rootkit隐遁攻击内存免疫取证研究新思路;同时,对构建新一代自主产权的Rootkit 安全取证产品具有重要参考价值。
期刊论文列表
专著列表
科研奖励列表
会议论文列表
专利列表
DOI: --
发表时间: 2015
期刊: 电子科技大学学报
影响因子: --
作者: [张瑜, 刘庆中, 李涛, 吴丽华]
通讯作者: 吴丽华
DOI: --
发表时间: 2018
期刊: 电子科技大学学报
影响因子: --
作者: [张瑜, 刘庆中, 石元泉, 曹均阔]
通讯作者: 曹均阔
Unsupervised Anomaly Detection for Network Flow Using Immune Network Based K-means Clustering
使用基于免疫网络的 K 均值聚类对网络流进行无监督异常检测
DOI: 10.1007/978-981-10-6385-5_33
发表时间: 2017-09
期刊: Journal of Computational Information Systems
影响因子: --
作者: [Yuanquan Shi, Xiaoning Peng, Renfa Li, Yu Zhang]
通讯作者: Yu Zhang
DOI: --
发表时间: 2015
期刊: 四川大学学报(工程科学版)
影响因子: --
作者: [张瑜, 刘庆中, 李涛, 吴丽华]
通讯作者: 吴丽华
8
    基于免疫的隐遁勒索软件攻击机理分析与防御方法研究
    • 批准号:
      61862022
    • 项目类别:
      地区科学基金项目
    • 资助金额:
      40.0万元
    • 批准年份:
      2018
    • 负责人:
      张瑜
    • 依托单位:
    基于免疫的Rootkit渗透攻击机理分析与检测方法研究
    • 批准号:
      61262077
    • 项目类别:
      地区科学基金项目
    • 资助金额:
      45.0万元
    • 批准年份:
      2012
    • 负责人:
      张瑜
    • 依托单位:
    国内基金
    海外基金