课题基金 / 基金详情

ITR: Intrusion Detection and Intrusion Prevention Through Dynamic Binary Translation

ITR: Intrusion Detection and Intrusion Prevention Through Dynamic Binary Translation
ITR:通过动态二进制翻译进行入侵检测和入侵防御
批准号:
0219587
负责人:
Darko Stefanovic
金额:
$13.22万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-09-01 至 2005-08-31

项目摘要

项目成果

Darko Stefanovic的其他基金

相似基金

相关文献

中文摘要
翻译
恶意代码对我们的社会构成了重大威胁,我们的社会越来越依赖于网络计算机系统进行商业和通信。恶意软件,包括病毒、蠕虫和特洛伊木马,具有破坏通信和威胁整个互联网稳定的潜力。因此,本研究的目的是分析、检测和缓解恶意代码。根据利用的漏洞和效果,对多种类型的恶意代码进行了调查和分组。这使得有选择地分别针对每个漏洞利用类成为可能。以前分析恶意代码的方法依赖于静态逆向工程、受限执行(通过程序语言沙盒)或网络跟踪。这些方法通常不适用于日益复杂的恶意代码,这些恶意代码可能使用运行时加密或动态多态性进行自我修改。动态恶意代码需要动态工具进行分析、检测和缓解。因此,正在开发允许此类分析的新动态工具,以及允许检测和减轻已知恶意代码类型的安全性增强。研究方法是利用运行时二进制转换实现透明的代码监控和重写。正在开发一个基于二进制转换的软件保证和安全系统的原型实现,并正在调查该解决方案的有效性及其潜在的部署成本。
英文摘要
Malicious code poses a significant threat to our society, which is becoming increasingly reliant on networked computer systems for commerce and communication. Malicious software, including viruses, worms, and Trojan Horses, has the potential to disrupt communications and threaten the stability of the Internet as a whole. Therefore the objective of this research is analysis, detection, and mitigation of malicious code. The many types of malicious code are being investigated and grouped by exploited vulnerability and effect. This makes it possible selectively to target each exploit class separately. Previous approaches to the analysis of malicious code relied on static reverse engineering, confined execution (via program language sandboxing), or network traces. These approaches are often inadequate for increasingly complex malicious code that may be self-modifying, using run-time encryption or dynamic polymorphism. Dynamic malicious code requires dynamic tools for analysis, detection, and mitigation. Therefore new dynamic tools to permit such analysis are being developed, together with security enhancements to allow detection and mitigation of known malicious code types. The research approach is to use run-time binary translation to achieve transparent code monitoring and rewriting. A prototype implementation of a system for software assurance and security based on binary translation is being developed, and the effectiveness of the solution and its potential deployment cost are being investigated.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Student and Postdoc Travel Support for DNA28
  • 批准号:
    2202396
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.0万
  • 财政年份:
    2022
  • 负责人:
    Darko Stefanovic
  • 依托单位:
SHF: Collaborative Research: Biocompatible I/O Interfaces for Robust Bioorthogonal Molecular Computing
  • 批准号:
    1763718
  • 项目类别:
    Standard Grant
  • 资助金额:
    $20.0万
  • 财政年份:
    2018
  • 负责人:
    Darko Stefanovic
  • 依托单位:
SHF: Large: Collaborative Research: Molecular computing for the real world
  • 批准号:
    1518861
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $93.44万
  • 财政年份:
    2015
  • 负责人:
    Darko Stefanovic
  • 依托单位:
AF: Small: Programmable Nanowalkers:Models and Simulations
  • 批准号:
    1422840
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2014
  • 负责人:
    Darko Stefanovic
  • 依托单位:
海外基金