ITR: Defending Against Virus Propagation on the Internet
ITR: Defending Against Virus Propagation on the Internet
批准号:
0326472
负责人:
Ljudevit Bauer
金额:
$0.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-09-15 至 2011-08-31
中文摘要
自从Morris蠕虫攻击互联网以来,病毒和蠕虫的演变一直使反病毒分析师忙碌忙于开发新的扫描和检测功能。新的病毒继续比当前的技术更聪明,并造成严重破坏。很明显,现有的策略是不够的,而只是有助于病毒作者和反病毒行业之间的持续军备竞赛。这个建议解决了这样一个问题:“下一个重大突破是什么,反病毒技术的下一次革命是什么?“PI建议CMU、赛门铁克和CERT共同研究全球防御机制和部署战略。而不是从单个节点的角度来处理问题,这项研究将采取网络范围内的观点。除了直接的影响,这个问题提出了研究的挑战,是非常有吸引力的理论家和从业者allowed.The初步研究表明,似乎有一个自组织临界性和病毒传播的原则之间的类比-一旦传播的动态状态跨越一个临界水平的分布,病毒传播,并达到最终的流行。这与传统的流行阈值形成对比,传统的流行阈值仅使用病毒的静态出生率和死亡率来表征。了解这种临界水平的分布是一个有趣的问题,它很可能指向阻止计算机病毒传播的新方法。研究动态模型等数学模型与病毒传播之间的相似性是该提案的中心主题。 PI在这项工作中提出了三个主要目标。1)确定现代病毒和蠕虫的拓扑结构。 有人认为,病毒传播遵循幂律结构,就像物理互联网拓扑结构一样。然而,没有理由相信病毒传播会反映网络的物理拓扑。相反,有证据表明,它们遵循某种社交网络,或者在某些蠕虫的情况下是随机网络。我们的工作将是第一个使用真实的攻击数据和用户数据开发病毒传播拓扑的确定模型。2)开发一个新的模型,捕获虚拟拓扑上的传播行为。具体来说,PI的兴趣是建模a)拓扑感知传播行为,B)环境因素的影响,以及c)感染(耗散)和防御(反馈力)之间的动态。3)使用数学模型来开发和推理以网络为中心的防御策略。PI团队是CMU计算机和通信安全中心(C3 S)的一部分。该中心的目标之一是促进安全教育。我们正在设计一个新的学位课程-信息安全硕士。我们希望这种合作研究的努力,以激发学生的兴趣,促进信息安全的进一步研究。赛门铁克将在整个过程中成为行业合作伙伴。具体来说,他们将向我们提供他们的专有数据库,其中包含有关病毒事件的广泛数据集。此外,其中两名PI与CERT(软件工程研究所的一部分,CMU运营的FFRDC)联合任命,并有权访问与真实的病毒事件相关的大量且不断增长的数据。
英文摘要
Since the Morris worm hit the Internet, the evolution of viruses and worms has kept anti-virus analysts busy developing new scanning and detection capabilities. New viruses continue to outsmart current technologies and wreak havoc. It is clear that existing strategies do not suffice but rather only contribute to the ongoing arms race between virus writers and the anti-virus industry. This proposal addresses the question: "What is the next big break, the next revolution in anti-virus technology?"The PIs propose a joint effort between CMU, Symantec and CERT to research global defense mechanisms and deployment strategies. Instead of approaching the problem from the perspective of individual nodes, this research will take on a network-wide point of view. In addition to the immediate impact, the problem presents research challenges that are extremely appealing to theorists and practitioners alike.The preliminary study suggests that there appears to be an analogy between the principles of self-organized criticality and virus propagation-once the dynamic state of propagation crosses a critical level of distribution, the virus flourishes and attains eventual prevalence. This is in contrast to the traditional epidemic threshold that is characterized using only static birth and death rate of the virus. Understanding this critical level of distribution is an interesting problem, and it is likely to point to new methods to thwart the spread of computer viruses. Studying the analogy between mathematical models such as dynamic-state models and virus propagation is a central theme of this proposal. The PIs propose three major thrusts in this work. 1) Determine the topology underlying modern viruses and worms. It has been suggested that virus propagation obeys a power-law structure much like the physical Internet topology. However, there is no reason to believe that viral propagations would mirror the physical topology of the network. Rather, evidence suggests that they follow some sort of a social network, or a random network in the case of some worms. Our work will be the first to develop a definitive model of virus propagation topology using real attack data and user data.2) Develop a new model that captures propagation behavior on the virtual topology. Specifically, the PIs are interested in modeling a) topology-aware propagation behavior, b) the effect of environmental factors, and c) the dynamics between infections (dissipation) and defenses (feedback force).3) Use the mathematical models to develop and reason about network-centric defense strategies.The PI team is part of the Center for Computer and Communications Security (C3S) at CMU. One of the center's goals is to promote security education. We are in the process of engineering a new degree program-Master in Information Security. We expect this collaborative research effort to stimulate student interests and foster further research in information security. Symantec will be an industry partner throughout this effort. Specifically, they will supply us with their proprietary database containing an extensive dataset with respect to virus incidents. In addition, two of the PIs hold joint appointments with CERT (part of the Software Engineering Institute, an FFRDC operated by CMU) and have access to a large and growing body of data associated with real virus episodes.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
-
批准号:2338301
-
项目类别:Continuing Grant
-
资助金额:$32.04万
-
财政年份:2024
-
负责人:Ljudevit Bauer
-
依托单位:
SaTC: CORE: Medium: Collaborative: Using Machine Learning to Build More Resilient and Transparent Computer Systems
-
批准号:1801391
-
项目类别:Standard Grant
-
资助金额:$69.16万
-
财政年份:2018
-
负责人:Ljudevit Bauer
-
依托单位:
Student Travel Grants for the 2014 Network and Distributed System Security Symposium
-
批准号:1354080
-
项目类别:Standard Grant
-
资助金额:$1.0万
-
财政年份:2013
-
负责人:Ljudevit Bauer
-
依托单位:
TC: Small: An Empirical Study of Text-based Passwords and Their Users
-
批准号:1116776
-
项目类别:Standard Grant
-
资助金额:$49.45万
-
财政年份:2011
-
负责人:Ljudevit Bauer
-
依托单位:
TC: Small: Towards precise specification of logic-based acces-control policies
-
批准号:1018211
-
项目类别:Standard Grant
-
资助金额:$47.96万
-
财政年份:2010
-
负责人:Ljudevit Bauer
-
依托单位:
Enabling Practical Cross-domain Logic-based Access Control
-
批准号:0917047
-
项目类别:Standard Grant
-
资助金额:$43.56万
-
财政年份:2009
-
负责人:Ljudevit Bauer
-
依托单位:
CT-M: Usable Security for Digital Home Storage
-
批准号:0831407
-
项目类别:Continuing Grant
-
资助金额:$100.0万
-
财政年份:2008
-
负责人:Ljudevit Bauer
-
依托单位:
CT-ISG: Collaborative Research: Trustworthy Enforcement of Domain-Independent Run-Time Policies
-
批准号:0716216
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Ljudevit Bauer
-
依托单位:
海外基金