CT-T: Using Structural and Behavioral Models to Detect Malware
CT-T: Using Structural and Behavioral Models to Detect Malware
批准号:
0627783
负责人:
Giovanni Vigna
金额:
$23.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2006
资助国家:
美国
项目状态:
已结题
起止时间:
2006-10-01 至 2008-09-30
中文摘要
提案编号:0627783PI:Giovanni Vigna Institution:加州大学圣巴巴拉分校标题:使用结构和行为模型检测恶意软件摘要在过去几年中,恶意软件(Malware)已经演变和多样化。附着在现有程序上并需要代表用户执行操作的简单病毒已经演变为蠕虫,可以感染数千台主机并扰乱整个网络。Rootkit和特洛伊木马程序已经从出于恶意目的模仿合法应用程序的简单程序演变为在操作系统内核级别运行的复杂软件组件,使得检测和根除它们变得困难。此外,出现了全新类型的恶意软件,如间谍软件和广告软件。不幸的是,恶意软件的演变并没有与防御工具的相应演变相匹配。大多数恶意软件检测工具都是基于语法的,并且使用相对简单的模式匹配技术。这些技术只能识别已知的恶意软件,此外,它们很容易被使用混淆和多态技术的复杂恶意软件愚弄。为了能够可靠地检测复杂的恶意软件,有必要开发依赖于程序语法结构以外的信息的分析技术。因此,这项研究工作将集中在开发新的二进制分析技术,使用结构和行为模型来检测复杂的恶意软件。更准确地说,所提出的技术使用静态和动态分析的组合来识别其行为类似于诸如病毒、蠕虫、间谍软件程序或Rootkit等恶意软件的行为的代码。这种方法将允许人们检测以前未见过的恶意软件,并识别已知恶意软件的突变。
英文摘要
Proposal Number: 0627783PI: Giovanni Vigna Institution: University of California, Santa Barbara Title: Using Structural and Behavioral Models to Detect Malware AbstractIn the past few years, malicious software (malware) has evolved and diversified. Simple viruses that attach to existing programs and require action on behalf of a user to execute have evolved into worms that can infectthousands of hosts and disrupt entire networks. Rootkits and Trojan horses have evolved from simple programs that mimic legitimate applications for malicious purposes into sophisticated software components that operate at the OS kernel level, making it difficult to detect and eradicate them. In addition, completely new types of malware, such as spyware and adware, have emerged.Unfortunately, the evolution of malware has not been matched by a corresponding evolution in defense tools. Most malware detection tools are syntax-based and use relatively simple pattern matching techniques. Thesetechniques can only recognize known malware, and, in addition, they can be easily fooled by sophisticated malware that uses obfuscation and polymorphic techniques.To be able to reliably detect sophisticated malware it is necessary to develop analysis techniques that rely on information other than the syntactic structure of the program. Therefore, this research effort will focus ondeveloping novel binary analysis techniques that use structural and behavioral models to detect sophisticated malware. More precisely, the proposed techniques use a composition of static and dynamic analysis to identify code whose behavior is similar to the behavior of malware such as viruses, worms, spyware programs, or rootkits. This approach will allow one to detect previously unseen malware and identify mutations of known malware.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
AI Institute for Agent-based Cyber Threat Intelligence and Operation
-
批准号:2229876
-
项目类别:Cooperative Agreement
-
资助金额:$1999.42万
-
财政年份:2023
-
负责人:Giovanni Vigna
-
依托单位:
SaTC: CORE: Medium: Augmenting Automated Vulnerability Analysis with Human Activity
-
批准号:1704253
-
项目类别:Continuing Grant
-
资助金额:$110.16万
-
财政年份:2017
-
负责人:Giovanni Vigna
-
依托单位:
EDU: Collaborative: Educating the Security Workforce through On-Demand Live Competitions
-
批准号:1623246
-
项目类别:Standard Grant
-
资助金额:$14.54万
-
财政年份:2016
-
负责人:Giovanni Vigna
-
依托单位:
TWC: TTP Option: Medium: Collaborative: Identifying and Mitigating Trust Violations in the Smartphone Ecosystem
-
批准号:1408632
-
项目类别:Standard Grant
-
资助金额:$106.61万
-
财政年份:2014
-
负责人:Giovanni Vigna
-
依托单位:
Organization of Grand Challenges in Cyber Security
-
批准号:0939188
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2009
-
负责人:Giovanni Vigna
-
依托单位:
SGER: Grand Challenges in Cyber Security
-
批准号:0820907
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2008
-
负责人:Giovanni Vigna
-
依托单位:
CT-ER: A Framework for Live Security Exercises and Challenges
-
批准号:0716753
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-T: Modeling and Analyzing Trust in Service-Oriented Architectures
-
批准号:0716095
-
项目类别:Standard Grant
-
资助金额:$85.0万
-
财政年份:2007
-
负责人:Giovanni Vigna
-
依托单位:
CT-ISG: Multi-Model Anomaly Detection for Web-Based Applications
-
批准号:0524853
-
项目类别:Continuing grant
-
资助金额:$45.0万
-
财政年份:2005
-
负责人:Giovanni Vigna
-
依托单位:
CAREER: A Multi-Level Approach to Malicious Mobile Code Detection
-
批准号:0238492
-
项目类别:Continuing grant
-
资助金额:$39.99万
-
财政年份:2003
-
负责人:Giovanni Vigna
-
依托单位:
Collaborative Research: MASSA: Mobile Agent System Security Through Analysis
-
批准号:0209065
-
项目类别:Continuing grant
-
资助金额:$23.01万
-
财政年份:2002
-
负责人:Giovanni Vigna
-
依托单位:
国内基金
海外基金
Capture and Release of Droplets Using Advanced Materials for High Technology Applications
-
批准号:52073127
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2020
-
负责人:Alidad Amirfazli
-
依托单位:
Molecular Interaction Reconstruction of Rheumatoid Arthritis Therapies Using Clinical Data
-
批准号:31070748
-
项目类别:面上项目
-
资助金额:34.0万元
-
批准年份:2010
-
负责人:Christine Nardini
-
依托单位: