SBIR Phase II: SAFE: Behavior-based Malware Detection and Prevention
SBIR Phase II: SAFE: Behavior-based Malware Detection and Prevention
批准号:
0750299
负责人:
Hao Wang
金额:
$0.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-03-01 至 2011-02-28
中文摘要
SBIR第二阶段项目的目标是实现一个具有商业竞争力的、基于主机的恶意软件检测和预防系统。在第一阶段,一个基于主机的恶意软件检测系统,展示了检测恶意进程的实用性,通过动态监视其系统事件的开发。这个原型称为SAFE(安全活动过滤引擎),它使用一个有状态的策略引擎过滤系统事件,该引擎的策略指定恶意行为和适当的响应。由于该技术不依赖于“签名”(即字节模式)的检测,因此它可以检测以前未见过的恶意软件。在第二阶段,将对政策引擎进行一些重大改进,包括检查点/回滚能力。当检测到违反策略时,建议的功能将删除与进程关联的文件系统和注册表更改。延迟检测恶意行为直到观察到详细的系统事件的能力提供了即时检测能力,其增加了检测过程的准确性,同时减少了误报。SAFE技术有可能展示一种有效的方法,以应对威胁格局中至少两种主要趋势。 其中一个趋势是制作混合威胁,使用多种感染媒介,如电子邮件阅读器,Web浏览器和消息传递软件来感染主机。另一个趋势是“恶意软件工具包”的流行,恶意软件作者可以使用这些工具包快速生成同一病毒的多个变体。混淆变体的快速扩散在两个方面对传统的基于签名的解决方案构成了潜在的威胁:恶意软件感染的速度可能会压倒生成签名以检测这些变体的努力,签名数据库大小的对数增长会降低签名扫描的性能。SAFE技术解决了这两个趋势。有状态策略引擎可以将多个子系统和进程中的非同步事件关联起来,从而检测和阻止混合威胁。 如果成功,拟议系统的架构将有可能解决无数的安全威胁,并产生重大的商业影响。
英文摘要
This SBIR Phase II project has the objective of implementing a commercially-competitive, host-based, malware detection and prevention system. During Phase I, a host-based malware detection system that demonstrated the practicality of detecting a malicious process by dynamically monitoring its system events was developed. The prototype called SAFE (Secure Activity Filtering Engine) filters system events using a stateful policy engine whose policies specify malicious behavior and the appropriate response. Because the technology does not rely upon the detection of "signatures" (i.e. patterns of bytes), it can detect previously unseen malware. During Phase II a number of significant enhancements to the policy engine including a checkpoint/rollback capability will be developed. The proposed functionality removes file system and registry changes associated with a process when a policy violation is detected. The ability to delay detection of malicious behavior until detailed system events are observed provides a just-in-time detection capability that increases the accuracy of the detection process while reducing false positives. The SAFE technology has the potential to demonstrate an effective approach to combating at least two of the dominant trends in the threat landscape. One such trend is the crafting of blended threats which use multiple infections vectors like email readers, web browsers, and messaging software to infect a host computer. Another trend is the popularity of "malware toolkits" which can be used by malware writers to quickly generate multiple variants of the same virus. The rapid proliferation of obfuscated variants is a potent threat to traditional signature-based solutions on two fronts: the rate of malware infection may overwhelm efforts to produce signatures to detect these variants and the logarithmic increase in the size of signatures databases reduces the performance of signature scanning. The SAFE technology addresses both of these trends. The stateful policy engine can correlate non simultaneous events across multiple sub systems and processes and thus detect and block blended threats. If successful, the architecture of the proposed system will have the potential to address a myriad of security threats and make a commercially-significant impact.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
RII Track-4:NSF: Federated Analytics Systems with Fine-grained Knowledge Comprehension: Achieving Accuracy with Privacy
-
批准号:2327480
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2024
-
负责人:Hao Wang
-
依托单位:
Collaborative Research: OAC: Core: Harvesting Idle Resources Safely and Timely for Large-scale AI Applications in High-Performance Computing Systems
-
批准号:2403398
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2024
-
负责人:Hao Wang
-
依托单位:
Collaborative Research: SaTC: CORE: Small: Critical Learning Periods Augmented Robust Federated Learning
-
批准号:2315612
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2023
-
负责人:Hao Wang
-
依托单位:
CRII: OAC: High-Efficiency Serverless Computing Systems for Deep Learning: A Hybrid CPU/GPU Architecture
-
批准号:2153502
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2022
-
负责人:Hao Wang
-
依托单位:
RI: Small: Enabling Interpretable AI via Bayesian Deep Learning
-
批准号:2127918
-
项目类别:Continuing Grant
-
资助金额:$49.99万
-
财政年份:2021
-
负责人:Hao Wang
-
依托单位:
US-China planning visit: Development of High Performance and Multifunctional Infrastructure Material
-
批准号:1338297
-
项目类别:Standard Grant
-
资助金额:$1.28万
-
财政年份:2013
-
负责人:Hao Wang
-
依托单位:
SBIR Phase I: SpiderWeb - Self-Healing Networks for Spyware Detection
-
批准号:0638170
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2007
-
负责人:Hao Wang
-
依托单位:
Constructibility and Large Cardinal Numbers
-
批准号:7902941
-
项目类别:Standard Grant
-
资助金额:$1.56万
-
财政年份:1979
-
负责人:Hao Wang
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Baryogenesis, Dark Matter and Nanohertz Gravitational Waves from a Dark
Supercooled Phase Transition
-
批准号:24ZR1429700
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:YUICHIRO NAKAI
-
依托单位:
ATLAS实验探测器Phase 2升级
-
批准号:11961141014
-
项目类别:国际(地区)合作与交流项目
-
资助金额:3350万元
-
批准年份:2019
-
负责人:刘衍文
-
依托单位:
地幔含水相Phase E的温度压力稳定区域与晶体结构研究
-
批准号:41802035
-
项目类别:青年科学基金项目
-
资助金额:12.0万元
-
批准年份:2018
-
负责人:张里
-
依托单位:
基于数字增强干涉的Phase-OTDR高灵敏度定量测量技术研究
-
批准号:61675216
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2016
-
负责人:叶青
-
依托单位:
基于Phase-type分布的多状态系统可靠性模型研究
-
批准号:71501183
-
项目类别:青年科学基金项目
-
资助金额:17.4万元
-
批准年份:2015
-
负责人:陈童
-
依托单位:
纳米(I-Phase+α-Mg)准共晶的临界半固态形成条件及生长机制
-
批准号:51201142
-
项目类别:青年科学基金项目
-
资助金额:25.0万元
-
批准年份:2012
-
负责人:张英波
-
依托单位:
连续Phase-Type分布数据拟合方法及其应用研究
-
批准号:11101428
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2011
-
负责人:黄卓
-
依托单位:
D-Phase准晶体的电子行为各向异性的研究
-
批准号:19374069
-
项目类别:面上项目
-
资助金额:6.4万元
-
批准年份:1993
-
负责人:张殿琳
-
依托单位: