TC: Medium: Collaborative Research: Multi-Perspective Bayesian Learning for Automated Diagnosis of Advanced Malware
TC: Medium: Collaborative Research: Multi-Perspective Bayesian Learning for Automated Diagnosis of Advanced Malware
批准号:
0905518
负责人:
Phillip Porras
金额:
$24.75万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-15 至 2014-08-31
中文摘要
当代互联网恶意软件不断发展,使防病毒和入侵检测系统越来越过时。简单地依靠二进制签名来识别恶意软件已不再被接受。当前和未来几代恶意软件都需要全新的检测策略,这些策略可以容忍二进制结构和有效载荷传递机制中的快速扰动。为此,一个有前途的方向是使用多角度,面向行为的范式恶意软件识别。在这个项目中,我们提出了一种新的方法,1)自动提取感染知识,基于多视角,面向行为的观点,2)快速应用这些获得的知识来诊断主机系统中是否存在恶意软件。对于每个恶意软件家族,将自动提取概率配置文件,其捕获其成员的不变行为特征。这种设想的知识提取过程应该在其不变行为表征中提供足够的抽象,使得可以识别未来的恶意软件变体。我们还提出了一个贝叶斯框架诊断现场的计算机系统上的恶意软件感染。如果成功,这项研究将引入一种新的补充策略,用于诊断恶意软件感染,其方式无法通过当前的防病毒对策套件击败。
英文摘要
Contemporary Internet malware is constantly evolving and making antivirus and intrusion detection systems increasingly obsolete. It is no longer acceptable to simply rely on binary signatures for malware identification. Both current and future generations of malware will require entirely new detection strategies that can tolerate the rapid perturbations in binary structure and payload delivery mechanisms. A promising direction to this end is the use of multi-perspective, behavioral-oriented paradigms for malware identification. In this project, we propose a new approach to 1) automatically extract infection knowledge, based on a multi-perspective, behavior-oriented view, and 2) rapidly apply this gained knowledge to diagnose the presence of malware in host computer systems. For each malware family, a probabilistic profile will be automatically extracted, which captures the invariant behavioral features of its members. This envisioned knowledge-extraction process should provide sufficient abstraction in its invariant behavior characterization such that future malware variants can be recognized. We also propose a Bayesian framework for diagnosing live malware infections on fielded computer systems. If successful, this research will introduce a new complementary strategy for diagnosing malware infections in ways that cannot be defeated through the current suite of antivirus countermeasures.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Convergence Accelerator Track: G: The Security-Enhanced Radio Access Network (SE-RAN)
-
批准号:2326882
-
项目类别:Cooperative Agreement
-
资助金额:$499.96万
-
财政年份:2023
-
负责人:Phillip Porras
-
依托单位:
NSF Convergence Accelerator Track: G: Security Services for the 5G Software-Defined Edge
-
批准号:2226443
-
项目类别:Standard Grant
-
资助金额:$74.87万
-
财政年份:2022
-
负责人:Phillip Porras
-
依托单位:
EAGER: Visualizing Cyber Defense Networks
-
批准号:1824258
-
项目类别:Standard Grant
-
资助金额:$29.99万
-
财政年份:2018
-
负责人:Phillip Porras
-
依托单位:
Exploring the Transition of Research-Derived Cyber-Threat Data
-
批准号:1640386
-
项目类别:Standard Grant
-
资助金额:$62.97万
-
财政年份:2016
-
负责人:Phillip Porras
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: S3D: A New SDN-Based Security Framework for the Science DMZ
-
批准号:1642150
-
项目类别:Standard Grant
-
资助金额:$34.98万
-
财政年份:2016
-
负责人:Phillip Porras
-
依托单位:
EAGER: ACI: A Software-Defined Network (SDN) WAN Security Testbed
-
批准号:1547206
-
项目类别:Standard Grant
-
资助金额:$24.96万
-
财政年份:2015
-
负责人:Phillip Porras
-
依托单位:
EAGER: ACI: Secure and Effective Policy Enforcement in Software-Defined WANs
-
批准号:1446426
-
项目类别:Standard Grant
-
资助金额:$29.97万
-
财政年份:2014
-
负责人:Phillip Porras
-
依托单位:
Collaborative Research: CT-L: CLEANSE: Cross-Layer Large-Scale Efficient Analysis of Network Activities to Secure the Internet
-
批准号:0831170
-
项目类别:Continuing Grant
-
资助金额:$17.5万
-
财政年份:2008
-
负责人:Phillip Porras
-
依托单位:
Collaborative Research: CT-T: Logic and Data Flow Extraction for Live and Informed Malware Execution
-
批准号:0716612
-
项目类别:Continuing Grant
-
资助金额:$44.0万
-
财政年份:2007
-
负责人:Phillip Porras
-
依托单位:
海外基金