课题基金 / 基金详情

CAREER: Towards Exterminating Stealthy Rootkits - A Systematic Immunization Approach

CAREER: Towards Exterminating Stealthy Rootkits - A Systematic Immunization Approach
事业:消灭隐形 Rootkit - 系统免疫方法
批准号:
0952640
负责人:
Xuxian Jiang
金额:
$42.42万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-02-15 至 2015-01-31

项目摘要

项目成果

Xuxian Jiang的其他基金

相似基金

相关文献

中文摘要
翻译
隐形rootkit的猖獗增长对网络空间构成了严重的安全威胁。具体地说,利用直接破坏计算机系统的软件信任根的能力,rootkit可以秘密地接管系统的控制,并在此后保持隐藏的存在。 为了有效地防御它们,研究人员探索了各种反rootkit解决方案。不幸的是,对我们不利的是,最先进的防御主要是反应性的,不能满足对他们的军备竞赛的挑战。这个项目正在开发一个系统的免疫方法,以主动预防和消灭rootkit攻击。这一目标正在通过三个关键步骤实现。首先,我们正在开发一种基本的免疫能力自我非自我歧视,以可靠地识别和防止恶意rootkit代码执行。其次,我们正在研究一个内核牧羊技术,以加强内核控制流的完整性。第三,我们正在设计和实现一个具有最小可信计算基础的高保证虚拟机管理程序,以建立和维持整个计算机系统的信任根。我们希望这项研究的结果将大大提高我们对难以捉摸的rootkit以及更通用的恶意软件的防御能力。我们将通过发布开发的工具以及适用于本科生和研究生课程以及行业和政府机构IT人员培训的相关教育材料来传播我们的成果。
英文摘要
The rampant growth of stealthy rootkits poses a serious security threat to cyberspace. Specifically, with the capability of directly subverting the software root of trust of a computer system, a rootkit can surreptitiously take over the control of the system and maintain a hidden presence thereafter. To effectively defend against them, researchers have explored various anti-rootkit solutions. Unfortunately, to our disadvantage, the state-of-the-art defense is mainly reactive and cannot meet the challenges in the arms-race against them.This project is developing a systematic immunization approach to proactively prevent and exterminate rootkit attacks. This goal is being achieved in three key steps. First, we are developing a fundamental immunization capability self-nonself discrimination to reliably discern and prevent malicious rootkit code execution. Second, we are investigating a kernel shepherding technique to enforce kernel control-flow integrity. Third, we are designing and implementing a high-assurance hypervisor with a minimal trusted computing base to establish and sustain the root-of-trust of the entire computer system. We expect the results from this research will substantially elevate our defense capability against elusive rootkits as well as more generic malware. We will disseminate our results by releasing the tools developed as well as associated education materials appropriate for undergraduate and graduate courses and IT staff training in industry and government agencies.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: II-NEW: OpenVMI: A Software Instrument for Virtual Machine Introspection
  • 批准号:
    0855036
  • 项目类别:
    Standard Grant
  • 资助金额:
    $22.5万
  • 财政年份:
    2009
  • 负责人:
    Xuxian Jiang
  • 依托单位:
CT-ISG: Understanding Botnet Command and Control (C&C) Communication
  • 批准号:
    0831160
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2008
  • 负责人:
    Xuxian Jiang
  • 依托单位:
CT-ISG: Collaborative: Enabling Detection of Elusive Malware by by Going Out of the Box with Semantically Reconstructed View (OBSERV)
  • 批准号:
    0852131
  • 项目类别:
    Standard Grant
  • 资助金额:
    $20.26万
  • 财政年份:
    2008
  • 负责人:
    Xuxian Jiang
  • 依托单位:
CT-ISG: Understanding Botnet Command and Control (C&C) Communication
  • 批准号:
    0855297
  • 项目类别:
    Standard Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2008
  • 负责人:
    Xuxian Jiang
  • 依托单位:
海外基金